Adversarial Sample Generation Method, Electronic Device
By performing noise processing and importance sampling on image data and gradually updating the noise value, the problem that the adversarial sample generation method in the prior art is easily trapped in local optimal solutions, and more efficient adversarial sample generation is achieved.
Patent Information
- Application Number
- CN202510138852.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-02-08
AI Technical Summary
The method of generating adversarial samples in the prior art is greedy and is prone to fall into local optimal solutions, resulting in poor results in the generated adversarial samples.
By adding noise to the image data, initializing the adversarial samples, and performing importance sampling based on the noise sensitivity of each pixel point, determining the set of important pixel points, gradually updating the noise value until the target adversarial samples are generated.
This method retains more comprehensive exploration space when searching for optimal noise distribution, reduces the possibility of local optimal solutions and improves the efficiency of adversarial sample generation.
Smart Images

Figure CN119580019B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of image processing and machine learning, and more particularly to an adversarial sample generation method and an electronic device. Background Art
[0002] With the rapid development of machine learning technologies such as deep learning, various models have achieved remarkable results in many fields such as image recognition and have been widely applied to practical scenarios. Although machine learning models perform well in the training and testing processes, they may be very sensitive to small changes in the input data. This vulnerability may be maliciously exploited, posing a security threat to systems that rely on these models. Therefore, the research on adversarial samples has emerged. In related technologies, methods such as the Fast Gradient Sign Method (FGSM) are used to generate adversarial samples.
[0003] In the process of implementing the inventive concept of the present invention, it is found that there are at least the following problems in related technologies: The methods in related technologies have a greedy nature and are prone to falling into local optimal solutions, resulting in poor effects of the generated adversarial samples, that is, the computer cannot obtain the required adversarial samples in a small number of calculations. Summary of the Invention
[0004] In view of the above problems, the present invention provides an adversarial sample generation method and an electronic device.
[0005] According to a first aspect of the present invention, an adversarial sample generation method is provided. The method includes: adding noise to image data to obtain an initial adversarial sample; initializing the noise sensitivity of each pixel point on the initial adversarial sample to determine the initial noise sensitivity of each pixel point on the initial adversarial sample; determining a first set of important pixel points from the initial adversarial sample according to the initial noise sensitivity of each pixel point on the initial adversarial sample and the sampling amount; updating the noise values of each pixel point in the first set of important pixel points on the initial adversarial sample to obtain a first adversarial sample; inputting the first adversarial sample into an image classification model to obtain a first classification result; and in the case where the first classification result is different from the label of the image data, using the first adversarial sample as a target adversarial sample.
[0006] According to an embodiment of the present invention, the above method further includes: when the above first classification result is the same as the label of the image data, determining a second set of important pixels from the above initial adversarial sample based on the respective initial noise sensitivities of the respective pixels in the above initial adversarial sample; obtaining a second adversarial sample based on the above second set of important pixels and the above first adversarial sample; inputting the above second adversarial sample into an image classification model to obtain a second classification result; when the second classification result is different from the label of the above image data, using the above second adversarial sample as the above target adversarial sample.
[0007] According to an embodiment of the present invention, the above method further includes: repeating the following operations until the above target adversarial sample is obtained; when the q-th classification result is the same as the label of the above image data, updating the respective noise sensitivities of the respective pixels on the q-th adversarial sample corresponding to the (q - 1)-th set of important pixels, and the respective noise sensitivities of the respective pixels on the q-th adversarial sample corresponding to the q-th set of important pixels, to obtain the respective updated noise sensitivities of the respective pixels on the q-th adversarial sample, where q is an integer greater than or equal to 2; determining the (q + 1)-th set of important pixels from the above initial adversarial sample according to the respective updated noise sensitivities of the respective pixels in the above q-th adversarial sample and the sampling amount; obtaining the (q + 1)-th adversarial sample based on the above (q + 1)-th set of important pixels and the above q-th adversarial sample; inputting the above (q + 1)-th adversarial sample into an image classification model to obtain the (q + 1)-th classification result; when the (q + 1)-th classification result is different from the label of the above image data, using the above (q + 1)-th adversarial sample as the above target adversarial sample.
[0008] According to an embodiment of the present invention, the above updating the respective noise sensitivities of the respective pixels on the q-th adversarial sample corresponding to the (q - 1)-th set of important pixels includes: increasing the respective noise sensitivities of the respective pixels in the above (q - 1)-th set of important pixels according to a first adjustment value.
[0009] According to an embodiment of the present invention, the respective noise sensitivities of the respective pixels on the q-th adversarial sample corresponding to the q-th set of important pixels include: reducing the respective noise sensitivities of the respective pixels in the above q-th set of important pixels according to a second adjustment value; where the above first adjustment value is greater than the above second adjustment value.
[0010] According to an embodiment of the present invention, determining the first set of important pixel points from the above-mentioned initialized adversarial samples according to the respective initialized noise sensitivities and sampling amounts of each pixel point includes: determining sampling points from the above-mentioned initialized adversarial samples; based on the noise sensitivity characterization value of the above-mentioned sampling points and the sum of the noise sensitivities of each pixel point in the above-mentioned initialized adversarial samples, determining the probability that the above-mentioned sampling points are a pixel point in the above-mentioned first set of important pixel points; and when the above-mentioned probability is equal to 1, using the pixel points in the above-mentioned sampling points as the above-mentioned first set of important pixel points.
