Attention disturbance-based confrontation sample generation method, system and device, and medium

By evaluating and processing the class activation graph matrix of deep learning models, the adversarial samples with attention disturbance are generated, which solves the problem of poor transferability of adversarial samples in the prior art, and achieves higher transferability of adversarial samples on different deep learning models.

CN119940469AActive Publication Date: 2025-05-06NORTHWESTERN POLYTECHNICAL UNIV
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510421353.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-05-06
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

When generating adversarial samples, existing input conversion methods ignore the differences in the degree of attention of deep learning models to different regions of the input data, making it difficult for the generated adversarial samples to be transferred to the robustly reinforced deep learning model.

Method used

By obtaining the class activation graph matrix of the output results of the deep learning model, the model's attention to different pixels in the input sample is evaluated, and it is divided into square subgraphs, sorted and interchanged according to the sum of element values, and generated an attention-disturbed class activation graph matrix, combined with the corrected samples for data enhancement, and generated adversarial samples.

Benefits of technology

By adding targeted perturbations to the attention area of ​​the deep learning model, the transferability of the generated adversarial samples is improved, allowing it to attack different types of deep learning models more effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119940469A_ABST
    Figure CN119940469A_ABST
Patent Text Reader

Abstract

The invention provides an attention disturbance-based adversarial sample generation method, system and device and a medium, and belongs to the technical field of artificial intelligence, and the method comprises the following steps: inputting an input sample into a deep learning model, and obtaining a class activation graph matrix of an output result; segmenting the class activation graph matrix into a plurality of square sub-graphs, sorting the square sub-graphs according to the sums of the element values of the square sub-graphs, and exchanging positions of the square sub-graphs with larger and smaller sums of the element values to obtain a class activation graph matrix with disturbance of attention; correcting the input sample of the tth round, and fusing the corrected input sample with the attention disturbed class activation graph matrix to obtain an enhanced sample; performing adversarial disturbance calculation on the enhanced sample to generate an adversarial sample; and repeating the generation of the class activation graph matrix, the segmentation process and the adversarial sample generation process until T rounds of adversarial sample generation are completed, and obtaining a final adversarial sample. According to the invention, the mobility of the adversarial sample for different depth models can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of artificial intelligence technology, and specifically relates to a method, system, device and medium for generating adversarial samples based on attention disturbance. Background Art

[0002] In recent years, deep learning models have achieved remarkable results in computer vision, natural language processing and other fields. However, studies have shown that deep learning models are vulnerable to adversarial sample attacks. Deep learning models are vulnerable to adversarial sample attacks, which poses serious security risks in real applications. By using adversarial sample generation algorithms to conduct adversarial attacks on deep learning models and explore the risk points of the models, we can provide a basis for strengthening the robustness of deep learning models.

[0003] The transfer attack method implements black-box attacks on deep learning models based on the transferability of adversarial samples. Due to its flexible nature, it has become a more commonly used black-box attack method. As a common method to improve the transferability of adversarial samples, the input conversion method enriches the search space of adversarial perturbations by increasing the diversity of data, thereby improving the transferability of adversarial samples. However, the existing input conversion methods ignore the differences in the degree of attention paid by deep learning models to different regions of the input data, and often enhance the data by randomly flipping, patching, and merging the input samples. As a result, the adversarial samples generated by the existing input conversion methods are difficult to effectively migrate to the deep learning models that have been reinforced with robustness. Summary of the invention

[0004] In order to overcome the shortcomings of the above-mentioned prior art, the present invention provides an adversarial sample generation method based on attention perturbation, comprising the following steps: Get the t Input samples of rounds; The first t Input samples of the round are input into the deep learning model, the output results of the deep learning model are obtained, and the class activation map matrix of the output results is calculated using a neural network visualization method; Mask the class activation map matrix, and perform the masked class activation map on the first t The input samples of the round are corrected; The class activation map matrix is ​​divided into multiple square sub-graphs with a side length of s; the multiple square sub-graphs are sorted according to the size of the sum of their element values, and some square sub-graphs are randomly extracted according to the proportion. Among the extracted square sub-graphs, the square sub-graph with the largest sum of element values ​​is swapped with the square sub-graph with the smallest sum of element values, and the square sub-graph with the second largest element value is swapped with the square sub-graph with the second smallest element value, and so on, and the positions of all the extracted square sub-graphs are swapped to obtain the class activation map matrix of attention disturbance; The class activation map matrix of the attention disturbance is fused with the modified sample enhancement to obtain the enhanced sample; the enhanced sample is subjected to adversarial perturbation calculation to generate the first t Round of adversarial examples; The generated t The adversarial sample of round 1 is used as t +1 round of input samples, input deep learning model, repeat the generation process of class activation map matrix, segmentation process and the first t +1 round of adversarial sample generation process is performed until T rounds of adversarial sample generation process are completed to obtain the final adversarial sample.

