A digital domain visible light adversarial sample performance testing method
By constructing a target detector and simulating the imaging environment using Fourier transform and transfer function, the robustness and stability testing problem of visible light adversarial examples was solved, enabling a comprehensive evaluation of adversarial example performance and guiding the generation of adversarial examples.
Patent Information
- Application Number
- CN202411376154.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-09-30
AI Technical Summary
Existing technologies lack robustness and stability testing methods for adversarial examples in the visible light digital domain, making it difficult to adapt to different imaging environments and devices.
By constructing a target detector, adding preset perturbations to generate adversarial examples, and using Fourier transform and transfer function to simulate the effects of the imaging environment and equipment, the performance indicators of the adversarial examples, including EOCM1 and EOCM2, are calculated to determine the adversarial changes.
It enriches the methods for testing the robustness and stability of adversarial examples, takes into account the influence of imaging environment and equipment, and guides the design and generation of physical domain adversarial examples.
Smart Images

Figure CN119441836B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of adversarial sample performance testing technology, and particularly relates to a digital domain visible light adversarial sample performance testing method. Background Technology
[0002] Digital domain visible light adversarial examples refer to tiny perturbations added to digital images or data that are almost imperceptible to the eye but can cause machine learning models (such as image classifiers, object detectors, etc.) to make incorrect predictions or decisions.
[0003] Adversarial examples generated in the digital domain are generally difficult to adapt to the real physical world, meaning their adversarial nature is hard to maintain under different imaging environments and devices. However, existing technologies lack robustness and stability testing methods for adversarial examples in the visible light digital domain. Summary of the Invention
[0004] To address the aforementioned technical problems, this invention proposes a method for testing the performance of adversarial samples in the digital domain visible light.
[0005] The first aspect of this invention discloses a method for testing the performance of adversarial samples in the digital domain visible light; the method includes:
[0006] Step 1: Construct normal samples based on the acquired digital images or data, train the target detector D using the normal samples, and record the average target detection accuracy M1 corresponding to the normal samples.
[0007] Step 2: Add preset perturbations to the acquired digital images or data to generate digital domain visible light adversarial sample A1;
[0008] Step 3: Input the digital domain visible light adversarial sample A1 into the trained target detector D, and record the average target detection accuracy M2 corresponding to A1.
[0009] Step 4: Based on the difference between M1 and M2, obtain the adversarial index EOCM1 before the adversarial example performance test for the trained target detector D.
[0010] Step 5: Perform a Fourier transform on A1 to obtain the Fourier transformed digital domain visible light adversarial sample A2;
[0011] Step 6: Based on A2, superimpose the transfer functions to obtain the superimposed result A3;
[0012] Step 7: Perform an inverse Fourier transform on A3 to obtain the superposition result A4 after the inverse Fourier transform;
[0013] Step 8: Input A4 into the trained target detector D and record the average target detection accuracy M3 corresponding to A4;
[0014] Step 9: Based on the difference between M1 and M3, obtain the adversarial index EOCM2 after adversarial example performance test for the trained target detector D.
[0015] Step 10: Based on EOCM1 and EOCM2, obtain the relative change index of adversarial performance before and after the adversarial example performance test for the trained target detector D, and then determine the adversarial nature of the adversarial example.
[0016] In step 1, the target detector D includes an SSD network, a YOLO v9 network, or a Faster RCNN network.
[0017] Step 6 specifically includes:
[0018] Based on A2, the atmospheric turbulence transfer function, aerosol modulation transfer function, diffraction limit transfer function, aberration transfer function, image sensor transfer transfer function, image sensor spatial filtering transfer function, and image sensor temporal filtering transfer function are superimposed to obtain the superimposed result A3.