[0011] According to an embodiment of the present invention, initializing the noise sensitivity of each pixel point on the above-mentioned initialized adversarial sample to determine the initialized noise sensitivity of each pixel point on the above-mentioned initialized adversarial sample includes: when the noise value of a pixel point is 0, determining the noise sensitivity of the pixel point to be 0; when the noise value of a pixel point is not 0, determining the noise sensitivity of the pixel point to be 1.
[0012] According to an embodiment of the present invention, obtaining a second adversarial sample based on the above-mentioned second set of important pixel points and the above-mentioned first adversarial sample includes: superimposing the respective noise values of each pixel point in the above-mentioned second set of important pixel points and the respective pixel values of each pixel point in the above-mentioned first adversarial sample to obtain the above-mentioned second adversarial sample.
[0013] According to an embodiment of the present invention, the above-mentioned method further includes: using the above-mentioned target adversarial sample and the label of the above-mentioned image data to train the image classification model to obtain a target image classification model.
[0014] A second aspect of the present invention provides an electronic device, including: one or more processors; a memory for storing one or more computer programs, wherein the above-mentioned one or more processors execute the above-mentioned one or more computer programs to implement the steps of the above-mentioned method.
[0015] According to an embodiment of the present invention, setting the attribute of noise sensitivity for each pixel point in the image data, and determining the first set of important pixel points from the initialized adversarial samples according to the initialized noise sensitivities and sampling amounts of each pixel point, and retaining the noise of the pixel points that do not belong to each pixel point in the first set of important pixel points can more comprehensively search the exploration space for finding the target adversarial sample when searching for the optimal noise distribution, no longer being limited to local greedy search, reducing the possibility of falling into a local optimal solution during the generation process of the adversarial sample, thereby reducing unnecessary calculations of the computer and improving the efficiency of the computer to generate adversarial samples. Description of the Drawings
[0016] Through the following description of the embodiments of the present invention with reference to the accompanying drawings, the above content and other objects, features, and advantages of the present invention will become clearer.
[0017] Figure 1 The application scenario diagram of the adversarial sample generation method according to an embodiment of the present invention is shown.
[0018] Figure 2 The flowchart of the adversarial sample generation method according to an embodiment of the present invention is shown.
[0019] Figure 3 The overall architecture diagram of the adversarial sample generation method according to an embodiment of the present invention is shown.
[0020] Figure 4 The flowchart of the adversarial sample generation method according to another embodiment of the present invention is shown.
[0021] Figure 5 The comparison diagram of noise results according to an embodiment of the present invention is shown.
[0022] Figure 6 The block diagram of an electronic device suitable for implementing the adversarial sample generation method according to an embodiment of the present invention is shown. Detailed Embodiments
[0023] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present invention. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present invention.
[0024] The terms used herein are merely for describing specific embodiments and are not intended to limit the present invention. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0025] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0026] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning that those skilled in the art usually understand this expression (for example, "a system having at least one of A, B, and C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0027] To improve the generalization ability of a trained image classification model, adversarial samples corresponding to the training samples used to train the image classification model can be generated. In related technologies, the methods for generating adversarial samples usually have a greedy nature and are prone to falling into local optimal solutions, resulting in poor effects of the generated adversarial samples.
[0028] For example, through a determined image classification model F, when judging whether an adversarial sample can be misclassified by the image classification model, it is necessary to call the image classification model to judge the classification result obtained by inputting the adversarial sample into the image classification model. In related technologies, the method for generating adversarial samples attempts to find an adversarial sample with a smaller probability of perturbation, that is, an adversarial sample with less added noise, under the condition of satisfying the budget of the number of calls. It can be understood through formula (1):
[0029] ,s.t. and (1);
[0030] Among them, represents the original image data, represents the adversarial sample, is 's label, is the set of all adversarial samples generated for inputting into the image classification model, is the budget of the frequency of calling the image classification model. refers to the norm used to measure the noise amplitude, including , and norms.
[0031] In related technologies, different mechanisms have been designed to solve the above problems. For example, a mechanism for customizing transformation functions and a mechanism for local modification. However, the above mechanisms can only partially alleviate the situation where the noise compression process falls into local optimality and cannot change the greedy nature in the existing methods.
[0032] This greedy property is attributed to the greedy characteristics of the above process in two aspects: the finiteness of the single-step search range and the overall compression of the entire image. In view of the greedy characteristics in the above two aspects, the present invention proposes an adversarial sample generation method based on adaptive importance sampling. This method limits the noise to pixel positions with less impact on the classification result during the noise compression process by modeling and updating the noise sensitivity at each pixel position.
[0033] An embodiment of the present invention provides an adversarial sample generation method, including: adding noise to image data to obtain an initial adversarial sample; initializing the noise sensitivity of each pixel point on the initial adversarial sample to determine the initial noise sensitivity of each pixel point on the initial adversarial sample; determining a set of first important pixel points from the initial adversarial sample according to the initial noise sensitivity of each pixel point on the initial adversarial sample and the sampling amount; updating the noise value of each pixel point in the set of first important pixel points on the initial adversarial sample to obtain a first adversarial sample; inputting the first adversarial sample into an image classification model to obtain a first classification result; and taking the first adversarial sample as a target adversarial sample when the first classification result is different from the label of the image data.
[0034] Figure 1 FIG. shows an application scenario diagram of the adversarial sample generation method according to an embodiment of the present invention.
[0035] As Figure 1 shown, the application scenario according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0036] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 through the network 104 to receive or send data, etc. Various communication client applications, such as web browser applications, search applications, instant messaging tools, etc. (only for example), may be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103.