[0005] Preferably, the dividing the class activation map matrix into a plurality of square subgraphs with a side length of s is specifically as follows: when the side length of the class activation map matrix is ​​divisible by s, the entire class activation map matrix is ​​divided into a plurality of square subgraphs with a side length of s; when the side length of the class activation map matrix is ​​not divisible by s, the central area of ​​the class activation map matrix that is divisible by s is divided into a plurality of square subgraphs with a side length of s, and the peripheral area of ​​the class activation map matrix remains unchanged.

[0006] Preferably, the class activation map matrix is ​​masked, and the masked class activation map matrix is ​​used to identify the t The input samples of the first round are corrected, specifically: the element values ​​in the class activation map matrix that are greater than their q quantiles are set to 0, and the remaining elements are set to -1, and the set element values ​​are dot-producted with the class activation map matrix, and the areas in the class activation map matrix that have a key impact on the output results of the deep learning model are masked to obtain the masked class activation map matrix; based on the masked class activation map matrix and the t -1 round of momentum gradient is used to correct the input samples.

[0007] Preferably, the enhanced sample is subjected to anti-disturbance calculation to generate the first t The adversarial examples of the round include the following steps: Set different extraction ratios , according to different extraction ratios Performing different degrees of enhancement on the corrected samples to obtain an enhanced picture set; The pixel values ​​of each image in the enhanced image set are scaled according to different proportions to obtain multiple scaled images. The adversarial perturbation is calculated based on the average gradient information of the scaled images to generate the first t Round of adversarial examples.

[0008] The present invention also provides an adversarial sample generation system based on attention disturbance, comprising: Data acquisition module, used to obtain the t Input samples of rounds; The class activation map matrix acquisition module is used to obtain the t Input samples of the round are input into the deep learning model, the output results of the deep learning model are obtained, and the class activation map matrix of the output results is calculated using a neural network visualization method; The correction module is used to mask the class activation map matrix and correct the t The input samples of the round are corrected; The attention disturbance module is used to divide the class activation map matrix into multiple square sub-graphs with a side length of s; sort the multiple square sub-graphs according to the size of the sum of their element values, randomly extract some square sub-graphs according to a proportion, and among the extracted square sub-graphs, swap the positions of the square sub-graph with the largest sum of element values ​​with the square sub-graph with the smallest sum of element values, and swap the positions of the square sub-graph with the second largest element value with the square sub-graph with the second smallest element value, and so on, to complete the position swapping of all the extracted square sub-graphs, and obtain the attention-disturbed class activation map matrix; The sample enhancement module is used to fuse the class activation map matrix of the attention disturbance with the modified sample enhancement to obtain the enhanced sample; the enhanced sample is subjected to adversarial perturbation calculation to generate the first t Round of adversarial examples; The sample generation module is used to generate t The adversarial sample of round 1 is used as t +1 round of input samples, input deep learning model, repeat the generation process of class activation map matrix, segmentation process and the first t +1 round of adversarial sample generation process is performed until T rounds of adversarial sample generation process are completed to obtain the final adversarial sample.

[0009] The present invention also provides a computer device, comprising a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to execute the adversarial sample generation method based on attention perturbation.

[0010] The present invention also provides a computer-readable storage medium, which stores a computer program, and the computer program is suitable for loading by a processor to execute the adversarial sample generation method based on attention perturbation.

[0011] The adversarial sample generation method based on attention disturbance provided by the present invention has the following beneficial effects: The present invention can evaluate the degree of attention paid by the deep learning model to different pixels in the input sample by obtaining the class activation map matrix of the output result of the deep learning model; by dividing the class activation map matrix into a plurality of square sub-graphs with a side length of s; by sorting the plurality of square sub-graphs according to the size of the sum of their element values, the area with a larger sum of element values ​​is the area (attention area) that the deep learning model pays more attention to, and by exchanging the square sub-graphs with a larger sum of element values ​​and the square sub-graphs with a smaller sum of element values ​​according to the extraction ratio, the class activation map matrix with disturbed attention can be obtained; by fusing the corrected sample with the class activation map matrix with disturbed attention, an enhanced sample can be obtained, and this process can perform differentiated data enhancement on different attention areas of the input sample; by performing adversarial perturbation calculation on the enhanced sample, an adversarial sample can be generated.