[0019] The specific process of superimposing transfer functions is as follows:
[0020] A3 = A2 × MTF turb ×MTF aero ×MTF diff ×MTF aber ×MTF CCD ×MTF ds ×MTF dt
[0021] Among them, MTF turb MTF is the atmospheric turbulence transfer function. aero aerosol modulation transfer function; MTF diff The diffraction-limited transfer function; MTF aber MTF is the aberration transfer function. CCD For image sensor transfer function; MTF ds The spatial filtering transfer function for image sensors; MTF dt Here, is the time-filtering transfer function for the image sensor; where,
[0022]
[0023] Where ν is the angular spatial frequency; λ is the refractive index structure constant; L is the visible light wavelength; L is the path length.
[0024]
[0025] in, α is the angular spatial cutoff frequency, and α is the diameter of the aerosol particle; k a k is the absorption coefficient. s The scattering coefficient;
[0026]
[0027] in, Let λ be the spatial cutoff frequency of the incoherent optical system, D0 be the effective aperture of the optical system, and λ be the λ value. s f is the center wavelength of incoherent light. x f y These are the spatial frequencies in the horizontal and vertical directions, respectively.
[0028]
[0029] Where σ is the standard deviation measured by angle;
[0030]
[0031] Where N is the number of bits in the CCD; η is the transfer efficiency; f t For time frequency; f tc Clock frequency;
[0032]
[0033] Where α and β are the spatial angles of the rectangular detector;
[0034]
[0035] Where f is the spatial frequency; f0 is the frequency corresponding to 3dB.
[0036] In step 10, the EOCM calculation method is as follows:
[0037]
[0038] In step 10, if EOCM > 0, the adversarial nature of the digital domain visible light adversarial sample is relatively weakened; if EOCM = 0, the adversarial nature of the digital domain visible light adversarial sample remains relatively unchanged; if EOCM < 0, the adversarial nature of the digital domain visible light adversarial sample is relatively enhanced.
[0039] A second aspect of this invention discloses a digital domain visible light adversarial sample performance testing system, the system comprising:
[0040] The first processing module is configured to construct normal samples based on the acquired digital images or data, train the target detector D using the normal samples, and record the average target detection accuracy M1 corresponding to the normal samples.
[0041] The second processing module is configured to add a preset perturbation to the acquired digital image or data to generate a digital domain visible light adversarial sample A1.
[0042] The third processing module is configured to send the digital domain visible light adversarial sample A1 into the trained target detector D and record the target average detection accuracy M2 corresponding to A1.
[0043] The fourth processing module is configured to obtain the adversarial index EOCM1 before the adversarial example performance test for the trained target detector D based on the difference between M1 and M2.
[0044] The fifth processing module is configured to perform a Fourier transform on A1 to obtain the Fourier transformed digital domain visible light adversarial sample A2.
[0045] The sixth processing module is configured to superimpose transfer functions based on A2 to obtain the superimposed result A3;
[0046] The seventh processing module is configured to perform an inverse Fourier transform on A3 to obtain the superposition result A4 after the inverse Fourier transform.
[0047] The eighth processing module is configured to send A4 into the trained target detector D and record the average target detection accuracy M3 corresponding to A4.
[0048] The ninth processing module is configured to obtain the adversarial index EOCM2 after adversarial example performance test for the trained target detector D based on the difference between M1 and M3.
[0049] The tenth processing module is configured to obtain the relative change index of adversarial performance before and after the adversarial example performance test for the trained target detector D based on EOCM1 and EOCM2, and then determine the adversarial nature of the adversarial example.
[0050] A third aspect of this invention discloses an electronic device. The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of the digital domain visible light adversarial sample performance testing method according to any one of the first aspects of this disclosure.
[0051] A fourth aspect of this invention discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the digital domain visible light adversarial sample performance testing method according to any one of the first aspects of this disclosure.
[0052] In summary, the solution proposed in this invention has the following technical effects: the technical solution of this invention takes into account the influence of the imaging environment and imaging equipment on the performance of visible light adversarial examples, enriches the means of testing the robustness and stability of digital domain adversarial examples, and has important guiding significance for the design and generation of physical domain adversarial examples. Attached Figure Description
[0053] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0054] Figure 1 This is a flowchart of a digital domain visible light adversarial sample performance testing method according to an embodiment of the present invention;
[0055] Figure 2 This is a structural diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0056] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0057] According to an embodiment of the present invention, in a first aspect, a method for testing the performance of adversarial examples in the digital domain visible light is provided; see also Figure 1 The method includes:
[0058] Step 1: Construct normal samples based on the acquired digital images or data, train the target detector D using the normal samples, and record the average target detection accuracy M1 corresponding to the normal samples.