[0037] The first terminal device 101, the second terminal device 102, and the third terminal device 103 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0038] Server 105 may be a server that provides various services. For example, it can be a background management server (merely an example) that supports the websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server can analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0039] It should be noted that the adversarial sample generation method provided in the embodiments of the present invention can generally be executed by server 105. The adversarial sample generation method provided in the embodiments of the present invention can also be executed by a server or a server cluster that is different from server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0040] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in
[0041] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figures 2 to 5 Based on the scenarios described below, the adversarial sample generation method of the embodiments of the present invention will be described in detail through
[0042] Figure 2 shows a flowchart of the adversarial sample generation method according to the embodiments of the present invention.
[0043] As Figure 2 shown, the adversarial sample generation method of this embodiment includes operations S210 to S260.
[0044] In operation S210, noise is added to the image data to obtain an initialized adversarial sample.
[0045] In operation S220, the noise sensitivity of each pixel point on the initialized adversarial sample is initialized to determine the initialized noise sensitivity of each pixel point on the initialized adversarial sample.
[0046] In operation S230, according to the initialized noise sensitivity of each pixel point on the initialized adversarial sample and the sampling amount, a set of first important pixel points is determined from the initialized adversarial sample.
[0047] In operation S240, the noise values of each pixel point in the set of first important pixel points on the initialized adversarial sample are updated to obtain a first adversarial sample.
[0048] In operation S250, the first adversarial sample is input into the image classification model to obtain a first classification result.
[0049] In operation S260, when the first classification result is different from the label of the image data, the first adversarial sample is used as the target adversarial sample. According to an embodiment of the present invention, the image data is data for which a correct image classification result is obtained using an image classification model. For example, the image data can be training samples used during the model training process before obtaining the image classification model.
[0050] According to an embodiment of the present invention, noise is randomly added to the image data. For example, random noise can be generated for the image data according to a Gaussian distribution to add the noise to the image data to obtain an initialized adversarial sample.
[0051] According to an embodiment of the present invention, the noise sensitivity of a pixel point characterizes the sensitivity of the image classification model to noise interference on the pixel points in the image data, and is used to reflect the stability and reliability of the classification result of the image classification model when facing local pixel changes.
[0052] According to an embodiment of the present invention, during the initialization process of the noise sensitivity of each pixel point on the initialized adversarial sample, the noise sensitivity of each pixel point can be initialized according to the noise value of each pixel point on the initialized adversarial sample to determine the initialization sensitivity of each pixel point, where the noise value of the pixel point is the pixel value added to the pixel point, and the value range of the noise value can be [0, 255]. Specifically, one or more preset noise thresholds can be set, and the noise sensitivity of each pixel point is initialized according to the relationship between the noise value of each pixel point on the initial adversarial sample and the one or more preset noise thresholds.
[0053] For example, the preset noise thresholds include 125 and 200. When the noise value of the pixel point is in the range of [0, 125], the noise sensitivity of the pixel point is initialized to 100; when the noise value of the pixel point is in the range of [125, 200], the noise sensitivity of the pixel point is initialized to 200; when the noise value of the pixel point is in the range of [200, 255], the noise sensitivity of the pixel point is initialized to 300.
[0054] According to an embodiment of the present invention, the sampling amount is a fixed value set based on expert experience or historical experimental records. Preferably, the sampling amount can be one-tenth of the product of the total number of pixel points and the number of channels of the image data. Using the respective initialization noise sensitivities and the sampling amount of each pixel point, a set of first importance pixel points is determined from the pixel points with the highest initialization noise sensitivities among the first sampling amount of pixel points.
[0055] For example, if the sampling amount is 2, and the initial noise sensitivities of pixel point 1 and pixel point 2 are greater than those of other pixel points, and the initial noise sensitivity of pixel point 1 is greater than that of pixel point 2, then the first set of important pixel points may be pixel point 1, and the first set of important pixel points may be pixel point 1. The value of the sampling amount here, i.e., "the sampling amount is 2", is only a schematic example for easy explanation, and "2" is not a value commonly used in actual applications.
[0056] According to an embodiment of the present invention, the noise values of the pixel points belonging to the first set of important pixel points on the initialized adversarial sample are set to 0 to update the noise values of the respective pixel points, thereby obtaining the first adversarial sample. The pixel values of the pixel points in the first set of important pixel points on the obtained first adversarial sample are the same as the pixel values of the pixel points in the first set of important pixel points on the image data.
[0057] According to an embodiment of the present invention, the noise values of the pixel points in the first set of important pixel points on the initialized adversarial sample can be updated by formula (2):
[0058] (2);
[0059] Wherein, represents the noise value of the pixel point at the position of ( ); represents the first set of important pixel points; represents the noise value of the pixel point at the position of ( ) after update.
[0060] According to an embodiment of the present invention, the first adversarial sample is input into the image classification model to verify whether the noise on the first adversarial sample will affect the output result of the image classification model, and a first classification result is obtained. The first classification result may be the type of object included in the first adversarial sample, for example, animals, plants, etc., or, for example, houses, cats, people, etc.
[0061] According to an embodiment of the present invention, the first classification result is different from the label of the image data. For example, the label of the image data is a house, but the first classification result is a tree. Then the first classification result is different from the label of the image data. In this case, it indicates that the noise on the first adversarial sample can cause the image classification model to fail in classification, and then the first adversarial sample can be used as the target adversarial sample.