[0012] In the process of adversarial sample generation, the method of the present invention can add targeted perturbations to the attention area of ​​the deep learning model for the input sample, thereby improving the transferability of the generated adversarial samples to different types of deep learning models. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the embodiment of the present invention and its design scheme, the following briefly introduces the drawings required for this embodiment. The drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0014] Figure 1 Flow chart of a method for generating adversarial samples based on attention disturbance according to an embodiment of the present invention; Figure 2 Schematic diagram of the principle of adversarial sample generation method based on attention perturbation; Figure 3 Schematic diagram of the principle of data augmentation. DETAILED DESCRIPTION

[0015] In order to enable those skilled in the art to better understand the technical solution of the present invention and implement it, the present invention is described in detail below in conjunction with the accompanying drawings and specific embodiments. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and cannot be used to limit the scope of protection of the present invention.

[0016] Example 1 The present invention provides an adversarial sample generation method based on attention disturbance, which first uses a deep neural network visualization method to calculate the class activation map matrix, so as to evaluate the degree of attention of the deep learning model to different pixels in the input sample; then, the area in the class activation map matrix that has a greater impact on the model output result is masked, and the input sample is corrected in combination with historical gradient information; after that, data enhancement is performed by exchanging the positions of the areas with a greater and lesser impact on the model output result of the class activation map matrix, and fusing them with the corrected data; then, the enhanced image is copied in multiple copies, and the pixel values ​​of each copy are scaled according to different proportions; finally, the adversarial disturbance is calculated based on the average gradient information of the scaled image, so as to generate an adversarial sample. The present invention improves the mobility of the generated adversarial sample through the angle of the deep learning model's attention area for the input sample, and has the characteristics of good cross-model migration effect.

[0017] The flow chart and principle diagram of the adversarial sample generation method based on attention disturbance of the present invention are respectively as follows: Figure 1 and Figure 2 As shown, the specific implementation process is as follows: S1: Parameter initialization.

[0018] Based on the original image with a shape of 299×299×3 First, initialize the perturbation step size in the adversarial sample generation process , the momentum gradient in the first round of generation , input sample , where the perturbation step length is is a fixed constant, is the maximum disturbance amplitude, set to , The number of generation rounds is set to 10.

[0019] S2: Model attention area mining.

[0020] Get the t The input sample of the round t The input samples of the round are input into the deep learning model, the output results of the deep learning model are obtained, and the deep learning model is calculated for the input samples using related neural network visualization methods such as Grad-CAM. The output of y The class activation matrix , specifically through the following formula: ; In the formula, It is the output matrix of the last convolutional layer of the deep learning model; for The number of channels; Relu is the activation function; H is the interpolation function used to map the class activation map matrix to the input sample Same shape; is the fusion coefficient, which is calculated as follows: ; In the formula, Z for The product of the length and width of for of The value of the element at position; is the output result of the deep learning model.

[0021] S3: Attention-driven data correction.

[0022] First, the class activation matrix In larger than The element values ​​of the quantiles are all set to 0, and the remaining elements are set to -1, and then compared with Perform dot product multiplication to mask some areas in the class activation map matrix that have a greater impact on the model prediction results, and obtain the masked class activation map matrix , as follows: ; In the formula, is the class activation map matrix after masking; is the class activation map matrix; is the class activation matrix Quantile; is a symbolic function.

[0023] Then, combine the masked class activation map matrix and the momentum gradient in the previous round For input samples Correction , as follows: ; In the formula, is the perturbation step length; For the t Input samples of rounds; is the class activation map matrix after masking; For the t -1 round momentum gradient, in addition, if the current round is the 1st round, then Initialize parameters for momentum gradient .

[0024] S4: Data augmentation based on attention perturbation.

[0025] First, the class activation matrix Divide into square subgraphs with side length s, if If the side length is divisible by s, the entire class activation map matrix is ​​split, otherwise only The middle area is divisible by s, and the outer area remains unchanged. Specifically, Figure 3 As shown, the class activation map matrix Center 275 The 275-pixel area is divided into square sub-images with a side length of s = 55 pixels, resulting in a total of 5 × 5 = 25 square sub-images, and the outer area remains unchanged.