[0059] In step 1, the target detector D includes, but is not limited to, an SSD network, a YOLO v9 network, or a Faster RCNN network.
[0060] Step 2: Add a preset perturbation to the acquired digital image or data to generate a digital domain visible light adversarial sample A1; in Step 2, the adversarial sample generation method includes, but is not limited to, Fast Gradient Sign Method (FGSM), Carlini and Wagner's Attack (C&W), Full-coverage Camouflage Attack (FCA), etc.
[0061] Step 3: Input the digital domain visible light adversarial sample A1 into the trained target detector D, and record the average target detection accuracy M2 corresponding to A1.
[0062] Step 4: Based on the difference between M1 and M2, obtain the adversarial performance index EOCM1 before adversarial example performance testing for the trained target detector D; the calculation method of EOCM1 is as follows:
[0063] EOCM1 = M1 - M2
[0064] Step 5: Perform a Fourier transform on A1 to obtain the Fourier transformed digital domain visible light adversarial sample A2;
[0065] Step 6: Based on A2, superimpose the transfer functions to obtain the superimposed result A3;
[0066] In step S6, the specific process of superimposing transfer functions is as follows:
[0067] A3 = A2 × MTF turb ×MTF aero ×MTF diff ×MTF aber ×MTF CCD ×MTF ds ×MTF dt
[0068] In step 6, the atmospheric turbulence transfer function is as follows:
[0069]
[0070] Where ν is the angular spatial frequency, representing the number of cycles per radian, and its relationship with the spatial frequency is ν = fυ (f is the focal length, υ is the spatial frequency); λ is the refractive index structure constant; λ is the wavelength; L is the path length.
[0071] In step 6, the aerosol transfer function is as follows:
[0072]
[0073] in, α is the angular spatial cutoff frequency, and α is the diameter of the aerosol particle; k a k is the absorption coefficient. s Let be the scattering coefficient, and the sum of the two is the extinction coefficient k. e , i.e., k e (h)=(3.912 / R m )exp(-h / 1200); R m h represents meteorological visibility distance; h represents altitude.
[0074] In step 6, the diffraction limit (optical) transfer function is as follows:
[0075]
[0076] in, λ is the spatial cutoff frequency of the incoherent optical system (in c / mrad), D0 is the effective aperture of the optical system (in mm); s The center wavelength of the incoherent light (in μm) can be taken as the average operating wavelength (λ1+λ2) / 2, where [λ1,λ2] is the operating wavelength range; f x f y These are the spatial frequencies in the horizontal and vertical directions, respectively.
[0077] In step 6, the aberration transfer function is as follows:
[0078]
[0079] Where σ is the standard deviation measured by angle, σ = σ c / f, measured in c / mrad, is directly related to the percentage of energy contained within the circle of confusion. Assuming all energy is concentrated within the circle of confusion, then the standard deviation σ... c It is equal to 1 / 4 of the diameter of the dispersion circle. This assumption can well approximate the shape of the dispersion patch and is easy to control. The diameter of the dispersion patch can be determined by the following formula:
[0080]
[0081] In step 6, the image sensor transfer function is as follows:
[0082]
[0083] Where N is the number of bits in the CCD; η is the transfer efficiency; f t For time frequency (in Hz); f tc This refers to the clock frequency (in Hz).
[0084] In step 6, the spatial filtering transfer function of the image sensor is as follows:
[0085]
[0086] Where α and β are the spatial angles of the rectangular detector; f x f y These are the spatial frequencies in the horizontal and vertical directions, respectively.