[0062] According to an embodiment of the present invention, an attribute of noise sensitivity is set for each pixel point in the image data, and based on the respective initialized noise sensitivities and sampling amounts of each pixel point, a set of first important pixel points is determined from the initialized adversarial samples, and only the noise that does not belong to each pixel point in the set of first important pixel points is retained, which can more comprehensively search for the exploration space of the target adversarial sample when searching for the optimal noise distribution, no longer being limited to local greedy search, reducing the possibility of falling into a local optimal solution during the generation process of the adversarial sample, thereby reducing unnecessary calculations of the computer and improving the efficiency of the computer in generating adversarial samples.
[0063] According to an embodiment of the present invention, the adversarial sample generation method further includes: when the first classification result is the same as the label of the image data, based on the respective initialized noise sensitivities of each pixel point in the initialized adversarial sample, determining a set of second important pixel points from the initialized adversarial sample; obtaining a second adversarial sample based on the set of second important pixel points and the first adversarial sample; inputting the second adversarial sample into the image classification model to obtain a second classification result; when the second classification result is different from the label of the image data, using the second adversarial sample as the target adversarial sample.
[0064] According to an embodiment of the present invention, that the first classification result is the same as the label of the image data indicates that the set of first important pixel points may include pixel points that are more sensitive to noise interference in the image classification model.
[0065] According to an embodiment of the present invention, the pixel points included in the set of second important pixel points are generally not completely the same as the pixel points included in the set of first important pixel points. Specifically, the number of pixel points in the set of second important pixel points is greater than the number of pixel points in the set of first important pixel points.
[0066] For example, when the set of first important pixel points includes pixel point 1, pixel point 2, and pixel point 14, the set of second important pixel points may include pixel point 1, pixel point 2, pixel point 14, pixel point 8, pixel point 10, and pixel point 37.
[0067] According to an embodiment of the present invention, a preset sorting algorithm is used to sort the initialized noise sensitivities of each pixel point in the initialized adversarial sample, so as to select the pixel points with a higher initialized sensitivity and a number of sampling amounts from the initialized noise sensitivities of each pixel point in the initialized adversarial sample to construct the set of second important pixel points. The preset sorting algorithm is one of the following algorithms: bubble sort, selection sort, etc.
[0068] For example, when the first adversarial sample includes 1 to 2000 pixel points, based on a preset sorting algorithm, the initial noise sensitivities of the pixel points in the first adversarial sample from high to low are: pixel point 1, pixel point 2, pixel point 3... pixel point 2000. Among them, the sampling quantity is 200, then the second important pixel points are pixel point 1, pixel point 2, pixel point 3... pixel point 200.
[0069] In the actual application process, there may be a situation where the noise sensitivities of multiple pixel points are the same. At this time, it is determined only based on the sorting result of the preset algorithm, ignoring whether their actual noise sensitivities are the same. For example, although the initial noise sensitivities of pixel point 200 and pixel point 201 are the same, however, the sorting result of the preset sorting algorithm makes pixel point 200 before pixel point 201, then it is determined that pixel point 200 belongs to the second important pixel points, and pixel point 201 does not belong to the second important pixel points.
[0070] According to an embodiment of the present invention, noise enhancement is performed on the noise of each pixel point corresponding to the second important pixel points on the first adversarial sample to obtain a second adversarial sample. Specifically, a fixed pixel value or a random pixel value can be added to each pixel point corresponding to the second important pixel points on the first adversarial sample to obtain a second adversarial sample.
[0071] For example, when the first adversarial sample includes 1 to 2000 pixel points and the second important pixel points are pixel point 1, pixel point 2, pixel point 3... pixel point 200, a pixel value of any fixed value from 1 to 255, or a pixel value of any value from 1 to 255 can be added to pixel point 1, pixel point 2, pixel point 3... pixel point 200 of the first adversarial sample to obtain a second adversarial sample.
[0072] According to an embodiment of the present invention, the second adversarial sample is input into an image classification model to verify whether the noise on the second adversarial sample will affect the output result of the image classification model, and a second classification result is obtained. The second classification result is different from the label of the image data, that is, the image classification model cannot correctly classify the second adversarial sample, so the second adversarial sample can be used as a target adversarial sample.
[0073] According to an embodiment of the present invention, when the first classification result is the same as the label of the image data, it indicates that the first set of important pixels may contain pixel points that have a greater impact on the output result of the image classification model. Based on the initial noise sensitivity of each pixel point in the initial adversarial sample, a second set of important pixel points is determined from the initial adversarial sample to obtain each pixel point with a higher sensitivity to noise interference of the image classification model. The noise of each pixel point corresponding to the second set of important pixel points on the first adversarial sample is increased to obtain a second adversarial sample with increased noise, thereby increasing the probability of misclassification of the image classification model, reducing the probability of the computer continuing to execute subsequent operations, and improving the efficiency of the computer to obtain the target adversarial sample.
[0074] According to an embodiment of the present invention, the adversarial sample method further includes: repeating the following operations until the target adversarial sample is obtained; when the q-th classification result is the same as the label of the image data, updating the respective noise sensitivities of each pixel point corresponding to the (q - 1)-th set of important pixel points on the q-th adversarial sample and the respective noise sensitivities of each pixel point corresponding to the q-th set of important pixel points on the q-th adversarial sample to obtain the respective updated noise sensitivities of each pixel point on the q-th adversarial sample, where q is an integer greater than or equal to 2; determining the (q + 1)-th set of important pixel points from the initial adversarial sample according to the respective updated noise sensitivities of each pixel point on the q-th adversarial sample and the sampling amount; obtaining the (q + 1)-th adversarial sample based on the (q + 1)-th set of important pixel points and the q-th adversarial sample; inputting the (q + 1)-th adversarial sample into the image classification model to obtain the (q + 1)-th classification result; when the (q + 1)-th classification result is different from the label of the image data, using the (q + 1)-th adversarial sample as the target adversarial sample.