[0026] Then, the square subgraphs are sorted according to the sum of their element values. The square subgraphs with the larger sum of their element values ​​are the ones that the deep learning model can use for the input samples. For the area of ​​more concern, some square sub-graphs are randomly extracted according to the proportion. In the extracted square sub-graphs, the square sub-graph with the largest sum of element values ​​is swapped with the square sub-graph with the smallest sum of element values, and the square sub-graph with the second largest element value is swapped with the square sub-graph with the second smallest element value. Specifically, the present invention has a total of 25 square sub-graphs, and the proportion is set to 0.5, then 14 square sub-graphs are extracted from the 25 square sub-graphs. For the 14 square sub-graphs extracted, the square sub-graph with the largest sum of element values ​​is swapped with the square sub-graph with the smallest sum of element values, and the square sub-graph with the second largest element value is swapped with the second smallest square sub-graph, and so on, to complete the position swapping of all the extracted square sub-graphs, thereby obtaining the class activation map matrix of attention disturbance , and then the class activation map matrix of the perturbed attention With the corrected sample Fusion, to obtain enhanced data, the calculation method is as follows: ; In the formula, For the enhanced data; is the corrected sample; is the fusion coefficient, ; is a random noise that obeys a normal distribution; in addition, since the class activation map matrix is ​​a single-channel grayscale image, in order to enrich the diversity of data enhancement results, the present invention introduces a magnitude in the result. Random noise between ,in, is the maximum perturbation size of the adversarial sample.

[0027] In order to disrupt the focus area of ​​the deep learning model on the input sample to the greatest extent, the present invention sets different extraction ratios ,right Perform different degrees of enhancement to obtain a collection of enhanced images , which is expressed as follows: ; ; In the formula, =1,2, 10; For different extraction ratios; The enhanced data obtained at different extraction ratios; For the enhanced image collection, the capacity of the image collection .

[0028] S5: Data scaling.

[0029] In order to further enhance the transferability of generated adversarial samples, the present invention combines the scale-invariant method SIM (Scale-Invariant Method) to set the enhanced image set The pixel value of each image in becomes 1, 1 / 2, 1 / 4, 1 / 8, 1 / 16 of the original image, thus The capacity is expanded 5 times, resulting in 5×10=50 copies of the image.

[0030] S6: Adversarial perturbation calculation based on gradient direction.

[0031] First, based on the acquired enhanced data, the loss function is back-propagated to calculate the Wheel gradient , calculated as follows: ; In the formula, For the t The gradient of the wheel; is the corrected sample; The enhanced data obtained at different extraction ratios; is the loss function; are the parameters of the model; is the loss function right Derivation; is the output of the deep learning model.

[0032] Then, the momentum accumulation algorithm is used to calculate the accumulated momentum gradient of the current round. The details are as follows: ; In the formula, is 1 norm; For the t The gradient of the wheel, is the attenuation coefficient hyperparameter, with a value of 1.0; For the t -1 round momentum gradient; in addition, if the current round is round 1, then Initialize parameters for momentum gradient , Subsequently, based on the Momentum gradient of the wheel Calculate the adversarial perturbation in the direction of and generate the adversarial sample of the current round (i.e. t +1 round of input samples), as follows: ; In the formula, For the t Input samples of rounds; is the perturbation step length; Sign is the sign function, For the The momentum gradient of the wheel.

[0033] The generated t The adversarial sample of round 1 is used as t +1 round of input samples, input deep learning model, repeat the generation process of class activation map matrix, segmentation process and the first t +1 round of adversarial sample generation process, until T rounds of adversarial sample generation process are completed. After the round of adversarial sample generation process is completed, the final adversarial sample can be obtained.

[0034] In this embodiment, the deep learning model used may be a deep convolutional neural network such as ResNet (Residual Network), VGG (Visual Geometry Group), Inception-V3, or Inception-V4.

