A momentum adversarial attack method and system using adaptive strategy

The momentum adversarial attack method based on an adaptive strategy improves the attack success rate and stability of the black-box model by utilizing an adaptive step-size matrix and momentum model. It solves the problems of insufficient transferability and stability in existing technologies and achieves the optimal convergence rate.

CN119721180BActive Publication Date: 2025-12-05NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411739802.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-29
Publication Date
2025-12-05
Estimated Expiration
2044-11-29

AI Technical Summary

Technical Problem

Existing momentum-based adversarial attack methods have low transferability when facing black-box models, and their attack success rate and stability are not high enough.

Method used

An adaptive momentum adversarial attack method is proposed. By introducing an adaptive step size matrix and momentum model, adversarial examples are generated and attacks are carried out using known white-box models, thereby improving transferability and stability.

Benefits of technology

It effectively improves the mobility and stability of adversarial attacks, achieves the highest attack success rate of existing methods, and has the best convergence rate in general convex cases, filling the gaps in theoretical analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119721180B_ABST
    Figure CN119721180B_ABST
Patent Text Reader

Abstract

The application provides a momentum attack method and system using an adaptive strategy, and the method comprises the following steps: training samples according to selected data; preprocessing the trained samples; selecting a neural network model based on the preprocessed samples to obtain a momentum model; introducing an adaptive step matrix, and obtaining an adversarial sample model according to the momentum model and the adaptive step matrix; and obtaining an adversarial attack success rate according to the adversarial sample model. The application effectively improves the migration and stability of the adversarial attack, and can achieve the highest attack success rate of the existing momentum-based attack method.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of artificial intelligence, in particular to a momentum adversarial attack method and system using an adaptive strategy. BACKGROUND

[0002] Whether it is a convolutional neural network or the current hot spot Transformer network and diffusion model, it is easy to be attacked by an adversarial sample, leading to model prediction errors, thereby restricting the popularization and use of artificial intelligence systems. The current momentum-based adversarial attack method mainly has the following problems: the white-box attack success rate of the adversarial attack method is high, and the black-box attack success rate is low. In other words, the adversarial attack method generally has low transferability, and the existing adversarial attack method has not high enough attack success rate. With the increase of the iteration number of the adversarial attack algorithm, the stability of the attack success rate is also not high enough.

[0003] In summary, the existing technology has the following problems: in the face of a black-box model, the existing momentum-based adversarial attack method has low transferability. SUMMARY

[0004] The purpose of the present application is to solve the problem of how to improve the transferability of the existing momentum adversarial attack method in the face of a black-box model.

[0005] To this end, on the one hand, the present application embodiment provides a momentum adversarial attack method using an adaptive strategy (a momentum adversarial attack method with optimal convergence), which comprises the following steps:

[0006] training samples selected from data;

[0007] preprocessing the trained samples;

[0008] selecting a momentum model based on the preprocessed samples and a neural network model;

[0009] introducing an adaptive step matrix, and obtaining an adversarial sample model according to the momentum model and the adaptive step matrix;

[0010] obtaining an adversarial attack success rate according to the adversarial sample model.

[0011] On the other hand, the present application embodiment also provides a momentum adversarial attack system using an adaptive strategy, which comprises:

[0012] a training unit for training samples selected from data;

[0013] a processing unit for preprocessing the trained samples;

[0014] a calculation unit for selecting a momentum model based on the preprocessed samples and a neural network model;

[0015] a constructing unit, configured to introduce an adaptive step matrix, and obtain an adversarial sample model according to the momentum model and the adaptive step matrix;

[0016] an output unit, configured to obtain an adversarial attack success rate according to the adversarial sample model.

[0017] The technical scheme has the following beneficial effects: the present application effectively improves the migration and stability of the adversarial attack, can achieve the highest attack success rate of the existing momentum-based attack method, and more importantly, proves that the method has the optimal convergence rate in the general convex case, filling the gap in the theoretical analysis of the field. BRIEF DESCRIPTION OF DRAWINGS

[0018] Figure 1 is a flowchart of a momentum adversarial attack method using an adaptive strategy provided by an embodiment of the present application;

[0019] Figure 2 is a structural schematic diagram of a momentum adversarial attack system using an adaptive strategy provided by an embodiment of the present application;

[0020] Figure 3 is an adversarial sample generation and migration attack schematic diagram provided by an embodiment of the present application;