[0075] According to an embodiment of the present invention, the q-th classification result is the same as the label of the image data, that is, the image classification model can correctly identify the q-th adversarial sample.
[0076] According to an embodiment of the present invention, the noise sensitivity of each pixel point in the (q - 1)-th set of important pixel points is increased, and the noise sensitivity of each pixel point in the q-th set of important pixel points is reduced to enhance the noise sensitivity of the pixel points in the (q - 1)-th set of important pixel points that have a greater impact on the image classification model, thereby obtaining the respective updated noise sensitivities of each pixel point.
[0077] According to an embodiment of the present invention, according to the respective updated noise sensitivities of each pixel point, pixel points with a larger number of sampling amounts of updated noise sensitivity are determined from the initial adversarial sample to form the (q + 1)-th set of important pixel points.
[0078] According to an embodiment of the present invention, on the q-th adversarial sample, the noise value corresponding to each pixel in the (q + 1)-th set of important pixels is increased to obtain the (q + 1)-th adversarial sample, where the noise value corresponding to each pixel added can be the noise value corresponding to each pixel in the (q + 1)-th set of important pixels in the initial adversarial sample.
[0079] According to an embodiment of the present invention, the (q + 1)-th adversarial sample is input into an image classification model to obtain the (q + 1)-th classification result until the (q + 1)-th classification result is different from the label of the image data, so as to use the (q + 1)-th adversarial sample as the target adversarial sample.
[0080] According to an embodiment of the present invention, by updating the noise sensitivity of each element, the noise of each pixel on the image data is adaptively adjusted, increasing the probability that the computer obtains the target adversarial sample, thereby improving the processing efficiency of the computer.
[0081] According to an embodiment of the present invention, the adversarial sample generation method further includes setting a maximum number of iterations. In the case where the maximum number of iterations is reached and the target adversarial sample is not obtained, the image data can be selected to be replaced, and the operation of obtaining the target adversarial sample is performed based on the replaced image data, so as to further reduce the ineffective calculations of the computer and improve the efficiency of the computer in obtaining the target adversarial sample.
[0082] Figure 3 Fig. shows the overall architecture diagram of the adversarial sample generation method according to an embodiment of the present invention.
[0083] As Figure 3 shown, according to the initialized initial noise the noise sensitivity of each pixel in the image data x is initialized. The first set of important pixels is determined according to the noise sensitivity and the sampling amount, that is, importance sampling is performed to obtain S C . Each pixel in the first set of important pixels is highlighted with a circle. Then, noise compression is performed according to the sampled first set of important pixels, that is, the noise value of each pixel in the first set of important pixels on the initialized adversarial sample is updated to obtain the compressed noise .
[0084] After adding the compressed noise to the image data x, the first adversarial sample x+ is obtained. After inputting the first adversarial sample x+ into the image classification model, the first classification result is obtained, and it is judged whether the first classification result Whether it is the same as the label y of the image data x. In the case where the first classification result is not the same as the label of the image data, that is, in the case of "yes" in the figure, set the noise sensitivity of each pixel corresponding to the first set of important pixels in the first adversarial sample to 0.
[0085] In the case where the first classification result is the same as the label of the image data, that is, in the case of "no" in the figure, backtracking will be performed. During backtracking, select the first N S pixel points with a high amount of pre-sampled noise sensitivity, and obtain the set S TOP , that is, the second set of important pixels (highlighted with circles), and increase the noise of each pixel in the second set of important pixels to construct the updated noise .
[0086] After adding the updated noise to the image data x, the second adversarial sample x+ is obtained. After inputting the second adversarial sample x+ into the image classification model, the second classification result is obtained, and it is judged whether the second classification result is the same as the label y of the image data x. In the case where the second classification result is not the same as the label of the image data, that is, in the case of "yes" in the figure, set the noise sensitivity of each pixel corresponding to the second set of important pixels in the second adversarial sample to 0.
[0087] In the case where the second classification result is the same as the label of the image data, that is, in the case of "no" in the figure, the noise sensitivity TS will be adaptively further updated to enter the subsequent loop process until the loop reaches the preset number of loop times. By gradually updating the noise sensitivity of each pixel, the possibility of falling into the local optimal solution is effectively reduced, so as to reduce the amount of noise added to the original image.
[0088] According to an embodiment of the present invention, updating the noise sensitivity of each pixel in the (q - 1)-th set of important pixels includes: increasing the noise sensitivity of each pixel in the (q - 1)-th set of important pixels according to the first adjustment value.
[0089] According to an embodiment of the present invention, the first adjustment value is a value greater than 0, and the first adjustment value is determined based on expert experience or historical experimental data. The first adjustment value can be , where is the number of pixel points of the image data in the width direction, is the number of pixel points of the image data in the height direction, is the number of channels of the image data, and Increase the noise sensitivity of each pixel in the set of the (q - 1)-th most important pixels.
[0090] According to an embodiment of the present invention, in the case where the image data has multiple channels, the meaning represented by the pixel herein is the point located at the position of ( ), where is greater than 0 and less than or equal to ; is greater than 0 and less than or equal to ; is greater than 0 and less than or equal to .
[0091] According to an embodiment of the present invention, by increasing the noise sensitivity of each pixel in the set of the (q - 1)-th most important pixels, the noise sensitivity of each pixel in the set of the (q - 1)-th most important pixels is improved, providing a reference for subsequent determination of the set of the (q + 1)-th most important pixels, reducing the number of iterations, and obtaining the target adversarial sample at a lower computational cost.