[0087] In step 6, the image sensor time filtering transfer function is as follows:
[0088]
[0089] Where f is the spatial frequency (unit: c / mrad); f0 is the frequency corresponding to 3dB (unit: c / mrad). (τ is the detector carrier lifetime (in μs)).
[0090] In step 6, the atmospheric turbulence transfer function and the aerosol modulation transfer function are used to characterize the imaging environment; the diffraction limit (optical) transfer function, aberration transfer function, image sensor transfer transfer function, image sensor spatial filtering transfer function, and image sensor temporal filtering transfer function are used to characterize the imaging device.
[0091] Step 7: Perform an inverse Fourier transform on A3 to obtain the superposition result A4 after the inverse Fourier transform;
[0092] Step 8: Input A4 into the trained target detector D and record the average target detection accuracy M3 corresponding to A4;
[0093] Step 9: Based on the difference between M1 and M3, obtain the adversarial performance index EOCM2 after adversarial example performance testing against the trained target detector D; the calculation method for EOCM2 is as follows:
[0094] EOCM2 = M1 - M3
[0095] Step 10: Based on EOCM1 and EOCM2, obtain the relative change index of adversarial performance before and after the adversarial example performance test for the trained target detector D, and then determine the adversarial nature of the adversarial example.
[0096] The EOCM calculation method is as follows:
[0097]
[0098] In step 10, if EOCM > 0, the adversarial nature of the digital domain visible light adversarial sample is relatively weakened; if EOCM = 0, the adversarial nature of the digital domain visible light adversarial sample remains relatively unchanged; if EOCM < 0, the adversarial nature of the digital domain visible light adversarial sample is relatively strengthened.
[0099] A second aspect of this invention discloses a digital domain visible light adversarial sample performance testing system, the system being used to implement the method described in any one of the above embodiments. The system includes:
[0100] The first processing module is configured to construct normal samples based on the acquired digital images or data, train the target detector D using the normal samples, and record the average target detection accuracy M1 corresponding to the normal samples.
[0101] The second processing module is configured to add a preset perturbation to the acquired digital image or data to generate a digital domain visible light adversarial sample A1.
[0102] The third processing module is configured to send the digital domain visible light adversarial sample A1 into the trained target detector D and record the target average detection accuracy M2 corresponding to A1.
[0103] The fourth processing module is configured to obtain the adversarial index EOCM1 before the adversarial example performance test for the trained target detector D based on the difference between M1 and M2.
[0104] The fifth processing module is configured to perform a Fourier transform on A1 to obtain the Fourier transformed digital domain visible light adversarial sample A2.
[0105] The sixth processing module is configured to superimpose transfer functions based on A2 to obtain the superimposed result A3;
[0106] The seventh processing module is configured to perform an inverse Fourier transform on A3 to obtain the superposition result A4 after the inverse Fourier transform.
[0107] The eighth processing module is configured to send A4 into the trained target detector D and record the average target detection accuracy M3 corresponding to A4.
[0108] The ninth processing module is configured to obtain the adversarial index EOCM2 after adversarial example performance test for the trained target detector D based on the difference between M1 and M3.
[0109] The tenth processing module is configured to obtain the relative change index of adversarial performance before and after the adversarial example performance test for the trained target detector D based on EOCM1 and EOCM2, and then determine the adversarial nature of the adversarial example.
[0110] A third aspect of this invention discloses an electronic device. The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of a digital domain visible light adversarial sample performance testing method according to any one of the first aspects of this disclosure.
[0111] Figure 2 This is a structural diagram of an electronic device according to an embodiment of the present invention, such as... Figure 2 As shown, the electronic device includes a processor, memory, communication interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, Near Field Communication (NFC), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input device can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the device's casing, or an external keyboard, touchpad, or mouse.
[0112] Those skilled in the art will understand that Figure 2 The structure shown is merely a structural diagram of the part related to the technical solution of this disclosure and does not constitute a limitation on the electronic device to which the solution of this application is applied. The specific electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0113] A fourth aspect of this invention discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps in a digital domain visible light adversarial sample performance testing method according to any one of the first aspects of this disclosure.