[0035] The present invention also provides an adversarial sample generation system based on attention disturbance, comprising a data acquisition module, a class activation map matrix acquisition module, a correction module, an attention disturbance module, a sample enhancement module and a sample generation module. The data acquisition module is used to obtain the first t The class activation map matrix acquisition module is used to obtain the input samples of the first round. tThe input samples of the first round are input into the deep learning model to obtain the output results of the deep learning model, and the class activation map matrix of the output results is calculated using the neural network visualization method; the correction module is used to mask the class activation map matrix, and the masked class activation map matrix is ​​used to correct the first t The input samples of the round are corrected; the attention disturbance module is used to divide the class activation map matrix into multiple square sub-graphs with a side length of s; the multiple square sub-graphs are sorted according to the size of the sum of their element values, and some square sub-graphs are randomly extracted according to the proportion. Among the extracted square sub-graphs, the square sub-graph with the largest sum of element values ​​is swapped with the square sub-graph with the smallest sum of element values, and the square sub-graph with the second largest element value is swapped with the square sub-graph with the second smallest element value, and so on, to complete the position swap of all the extracted square sub-graphs to obtain the attention-disturbed class activation map matrix; the sample enhancement module is used to fuse the attention-disturbed class activation map matrix with the corrected sample enhancement to obtain the enhanced sample; the enhanced sample is subjected to adversarial perturbation calculation to generate the first t The sample generation module is used to generate the adversarial samples of the first round. t The adversarial sample of round 1 is used as t +1 round of input samples, input deep learning model, repeat the generation process of class activation map matrix, segmentation process and the first t +1 round of adversarial sample generation process is performed until T rounds of adversarial sample generation process are completed to obtain the final adversarial sample.

[0036] The present invention also provides a computer device, comprising a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to execute the adversarial sample generation method based on attention perturbation.

[0037] The present invention also provides a computer-readable storage medium, which stores a computer program, and the computer program is suitable for loading by a processor to execute the adversarial sample generation method based on attention perturbation.

[0038] Example 2 In order to verify the method of the present invention, the following comparative test was carried out, and the specific process is as follows: (1) Test dataset.

[0039] One image is selected from each of the 1000 categories of the ImageNet dataset to form a test dataset, and the size of each image in the dataset is uniformly adjusted to 299×299×3.

[0040] (2) Attack model.

[0041] The deep learning models selected for testing include four normally trained deep convolutional neural networks Inc-V3 (Inception-V3), Inc-V4 (Inception-V4), IncResV2 (Inception-ResNet-V2), Res-101 (ResNet-v2-101) and three deep learning models Inc-V3 reinforced by adversarial training. ens3 、Inc-V3 ens4 、IncRes-V2 ens .

[0042] (3) Baseline comparison method.

[0043] The baseline comparison method (attack method) of the present invention respectively selects variance network invariant fast gradient sign method VNI-FGSM (Variance Network Invariant Fast Gradient Sign Method), hybrid method Admix, learned iterative fast gradient sign method LI-FGSM (Learned Iterative Fast Gradient Sign Method), spatial contextual manipulation and perturbation method SCM-P (Spatial Contextual Manipulation with Perturbation), mixed class activation mapping method MixCAM (Mixed Class Activation Mapping) and the method of the present invention.

[0044] (4) Test method.

[0045] Adversarial samples are generated for Inc-V3 and Inc-V4 models using the selected baseline method and the method of the present invention, respectively, and then the attack success rate of the generated adversarial samples for the selected models is verified. Table 1 shows the attack success rates of all models for adversarial samples generated by the present invention and the selected baseline method based on Inc-V3 and Inc-V4 models, respectively. It can be seen that since the method of the present invention generates adversarial samples by disrupting the angle of the model's focus area on the data, the attack success rate of the generated adversarial samples for known models is comparable to that of other methods (data marked with stars in the table), and the attack success rate for unknown models is better than that of other baseline comparison methods (data not marked with stars in the table). In summary, the method of the present invention can significantly improve the cross-model transferability of the generated adversarial samples without reducing the success rate of white-box attacks.

[0046] Table 1 Comparison of the attack success rates of different models between the method of the present invention and the baseline comparison method

[0047] The embodiments described above are only preferred specific implementation modes of the present invention, and the protection scope of the present invention is not limited thereto. Any simple changes or equivalent replacements of the technical solutions that can be obviously obtained by any technician familiar with the field within the technical scope disclosed in the present invention belong to the protection scope of the present invention.

Claims

1. A method for generating adversarial samples based on attention disturbance, characterized in that: The steps include: Get the t Input samples of rounds; The first t Input samples of the round are input into the deep learning model, the output results of the deep learning model are obtained, and the class activation map matrix of the output results is calculated using a neural network visualization method; Mask the class activation map matrix, and perform the masked class activation map on the first t The input samples of the round are corrected; The class activation map matrix is ​​divided into multiple square sub-graphs with a side length of s; the multiple square sub-graphs are sorted according to the size of the sum of their element values, and some square sub-graphs are randomly extracted according to the proportion. Among the extracted square sub-graphs, the square sub-graph with the largest sum of element values ​​is swapped with the square sub-graph with the smallest sum of element values, and the square sub-graph with the second largest element value is swapped with the square sub-graph with the second smallest element value, and so on, and the positions of all the extracted square sub-graphs are swapped to obtain the class activation map matrix of attention disturbance; The class activation map matrix of the perturbed attention is fused with the corrected sample enhancement to obtain the enhanced sample; Perform adversarial perturbation calculation on the enhanced samples to generate the t Round of adversarial examples; The generated t The adversarial sample of round 1 is used as t +1 round of input samples, input deep learning model, repeat the generation process of class activation map matrix, segmentation process and the first t +1 round of adversarial sample generation process is performed until T rounds of adversarial sample generation process are completed to obtain the final adversarial sample.