[0021] Figure 4 is a comparison diagram of a momentum adversarial attack method using an adaptive strategy and the convergence of the existing method MI-FGSM in a first implementation manner provided by an embodiment of the present application;

[0022] Figure 5 is a comparison diagram of a momentum adversarial attack method using an adaptive strategy and the convergence of the existing method MI-FGSM in a second implementation manner provided by an embodiment of the present application;

[0023] Figure 6 is a comparison diagram of a momentum adversarial attack method using an adaptive strategy and the convergence of the existing method MI-FGSM in a third implementation manner provided by an embodiment of the present application;

[0024] Figure 7 is a comparison diagram of a momentum adversarial attack method using an adaptive strategy and the convergence of the existing method MI-FGSM in a fourth implementation manner provided by an embodiment of the present application;

[0025] Figure 8 is a comparison diagram of a momentum adversarial attack method using an adaptive strategy and the convergence of the existing method MI-FGSM in a fifth implementation manner provided by an embodiment of the present application;

[0026] Figure 9is a sixth embodiment comparison chart of a momentum adversarial attack method using an adaptive strategy provided by the embodiment of the present application compared with the convergence of the existing method MI-FGSM; DETAILED DESCRIPTION

[0027] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative labor are within the scope of protection of the present application.

[0028] Whether it is a convolutional neural network or the current hot spot Transformer network and diffusion model, it is vulnerable to adversarial samples, leading to model prediction errors, thereby restricting the popularization and use of artificial intelligence systems. Therefore, it is of great significance to study the adversarial attack method existing in deep learning for building a safe and reliable artificial intelligence system. Figure 3 is an adversarial sample generation and transferability attack schematic diagram, which represents the adversarial attack process for image data, which is divided into two stages: one is adversarial sample generation, and the other is black-box transferability attack. Because the hyperparameters of the black-box model are unknown, the second stage is the reason why the success rate of the current adversarial attack method is not high.

[0029] In the embodiments of the present application, as Figure 1 , a momentum adversarial attack method using an adaptive strategy is provided, which comprises the following steps:

[0030] S101: training samples are selected according to the selected data;

[0031] When the device detects that the firmware or software needs to be updated, an update request is started. The device sends an update request message to the remote server through the network, which contains the unique identifier of the device, such as device ID.

[0032] Server response to request: after the server receives the update request, it checks whether the unique identifier of the device is in the list of devices allowed to update.

[0033] If the device is authorized to update, the server selects a challenge information (Challenge) from the pre-stored challenge-response database, and sends the string to the device together with the certificate of the server.

[0034] S102: pre-processing the trained samples;

[0035] S103: selecting a momentum model based on the pre-processed samples and a neural network model;

[0036] S104: introducing an adaptive step size matrix, obtaining an adversarial sample model according to the momentum model and the adaptive step size matrix;

[0037] S105: obtaining an adversarial attack success rate according to the adversarial sample model.

[0038] The momentum model comprises:

[0039]

[0040] Wherein, g t is the accumulated gradient in the previous t iterations, μ t is a momentum coefficient μ t > 0; x adv is an adversarial sample generated by adding noise to the original sample x, and y is the label of the original sample. is a gradient operation at x.

[0041] The adaptive step size matrix is specifically:

[0042]

[0043] Wherein, V t = diag(v t ),

[0044] I is an identity matrix, δ is a constant coefficient, g j is the accumulated gradient in the previous j iterations, and v t is the arithmetic mean of the square of the accumulated gradient g.

[0045] The adversarial sample model comprises:

[0046]

[0047] P is a projection operation, denotes an adversarial sample image generated at the t-th step, denotes an adversarial sample image generated at the t+1-th step; α t is a step size, α t > 0; g t+1 is the accumulated gradient in the previous t+1 iterations.

[0048] Obtaining an adversarial attack success rate according to the adversarial sample model comprises:

[0049] An adversarial sample is generated by using a known white box model, and then the generated adversarial sample is used to attack an unknown black box model, so that a transferable adversarial attack is realized.

[0050] The application also provides a device remote updating device based on PUF security, likeFigure 2 As shown, comprising:

[0051] The training unit 21 is configured to train the selected data sample;

[0052] The processing unit 22 is configured to preprocess the trained sample;

[0053] The computing unit 23 is configured to select a momentum model based on the preprocessed sample and a neural network model;

[0054] The construction unit 24 is configured to introduce an adaptive step matrix, and obtain an adversarial sample model based on the momentum model and the adaptive step matrix;

[0055] The output unit 25 is configured to obtain an adversarial attack success rate based on the adversarial sample model.