[0114] In summary, the technical solution proposed in this invention has the following technical effects: the technical solution of this invention takes into account the influence of the imaging environment and imaging equipment on the performance of visible light adversarial examples, enriches the means of testing the robustness and stability of digital domain adversarial examples, and has important guiding significance for the design and generation of physical domain adversarial examples.
[0115] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein, and such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for testing the performance of adversarial examples in the digital domain visible light, characterized in that, The method includes: Step 1: Construct normal samples based on the acquired digital images or data, train the target detector using the normal samples, and record the average target detection accuracy M1 corresponding to the normal samples. Step 2: Add preset perturbations to the acquired digital images or data to generate digital domain visible light adversarial sample A1; Step 3: Input the digital domain visible light adversarial sample A1 into the trained target detector and record the average target detection accuracy M2 corresponding to the digital domain visible light adversarial sample A1. Step 4: Calculate the difference between the average target detection accuracy M1 and the average target detection accuracy M2 to obtain the adversarial index EOCM1 before the adversarial sample performance test for the target detector that has been trained. Step 5: Perform a Fourier transform on the digital domain visible light adversarial sample A1 to obtain the Fourier transformed digital domain visible light adversarial sample A2. Step 6: Superimpose the transfer function onto the digital domain visible light adversarial sample A2 to obtain the first superposition result A3; Step 6 specifically includes: Against the adversarial sample A2, the atmospheric turbulence transfer function, aerosol modulation transfer function, diffraction limit transfer function, aberration transfer function, image sensor transfer transfer function, image sensor spatial filtering transfer function, and image sensor temporal filtering transfer function are superimposed to obtain the first superposition result A3; The specific process of superimposing transfer functions is as follows: A3A2×MTF turb ×MTF aero ×MTF diff ×MTF aber ×MTF CCD ×MTF ds ×MTF dt Among them, MTF turb MTF is the atmospheric turbulence transfer function. aero aerosol modulation transfer function; MTF diff The diffraction-limited transfer function; MTF aber MTF is the aberration transfer function. CCD For image sensor transfer function; MTF ds The spatial filtering transfer function for image sensors; MTF dt For image sensor time filtering transfer function; in, Where ν is the angular spatial frequency; λ is the refractive index structure constant; L is the visible light wavelength; L is the path length. in, α is the angular spatial cutoff frequency, and α is the diameter of the aerosol particle; k a k is the absorption coefficient. s The scattering coefficient; in, Let λ be the spatial cutoff frequency of the incoherent optical system, D0 be the effective aperture of the optical system, and λ be the λ value. s f is the center wavelength of incoherent light. x f y These are the spatial frequencies in the horizontal and vertical directions, respectively; Where σ is the standard deviation measured by angle; Where N is the number of bits in the CCD; η is the transfer efficiency; ft is the time frequency; f tc Clock frequency; Where α and β are the spatial angles of the rectangular detector; Where f is the spatial frequency; f0 is the frequency corresponding to 3dB; Step 7: Perform an inverse Fourier transform on the first superposition result A3 to obtain the second superposition result A4; Step 8: Input the second superposition result A4 into the target detector D that has been trained, and record the average target detection accuracy M3 corresponding to the second superposition result A4; Step 9: Calculate the difference between the average target detection accuracy M1 and the average target detection accuracy M3 to obtain the adversarial index EOCM2 after the adversarial example performance test for the trained target detector. Step 10: Based on the adversarial index EOCM1 and adversarial index EOCM2, obtain the adversarial relative change index EOCM before and after the adversarial sample performance test for the target detector that has been trained, so as to determine the adversarial nature of the digital domain visible light adversarial sample A1 according to the adversarial relative change index EOCM.
2. The method according to claim 1, characterized in that, In step 1, the target detector includes an SSD network, a Yolov9 network, or a Faster RCNN network.