2. The method for generating adversarial samples based on attention disturbance according to claim 1, characterized in that: The class activation map matrix is ​​divided into a plurality of square subgraphs with a side length of s, specifically: when the side length of the class activation map matrix is ​​divisible by s, the entire class activation map matrix is ​​divided into a plurality of square subgraphs with a side length of s; when the side length of the class activation map matrix is ​​not divisible by s, the central area of ​​the class activation map matrix that is divisible by s is divided into a plurality of square subgraphs with a side length of s, and the peripheral area of ​​the class activation map matrix remains unchanged.

3. The method for generating adversarial samples based on attention disturbance according to claim 1, characterized in that: The class activation map matrix is ​​masked, and the class activation map matrix is ​​masked based on the masked class activation map matrix. t The input samples of the first round are corrected, specifically: the element values ​​in the class activation map matrix that are greater than their q quantiles are set to 0, and the remaining elements are set to -1, and the set element values ​​are dot-producted with the class activation map matrix, and the areas in the class activation map matrix that have a key impact on the output results of the deep learning model are masked to obtain the masked class activation map matrix; based on the masked class activation map matrix and the t -1 round of momentum gradient is used to correct the input samples.

4. The method for generating adversarial samples based on attention disturbance according to claim 1, characterized in that: The enhanced samples are subjected to counter-perturbation calculation to generate the first t The adversarial examples of the round include the following steps: Set different extraction ratios , according to different extraction ratios Performing different degrees of enhancement on the corrected samples to obtain an enhanced picture set; The pixel values ​​of each image in the enhanced image set are scaled according to different proportions to obtain multiple scaled images. The adversarial perturbation is calculated based on the average gradient information of the scaled images to generate the first t Round of adversarial examples.

5. A system for generating adversarial samples based on attention disturbance, characterized in that: include: Data acquisition module, used to obtain the t Input samples of rounds; The class activation map matrix acquisition module is used to obtain the t Input samples of the round are input into the deep learning model, the output results of the deep learning model are obtained, and the class activation map matrix of the output results is calculated using a neural network visualization method; The correction module is used to mask the class activation map matrix and correct the t The input samples of the round are corrected; The attention disturbance module is used to divide the class activation map matrix into multiple square sub-graphs with a side length of s; sort the multiple square sub-graphs according to the size of the sum of their element values, randomly extract some square sub-graphs according to a proportion, and among the extracted square sub-graphs, swap the positions of the square sub-graph with the largest sum of element values ​​with the square sub-graph with the smallest sum of element values, and swap the positions of the square sub-graph with the second largest element value with the square sub-graph with the second smallest element value, and so on, to complete the position swapping of all the extracted square sub-graphs, and obtain the attention-disturbed class activation map matrix; The sample enhancement module is used to fuse the attention-perturbed class activation map matrix with the corrected sample enhancement to obtain the enhanced sample; Perform adversarial perturbation calculation on the enhanced samples to generate the t Round of adversarial examples; The sample generation module is used to generate t The adversarial sample of round 1 is used as t +1 round of input samples, input deep learning model, repeat the generation process of class activation map matrix, segmentation process and the first t +1 round of adversarial sample generation process is performed until T rounds of adversarial sample generation process are completed to obtain the final adversarial sample.

6. A computer device, characterized in that: It includes a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to execute the adversarial sample generation method based on attention disturbance as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which is suitable for loading by a processor to execute the adversarial sample generation method based on attention perturbation as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Generation method of Chinese character font generation model and Chinese character font generation method and device

    CN113962192A

  • Low-disturbance adversarial attack method based on attention mechanism

    CN114332569A

  • Image automatic annotation method and system based on attention disturbance and medium

    CN114359659A

  • Anti-texture image generation method and device based on model sharing structure

    CN114943641A

  • Class activation mapping-based adversarial sample visual interpretation method

    CN115630303A