[0056] The momentum model comprises:

[0057]

[0058] Wherein, g t is the accumulated gradient in the previous t iterations, μ t is a momentum coefficient μ t > 0; x adv is an adversarial sample generated by adding noise to the original sample x, and y is the label of the original sample. is a gradient operation at x.

[0059] The adaptive step matrix is specifically:

[0060]

[0061] Wherein, V t = diag(v t ),

[0062] I is an identity matrix, δ is a constant coefficient, g j is the accumulated gradient in the previous j iterations, and v t is the arithmetic mean of the square of the accumulated gradient g.

[0063] The adversarial sample model comprises:

[0064]

[0065] P is a projection operation, denotes the adversarial sample image generated in the t-th step, denotes the adversarial sample image generated in the t+1-th step; α t is a step size, and α t > 0; gt+1 is the accumulated gradient in the previous t+1 iteration.

[0066] The output unit comprises:

[0067] The method can generate an adversarial sample by using a known white box model, and then use the generated adversarial sample to attack an unknown black box model, so that a transferable adversarial attack can be realized.

[0068] The method can effectively improve the transferability of the adversarial attack, can achieve the highest attack success rate of the existing momentum-based attack method, and more importantly, proves that the method has the optimal convergence rate in the general convex case, and fills the gap in the theoretical analysis of the field. The adaptive step matrix can be combined with the existing adversarial attack method as a kind of general strategy, and effectively improves the transferability and stability of the black box attack.

[0069] The above technical solutions of the embodiments of the present application will be described in detail below in combination with specific application examples, and the technical details not introduced in the implementation process can be referred to the related description in the foregoing.

[0070] Embodiment 1:

[0071] The present application provides a momentum adversarial attack method using an adaptive strategy, that is, a momentum adversarial attack method with optimal convergence. Adversarial attacks can be divided into targeted attacks and non-targeted attacks, wherein the targeted attack is to generate an adversarial sample to make the model output a specified label, that is, f(x adv )=y * . Here, x adv is an adversarial sample generated by adding noise to the original sample x, y * is the target label specified by the attacker, y is the label of the original sample and y * ≠y. In contrast, the non-targeted attack only needs to satisfy that the generated adversarial sample makes the model output an incorrect label, that is, f(x adv )≠y. In order to ensure the quality of the generated adversarial sample, the added perturbation is usually constrained: ||x adv -x|| p ≤∈.

[0072] The process of generating an adversarial sample is actually a kind of solving a maximization loss problem with constraints.

[0073] max J(x adv , y), s.t. ||x adv -x|| ∞ ≤ε,

[0074] where J(x advy) represents a first-order differentiable loss function.

[0075] In the field of adversarial attack, the momentum-based iterative fast gradient sign method (MI-FGSM) has become the mainstream method. The update rule is described as follows:

[0076]

[0077] where g t is the accumulated gradient in the previous t iterations, and μ is the momentum coefficient. The MI-FGSM method can stabilize the update direction and easily jump over local extreme points due to the addition of the momentum term and the accumulation of historical gradient information. However, research shows that MI-FGSM lacks theoretical analysis in terms of convergence and stability due to the inclusion of the sign gradient operation. To fill this gap, the present application uses the MI-FGSM as an example and uses the adaptive strategy momentum adversarial attack method, namely AdaMI,

[0078]

[0079] It can be seen that the adaptive step matrix is introduced in AdaMI, and the sign gradient operation is no longer included. This method can obtain the desired theoretical convergence result. The specific AdaMI includes the following steps:

[0080] Select experimental data, set a random seed, and extract 1000 training samples.

[0081] Input image sample data x, perform necessary preprocessing work, and reset the image size to 3x224x244;

[0082] Select a neural network model, including a white box model and a black box model. In the following steps, the AdaMI algorithm proposed in the present application will be used to generate adversarial samples using a known white box model, and then these samples will be used to attack other unknown black box models, thereby realizing transferable adversarial attack.

[0083] Initialize the adversarial perturbation ∈, the step size α t > 0, the momentum coefficient μ t > 0, the momentum g0 = 0, and the adaptive step matrix V0 = 0 is initialized. d×d ;

[0084] Calculate the momentum

[0085] Calculate the adaptive step matrix

[0086] Iterative output generated adversarial samples: where P is the projection operation, denotes the adversarial sample image generated at the t-th step, Let represent the adversarial sample image generated in step t+1.