3. The method according to claim 1, characterized in that, In step 10, the EOCM calculation method is as follows:
4. The method according to claim 3, characterized in that, In step 10, if EOCM > 0, the adversarial nature of the digital domain visible light adversarial sample is determined to be relatively weakened; if EOCM = 0, the adversarial nature of the digital domain visible light adversarial sample remains relatively unchanged; if EOCM < 0, the adversarial nature of the digital domain visible light adversarial sample is determined to be relatively strengthened.
5. A digital domain visible light adversarial sample performance testing system, characterized in that, The system includes: The first processing module is configured to construct normal samples based on the acquired digital images or data, train the target detector using the normal samples, and record the average target detection accuracy M1 corresponding to the normal samples. The second processing module is configured to add a preset perturbation to the acquired digital image or data to generate a digital domain visible light adversarial sample A1. The third processing module is configured to send the digital domain visible light adversarial sample A1 into the trained target detector and record the target average detection accuracy M2 corresponding to the digital domain visible light adversarial sample A1. The fourth processing module is configured to calculate the difference between the average target detection accuracy M1 and the average target detection accuracy M2, and obtain the adversarial index EOCM1 before the adversarial example performance test for the trained target detector D. The fifth processing module is configured to perform a Fourier transform on the digital domain visible light adversarial sample A1 to obtain the Fourier transformed digital domain visible light adversarial sample A2. The sixth processing module is configured to superimpose a transfer function onto the digital domain visible light adversarial sample A2 to obtain the first superposition result A3; specifically, the sixth processing module is configured as follows: Against the adversarial sample A2, the atmospheric turbulence transfer function, aerosol modulation transfer function, diffraction limit transfer function, aberration transfer function, image sensor transfer transfer function, image sensor spatial filtering transfer function, and image sensor temporal filtering transfer function are superimposed to obtain the first superposition result A3; The specific process of superimposing transfer functions is as follows: A3A2×MTF turb ×MTF aero ×MTF diff ×MTF aber ×MTF CCD ×MTF ds ×MTF dt Among them, MTF turb MTF is the atmospheric turbulence transfer function. aero aerosol modulation transfer function; MTF diff The diffraction-limited transfer function; MTF aber MTF is the aberration transfer function. CCD For image sensor transfer function; MTF ds The spatial filtering transfer function for image sensors; MTF dt For image sensor time filtering transfer function; in, Where ν is the angular spatial frequency; λ is the refractive index structure constant; L is the visible light wavelength; L is the path length. in, α is the angular spatial cutoff frequency, and α is the diameter of the aerosol particle; k a k is the absorption coefficient. s The scattering coefficient; in, Let λ be the spatial cutoff frequency of the incoherent optical system, D0 be the effective aperture of the optical system, and λ be the λ value. s f is the center wavelength of incoherent light. x f y These are the spatial frequencies in the horizontal and vertical directions, respectively. Where σ is the standard deviation measured by angle; Where N is the number of bits in the CCD; η is the transfer efficiency; ft is the time frequency; f tc Clock frequency; Where α and β are the spatial angles of the rectangular detector; Where f is the spatial frequency; f0 is the frequency corresponding to 3dB; The seventh processing module is configured to perform an inverse Fourier transform on the first superposition result A3 to obtain the second superposition result A4; The eighth processing module is configured to send the second superposition result A4 into the trained target detector D and record the average target detection accuracy M3 corresponding to the second superposition result A4. The ninth processing module is configured to calculate the difference between the average target detection accuracy M1 and the average target detection accuracy M3, and obtain the adversarial index EOCM2 after adversarial example performance test against the trained target detector D. The tenth processing module is configured to obtain the relative change index of adversarial performance before and after the adversarial sample performance test for the trained target detector based on the adversarial index EOCM1 and the adversarial index EOCM2, so as to determine the adversarial nature of the digital domain visible light adversarial sample A1 based on the adversarial relative change index EOCM1.
6. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps in the digital domain visible light adversarial sample performance testing method according to any one of claims 1 to 4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps in the digital domain visible light adversarial sample performance testing method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Counter attack generation method and system based on loop generation network
CN118194932A