[0092] According to an embodiment of the present invention, updating the noise sensitivity of each pixel in the set of the q-th most important pixels includes: reducing the noise sensitivity of each pixel in the set of the q-th most important pixels according to a second adjustment value; wherein the first adjustment value is greater than the second adjustment value.
[0093] According to an embodiment of the present invention, the second adjustment value is a value greater than 0 and less than the first adjustment value, and the second adjustment value is determined based on expert experience or historical experimental data. The second adjustment value can be , and is used to reduce the noise sensitivity of each pixel in the set of the q-th most important pixels.
[0094] According to an embodiment of the present invention, by reducing the noise sensitivity of each pixel in the set of the q-th most important pixels, the noise sensitivity of each pixel in the set of the q-th most important pixels is reduced, providing a reference for subsequent determination of the set of the (q + 1)-th most important pixels, reducing the number of iterations, and enabling the computer to obtain the target adversarial sample at a lower computational cost.
[0095] According to an embodiment of the present invention, by restricting the relative magnitude between the first adjustment value and the second adjustment value, the possibility of the noise sensitivity being a negative value is reduced, thereby reducing the resource waste caused by the presence of negative values in the data during the computer processing.
[0096] According to an embodiment of the present invention, a first set of important pixels is determined from the initialized adversarial sample according to the respective initialization noise sensitivities and sampling amounts of each pixel, including: determining sampling points from the initialized adversarial sample; determining the probability that a sampling point is a pixel in the first set of important pixels based on the noise sensitivity characterization value of the sampling point and the sum of the noise sensitivities of each pixel in the initialized adversarial sample; and in the case where the probability is equal to 1, taking the pixels in the sampling points as the first set of important pixels.
[0097] According to an embodiment of the present invention, the sampling points may be sampled pixels. The sampling points may represent the pixels selected during the importance sampling process. The noise sensitivity characterization value may be the product of the noise sensitivity of the sampling point and the sampling amount. Based on the noise sensitivity characterization value of the sampling point, a ratio is made with the sum of the noise sensitivities of each pixel in the initialized adversarial sample to determine the probability that the pixel belongs to the first set of important pixels.
[0098] According to an embodiment of the present invention, the probability that a sampling point is a pixel in the first set of important pixels may also be determined by formula (3):
[0099] (3);
[0100] Wherein, represents the sampling point at the position of ( ); represents the first set of important pixels; represents the sampling amount; represents the noise sensitivity of the pixel at the position of (w, h, c); , , is a free variable, is at the position of ( , , ) the noise sensitivity of the pixel.
[0101] According to an embodiment of the present invention, a first set of important pixels is determined from the initialized adversarial sample according to the respective initialization noise sensitivities and sampling amounts of each pixel, and the number of pixels in the first set of important pixels is controlled by the sampling amount to reasonably perform noise compression on the first set of important pixels, reducing the probability of potential local optimal solutions that may be caused by performing noise compression on the entire image.
[0102] According to an embodiment of the present invention, the noise sensitivities of each pixel point on the initialized adversarial sample are initialized, and the initialized noise sensitivities of each pixel point on the initialized adversarial sample are determined. Specifically, when the noise value of a pixel point is 0, the noise sensitivity of the pixel point can be determined as the first initial sensitivity; when the noise value of the pixel point is not 0, the noise sensitivity of the pixel point is determined as the second initial sensitivity, where the second initial sensitivity is less than the second initial sensitivity.
[0103] According to an embodiment of the present invention, initializing the noise sensitivities of each pixel point on the initialized adversarial sample to determine the initialized noise sensitivities of each pixel point includes: for each pixel point, when the noise value of the pixel point is 0, the noise sensitivity of the pixel point is determined as 0; when the noise value of the pixel point is not 0, the noise sensitivity of the pixel point is determined as 1.
[0104] According to an embodiment of the present invention, the noise sensitivities of each pixel point on the initialized adversarial sample are initialized to determine the initialized noise sensitivities of each pixel point, which can be determined by formula (4):
[0105] (4);
[0106] where is the noise value of the pixel point at the position ( ) in the initialized adversarial sample.
[0107] According to an embodiment of the present invention, since the noise sensitivity of a pixel point characterizes the sensitivity of the image classification model to noise interference of pixel points in image data, therefore, the noise sensitivity is initialized using the noise value of the pixel point to pre-identify the pixel points with added noise and the pixel points without added noise using the noise sensitivity. When generating adversarial samples subsequently, pixel points that have a greater impact on the model can be screened out for key processing, avoiding calculations on a large number of insignificant pixels, thereby significantly reducing the computational amount.
[0108] According to an embodiment of the present invention, obtaining a second adversarial sample based on the second set of important pixel points and the first adversarial sample includes: superimposing the noise values of each pixel point in the second set of important pixel points and the pixel values of each pixel point in the first adversarial sample to obtain the second adversarial sample.
[0109] According to an embodiment of the present invention, in the first adversarial sample, a noise value is added to the pixel corresponding to each pixel in the second set of important pixels to construct a second adversarial sample. Since the first classification result is the same as the label of the image data, it indicates that the first set of important pixels may contain pixels that have a greater impact on the output result of the image classification model. The first set of important pixels may include multiple pixels that have a smaller impact on the output result of the image classification model. Therefore, by adding a noise value to the pixel corresponding to each pixel in the second set of important pixels, it is possible to add noise only to the pixels with a higher current noise sensitivity, so as to improve the sample strength of the second adversarial sample and increase the possibility of misclassification by the image classification model, thereby improving the efficiency of the computer to obtain the target adversarial sample.