[0087] Calculate the success rate of counterattacks;

[0088] Visualize the output adversarial examples and attack effects;

[0089] This invention proposes a general adaptive strategy that can be combined with current momentum-based adversarial attacks to form new algorithms, such as combining with MI-FGSM to form AdaMI, combining with NI-FGSM to form AdaNI, and combining with PGN to form AdaPGN.

[0090] The evaluation criterion for adversarial example generation is mainly measured by the success rate of adversarial attacks; a higher success rate for black-box attacks indicates better transferability of the adversarial attack method. Furthermore, the quality of an adversarial attack algorithm is primarily represented by its convergence rate.

[0091] To verify the effect, such as Figure 4 , Figure 5 , Figure 6 , Figure 7 , Figure 8 , Figure 9 As shown, this invention selects ILSVRC2012 as the dataset for algorithm verification. Model selection is divided into two main categories: Convolutional Neural Networks (CNNs) and Visual Transformers (ViTs). CNN models include ResNet (Res34) and Inception (Inc_v3), while ViT models include Visformer (Vis_s) and Swin (Swin_s). The effectiveness of adversarial attacks is evaluated using the attack success rate; a higher rate indicates a better attack effect and a more effective attack method. Figure 6 and Figure 7 This demonstrates that as the number of algorithm iterations increases, the adaptive strategy method used in this invention exhibits better stability and can still maintain a high attack success rate, while MI-FGSM shows a decrease in attack success rate.

[0092] As a general strategy, the adaptive strategy can be combined with existing momentum attacks to form new adversarial attack methods, as shown in Table 1. The adaptive strategy proposed in this invention can effectively improve the attack success rate of the corresponding original algorithms. It can be seen that AdaI is better than I-FGSM, AdaMI is better than MI-FGSM, and AdaNI is better than NI-FGSM. Among the new methods generated after combination, AdaPGN has the best attack success rate (transferability) among current momentum-based adversarial attack methods.

[0093] Table 1. Comparison of success rates (%) of momentum attack methods

[0094]

[0095]

[0096] The application effectively improves the migration of the attack, can achieve the highest attack success rate of the existing momentum-based attack method, and more importantly, proves that the method has the optimal convergence rate in the general convex case, fills the gap in the theoretical analysis of the field. The adaptive step matrix proposed in the application can be combined with the existing counter-attack method as a general strategy, effectively improving the migration and stability of the black-box attack.

[0097] It should be understood that the specific order or hierarchy of steps in the processes disclosed should not be taken as a reflection of a preferred order or hierarchy. The specific order or hierarchy of steps in the processes can be re-arranged based on design choices made by the implementer. The accompanying method claims set forth in the appended claims are to be interpreted in accordance with the cause of the steps recited, and not according to the specific order or hierarchy presented in the disclosure.

[0098] In the detailed description above, various features are grouped together in single embodiments for the purpose of streamlining the disclosure. This disclosed approach is not to be interpreted as reflecting an intention that the embodiments of the claimed subject matter require more features than are expressly recited in each claim. Rather, as the appended claims reflect, inventive subject matter lies in fewer than all features of the disclosed embodiments. Thus, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate preferred embodiment.

[0099] The disclosed embodiments are presented for the purpose of enabling any person skilled in the art to practice or use the application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and generic principles defined herein can be applied to other embodiments without departing from the spirit or scope of the disclosure. Thus, the present disclosure is not intended to be limited to the embodiments presented herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0100] The above description includes examples of one or more embodiments. Of course, not all possible combinations of components or methods described above will be employed to make or use the embodiments nor will all of the following described examples necessarily be realized. One of ordinary skill in the art, however, having the benefit of the present description, can understand how to make and use variations of the embodiments under the teachings and concepts described herein. Thus, the embodiments described herein are intended to embrace all such alterations, modifications, and variations that fall within the scope of the appended claims. Furthermore, the terms "comprises", "comprising", "includes", "including", "has", "having" and the like are to be construed open-ended, as "comprising", "including" and "having" are to be interpreted in the same manner as "consisting of", "consisting essentially of" and "substantially consisting of" under 35 U.S.C. § 112, Paragraph 6, as that terminology is interpreted in the context of the specification as a whole. Additionally, the terms "a" and "an" are defined as "one or more" in the context of the specification as a whole.

[0101] Those skilled in the art will further appreciate that the various illustrative logical blocks, modules, and steps described in connection with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans can implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present embodiments.

