A method, system, storage medium, and terminal for generating adversarial examples

CN119672700BActive Publication Date: 2026-05-26UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
UNIV OF ELECTRONICS SCI & TECH OF CHINA
Filing Date
2024-11-27
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing 3D target detection systems are sensitive to adversarial attacks, which directly damage the integrity of the target object, resulting in poor attack concealment and low efficiency.

Method used

By determining the context region of the target object, dividing it into multiple sub-regions for importance analysis, generating a context attribution map, selecting influential sub-regions and fine-tuning them under the guidance of the total loss function, adversarial examples are generated.

Benefits of technology

It improves the stealth and efficiency of attacks, ensures that counter-disturbances are imperceptible, and enhances the defensive capabilities of the detection model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119672700B_ABST
    Figure CN119672700B_ABST
Patent Text Reader

Abstract

This invention discloses an adversarial example generation method, system, storage medium, and terminal, belonging to the field of adversarial attack technology. The method includes: determining the context region of a target object and dividing it into multiple sub-regions; performing importance analysis on each sub-region; mapping the influence of each sub-region on the detection results of the target detection model to the context region, generating a context attribution graph; selecting one or more influential sub-regions exceeding an influence threshold; and fine-tuning the influential sub-regions under a total loss function (including a loss function and a perceptual loss function) to generate adversarial examples. This invention accurately guides the attack direction through the context attribution graph and introduces a dual loss function, suppressing position, direction, and confidence prediction while ensuring the visual imperceptibility of adversarial perturbations, thus preserving the integrity of the target object and enhancing the stealth of the attack. Attacking only some influential sub-regions improves attack efficiency.
Need to check novelty before this filing date? Find Prior Art