[0110] Figure 4 FIG. shows a flowchart of an adversarial sample generation method according to another embodiment of the present invention.
[0111] As Figure 4 shown, the adversarial sample generation method of this embodiment includes operations S401 to S412.
[0112] In operation S401, noise is added to the image data to obtain an initial adversarial sample.
[0113] In operation S402, the noise sensitivity of each pixel on the initial adversarial sample is initialized to determine the noise sensitivity of each pixel in the first round.
[0114] In operation S403, according to the noise sensitivity of each pixel in the nth round and the sampling amount, the set of first important pixels in the nth round is determined from the initial adversarial sample or the second adversarial sample in the nth round, where n is an integer greater than or equal to 1.
[0115] In operation S404, the noise value of each pixel in the set of first important pixels in the nth round on the initial adversarial sample or the second adversarial sample in the nth round is updated to obtain the first adversarial sample in the nth round.
[0116] In operation S405, the first adversarial sample in the nth round is input into the image classification model to obtain the first classification result in the nth round.
[0117] In operation S406, it is determined whether the first classification result in the nth round is the same as the label of the image data.
[0118] When the first classification result in the nth round is the same as the label of the image data, operation S407 is executed; otherwise, operation S412 is executed.
[0119] In operation S407, based on the noise sensitivities of the respective pixel points in the n-th round, determine the set of second-importance pixel points from the initialized adversarial sample.
[0120] In operation S408, based on the set of second-importance pixel points in the n-th round and the first adversarial sample in the n-th round, obtain the second adversarial sample in the n-th round.
[0121] In operation S409, input the second adversarial sample in the n-th round into the image classification model to obtain the second classification result in the n-th round.
[0122] In operation S410, determine whether the second classification result in the n-th round is the same as the label of the image data.
[0123] When the second classification result in the n-th round is the same as the label of the image data, perform the operation in operation S411; otherwise, perform operation S412.
[0124] In operation S411, update the noise sensitivities of the respective pixel points in the set of first-importance pixel points and the set of second-importance pixel points in the n-th round to obtain the updated noise sensitivities of the respective pixel points in the n-th round.
[0125] Specifically, increase the noise sensitivities of the respective pixel points in the set of first-importance pixel points according to the first adjustment value. Decrease the noise sensitivities of the respective pixel points in the set of second-importance pixel points according to the second adjustment value; wherein, the first adjustment value is greater than the second adjustment value.
[0126] In operation S412, use the first adversarial sample in the n-th round or the second adversarial sample in the n-th round as the target adversarial sample.
[0127] According to an embodiment of the present invention, during the loop process, the noise sensitivity will gradually become accurate along with noise compression and the judgment of the first classification result or the second classification result and the label. Under the guidance of the noise sensitivity, with adaptive importance sampling, continuously select the least sensitive elements for noise compression until the budget of the iterative loop is exhausted.
[0128] According to an embodiment of the present invention, effectively reduce the possibility of falling into a local optimal solution by gradually updating the noise sensitivities of the respective pixel points. During the judgment process of the first classification result or the second classification result and the label, adaptively allocate multiple pixel points belonging to the set of first-importance pixel points according to the noise sensitivity of each pixel point, and perform noise compression on the multiple pixel points in the set of first-importance pixel points. Compared with the method of generating adversarial samples in the related art, the possibility of noise compression falling into a local optimal solution is significantly reduced.
[0129] According to an embodiment of the present invention, the adversarial sample generation method further includes: training an image classification model using the target adversarial sample and the label of the image data to obtain a target image classification model.
[0130] With the development of deep learning technology, neural networks have achieved great success in fields such as image classification and object detection. During the process of classifying images based on neural network models, it is found that the accuracy of image classification results cannot be further improved only based on the training samples used in related technologies. For example, when encountering images that are slightly different from the training samples, such as noise, deformation, occlusion, etc., the neural network model cannot accurately classify. Therefore, the image classification model can be trained using the target adversarial sample and the label of the image data, calculating the loss using the cross-entropy loss function, and updating the model parameters using an optimizer, so as to obtain a target image classification model and improve the generalization ability of the image separation model.
[0131] Figure 5 A comparison graph of noise results according to an embodiment of the present invention is shown.
[0132] As Figure 5 shown, three kinds of image data are shown , the adversarial noise generated by corresponding to each of the three kinds of image data x, the noise sensitivity records corresponding to each of the three kinds of image data x based on the adversarial sample generation method of the present embodiment , the noise generated corresponding to each of the three kinds of image data x based on the adversarial sample generation method of the present embodiment and the noise generated corresponding to each of the three kinds of image data x based on the boundary adversarial sample generation method . The image data x comes from a publicly available training image set. Among them, the maximum number of times that the adversarial sample can be input into the image classification model to determine whether the classification result is the same as the label of the image data is 1000.
[0133] The experimental results show that under a limited query budget, the present invention has a high adversarial sample generation efficiency.
[0134] Figure 6 A block diagram of an electronic device suitable for implementing the adversarial sample generation method according to an embodiment of the present invention is shown.
[0135] As Figure 6As shown, an electronic device according to an embodiment of the present invention includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603. The processor 601 can include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application-specific integrated circuit (ASIC)), etc. The processor 601 can also include on-board memory for caching purposes. The processor 601 can include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.
[0136] In the RAM 603, various programs and data required for the operation of the electronic device 600 are stored. The processor 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. The processor 601 performs various operations of the method flow according to an embodiment of the present invention by executing programs in the ROM 602 and / or the RAM 603. It should be noted that the program can also be stored in one or more memories other than the ROM 602 and the RAM 603. The processor 601 can also perform various operations of the method flow according to an embodiment of the present invention by executing programs stored in the one or more memories.