[0102] The various illustrative logical blocks and modules described in connection with the embodiments disclosed herein can be implemented or performed with a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor can be a microprocessor, but in the alternative, the general purpose processor can be any conventional processor, controller, microcontroller, or state machine. A processor can also be implemented as a combination of computing devices, e.g., a combination of a digital signal processor and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a digital signal processor core, or any other such configuration.

[0103] The steps of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such the processor can read information from, and write information to, the storage medium. In the alternative, the storage medium can be integral to the processor. The processor and the storage medium can reside in an ASIC. The ASIC can reside in a user terminal. In the alternative, the processor and the storage medium can reside as discrete components in a user terminal.

[0104] In one or more exemplary designs, the functions described can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions can be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media include both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. Storage media can be any available media that can be accessed by a general purpose or special purpose computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code means in the form of instructions or data structures and that can be accessed by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor. Also, any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or data

[0105] The above detailed description describes the purpose, technical solutions and advantages of the present application. It should be understood that the above description is only a specific embodiment of the present application and is not intended to limit the scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the scope of the present application.

[0106] This solution will be used in legal situations.

Claims

1. A method of momentum adversarial attack using adaptive strategy, characterized in that, The method comprises the following steps: According to the selected data training sample; The preprocessed sample is trained; Based on the preprocessed sample, a momentum model is obtained by selecting a neural network model; An adaptive step matrix is introduced, and an adversarial sample model is obtained according to the momentum model and the adaptive step matrix; According to the adversarial sample model, the success rate of the adversarial attack is obtained; The adversarial sample model comprises: P is a projection operation, denotes the adversarial sample image generated at the t-th step, denotes the adversarial sample image generated at the t+1-th step; a t is a step size, a t > 0; g t+1 is the accumulated gradient in the first t+1 iterations; According to the adversarial sample model, the success rate of the adversarial attack is obtained, comprising: An unknown white box model is used to generate an adversarial sample, and the generated adversarial sample is used to attack an unknown black box model, so as to realize the transferable adversarial attack.

2. The method of claim 1, wherein the adaptive strategy is used to perform the momentum attack. The momentum model comprises: where g t is the accumulated gradient in the previous t iterations, μ t is the momentum coefficient μ t > 0; x adv is the original sample x through the addition of noise to generate an adversarial sample, y is the label of the original sample, is representative of the gradient operation at x.

3. The method of claim 2, wherein the adaptive strategy is used to generate the momentum attack. The adaptive step matrix is specifically: where V t = diag(v t ), I is the identity matrix, δ is a constant coefficient, g j is the accumulated gradient in the previous j iterations, v t is the arithmetic mean of the square of the accumulated gradient g.

4. A momentum adversarial attack system using adaptive strategies, characterized in that, Comprise: The training unit is used for training the selected data training sample; The processing unit is used for pre-processing the trained sample; The calculation unit is used for obtaining a momentum model based on the pre-processed sample by selecting a neural network model; The construction unit is used for introducing an adaptive step matrix, and obtaining an adversarial sample model according to the momentum model and the adaptive step matrix; The output unit is used for obtaining the success rate of the adversarial attack according to the adversarial sample model; The adversarial sample model; Comprise: P is a projection operation, denotes the adversarial sample image generated at the t-th step, denotes the adversarial sample image generated at the t+1-th step; α t is a step size, α t > 0; g t+1 is the accumulated gradient in the first t+1 iterations; The output unit comprises: An unknown white box model is used to generate an adversarial sample, and the generated adversarial sample is used to attack an unknown black box model, so as to realize the transferable adversarial attack.

5. The momentum adversarial attack system using adaptive strategies of claim 4, wherein, The momentum model comprises: where g t is the accumulated gradient in the previous t iterations, μ t is the momentum coefficient μ t > 0; x adv is the original sample x through the addition of noise generated by the adversarial sample, y is the label of the original sample, is representative of the gradient operation at x.

6. The momentum adversarial attack system using adaptive strategies of claim 5, wherein, The adaptive step matrix is specifically: where V t = diag(v t ), I is the identity matrix, δ is a constant coefficient, g j is the accumulated gradient in the previous j iterations, v t is the arithmetic mean of the square of the accumulated gradient g.

Citation Information

Patent Citations

  • A step size self-adaptive attack resisting method based on model extraction

    CN109948663A

  • Step length calculation method and system suitable for waveform inversion

    CN113552620A