[0137] According to an embodiment of the present invention, the electronic device 600 may further include an input / output (I / O) interface 605, and the input / output (I / O) interface 605 is also connected to the bus 604. The electronic device 600 may further include one or more of the following components connected to the input / output (I / O) interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read from it can be installed into the storage section 608 as needed.
[0138] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist alone without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiments of the present invention is implemented.
[0139] According to an embodiment of the present invention, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present invention, the computer-readable storage medium may include the above-described ROM 602 and / or RAM 603 and / or one or more memories other than ROM 602 and RAM 603.
[0140] An embodiment of the present invention further includes a computer program product, which includes a computer program, and the computer program contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the adversarial sample generation method provided by the embodiments of the present invention.
[0141] When the computer program is executed by the processor 601, the above functions defined in the system / apparatus of the embodiments of the present invention are executed. According to an embodiment of the present invention, the above-described systems, apparatuses, modules, units, etc. may be implemented by computer program modules.
[0142] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 609, and / or be installed from the removable medium 611. The program code contained in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0143] In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the processor 601, the above-described functions defined in the system of the embodiments of the present invention are performed. According to an embodiment of the present invention, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0144] According to an embodiment of the present invention, program code for executing the computer program provided by the embodiments of the present invention can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0145] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0146] Those skilled in the art can understand that the features described in the various embodiments of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features described in the various embodiments of the present invention can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.
[0147] The embodiments of the present invention have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. Without departing from the scope of the present invention, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present invention.
Claims
1. A method for generating adversarial samples, characterized in that: The method comprises: Add noise to the image data to obtain an initialized adversarial sample; Initializing the noise sensitivity of each pixel point on the initialized adversarial sample, and determining the initialization noise sensitivity of each pixel point on the initialized adversarial sample; Determine a first set of important pixels from the initialized adversarial sample according to the initialization noise sensitivity and sampling amount of each pixel on the initialized adversarial sample; Updating the noise value of each pixel in the first important pixel set on the initialized adversarial sample to obtain a first adversarial sample; Inputting the first adversarial sample into an image classification model to obtain a first classification result; When the first classification result is different from the label of the image data, using the first adversarial sample as a target adversarial sample; The method further comprises: In a case where the first classification result is the same as the label of the image data, determining a second set of important pixels from the initialized adversarial sample based on the initialization noise sensitivity of each pixel in the initialized adversarial sample; Obtaining a second adversarial sample based on the second important pixel set and the first adversarial sample; Inputting the second adversarial sample into the image classification model to obtain a second classification result; When the second classification result is different from the label of the image data, the second adversarial sample is used as the target adversarial sample.
2. The method according to claim 1, characterized in that The method further comprises: Repeat the following steps until the target adversarial sample is obtained. When the qth classification result is the same as the label of the image data, updating the noise sensitivity of each pixel corresponding to the q-1th important pixel set on the qth adversarial sample and the noise sensitivity of each pixel corresponding to the qth important pixel set on the qth adversarial sample to obtain the updated noise sensitivity of each pixel on the qth adversarial sample, where q is an integer greater than or equal to 2; Determine the q+1th important pixel set from the initialized adversarial sample according to the update noise sensitivity and sampling amount of each pixel on the qth adversarial sample; Based on the q+1th important pixel point set and the qth adversarial sample, obtain the q+1th adversarial sample; Inputting the q+1th adversarial sample into the image classification model to obtain the q+1th classification result; When the q+1th classification result is different from the label of the image data, the q+1th adversarial sample is used as the target adversarial sample.
3. The method according to claim 2, characterized in that The updating of the noise sensitivity of each pixel in the q-1th important pixel set includes: The noise sensitivity of each pixel in the q-1th important pixel set is increased according to the first adjustment value.
4. The method according to claim 3, characterized in that: The updating of the noise sensitivity of each pixel in the qth important pixel set includes: Reducing the noise sensitivity of each pixel in the qth important pixel set according to the second adjustment value; Wherein, the first adjustment value is greater than the second adjustment value.
5. The method according to claim 1, characterized in that The determining a first set of important pixel points from the initialized adversarial samples according to the respective initialized noise sensitivities and sampling amounts of the respective pixel points comprises: Determining a sampling point from the initialized adversarial sample; Determine, based on the sum of the noise sensitivity representation value of the sampling point and the noise sensitivity of each pixel in the initialization adversarial sample, the probability that the sampling point is a pixel in the first important pixel set; and When the probability is equal to 1, the pixel points of the sampling point are taken as the first important pixel point set.
6. The method according to claim 1, characterized in that Initializing the noise sensitivity of each pixel point on the initialized adversarial sample to determine the initialization noise sensitivity of each pixel point on the initialized adversarial sample includes: For each pixel: When the noise value of the pixel point is 0, the noise sensitivity of the pixel point is determined to be 0; When the noise value of the pixel point is not 0, the noise sensitivity of the pixel point is determined to be 1.
7. The method according to claim 1, characterized in that The obtaining a second adversarial sample based on the second important pixel point set and the first adversarial sample includes: The noise value of each pixel in the second important pixel set and the pixel value of each pixel in the first adversarial sample are superimposed to obtain the second adversarial sample.
8. The method according to claim 1, characterized in that The method further comprises: The image classification model is trained using the target adversarial sample and the label of the image data to obtain a target image classification model.
9. An electronic device, comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Pixel point guided black box attack method and device
CN119250158A