Adversarial sample generation method, system and device

By calculating synthetic samples and performing data enhancement methods, the adversarial samples are generated, which solves the problem of insufficient migration of adversarial samples in the prior art, and achieves a stronger attack cross-model effect.

CN120014383APending Publication Date: 2025-05-16SOUTHWEST PETROLEUM UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510104657.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

While maintaining the concealment of adversarial samples, existing adversarial samples are difficult to improve their migration, limiting the cross-model effect of attacks.

Method used

By obtaining the original data set, compute the synthetic samples and update the data set, perform data augmentation, calculate the anti-noise and process the sample image, and generate the adversarial samples. This method improves the generalization ability and transferability of the adversarial samples by introducing synthetic samples and increasing diversity.

Benefits of technology

It realizes that while maintaining the concealment of adversarial samples, it significantly improves its migration ability, making adversarial attacks have better cross-model effects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120014383A_ABST
    Figure CN120014383A_ABST
Patent Text Reader

Abstract

The invention discloses an adversarial sample generation method, system and device, and relates to the technical field of adversarial attacks, and the adversarial sample generation method provided by the invention effectively introduces synthetic data so as to improve the sample generalization ability. Block segmentation multidirectional transformation is used to obtain richer feature information, different image enhancement transformations are carried out on segmented image blocks, and then the gradient is calculated, so that instability caused by too large transformation differences is eliminated; and finally, based on an image fine-grained significance mapping result, the disturbance of different pixel points is optimized, so that the disturbance selectively acts on an iterative sample, and the transferability of the anti-attack is improved while the imperceptibility of the anti-attack sample is kept.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of anti-attack technology, and in particular, to an adversarial sample generation method, system and device. Background Art

[0002] With the development of deep neural networks, they have achieved remarkable results in various computer vision tasks such as image classification, object detection, and face recognition. However, studies have shown that neural networks are susceptible to adversarial attacks, which exploit the shortcomings of deep learning to destroy the recognition system and make special changes to the recognized object, causing the neural network to fail to recognize or classify without the naked eye being able to see anything unusual. The property that adversarial samples generated by one model can deceive another different model with a certain probability is called the transferability of adversarial samples. Research on generating adversarial samples with strong transferability not only helps to identify the vulnerabilities of neural networks, but also improves the robustness of network adversarial attacks in practical applications. Gradient-based attacks are one of the most commonly used and effective adversarial attack methods in the field of image classification, and the image is transformed before the gradient calculation to improve transferability. Existing attacks of this type use real data for enhancement. At the same time, in order to maintain the visual similarity between the adversarial sample and the original image, the image transformation range is limited to global transformations that do not change the local relationship between the input image objects. Both hinder the transferability of attacks to a certain extent and limit the cross-model effect of attacks. Therefore, how to maintain the concealment of adversarial samples while improving their transferability has become a key issue in the field of adversarial attacks. Summary of the invention

[0003] In order to improve the transferability of adversarial attacks while maintaining the visual similarity between adversarial samples and original images, the present invention provides an adversarial sample generation method, the adversarial sample generation method comprising:

[0004] Obtaining a first data set, wherein the first data set includes a plurality of first sample images;

[0005] Calculate a synthetic sample according to the first sample image, and update the first image data set according to the synthetic sample to obtain a second image data set;

[0006] Performing data enhancement on the second image data set to obtain a third data set;

[0007] The adversarial noise corresponding to the third data set is calculated and the first sample image is processed according to the adversarial noise to generate an adversarial sample.

[0008] The principle of this method is as follows: after obtaining the first data set corresponding to the original data, first calculate the synthetic sample corresponding to the first sample image, and update the first data set through the synthetic sample. The synthetic sample introduces more variability than the original data, which can ensure the diversity of samples while avoiding over-reliance on a single data mode, thereby enhancing the generalization ability of adversarial samples on different models. Perform data enhancement on the updated image data set, use the fully transformed image to calculate the adversarial noise and finally generate the adversarial sample, while maintaining the concealment of the adversarial attack and making the adversarial attack have good transferability.

[0009] Furthermore, using only original data or synthetic samples to calculate adversarial noise and generate adversarial samples will result in a corresponding decrease in the generalization ability of the adversarial attack. Specifically, using only original data to calculate adversarial noise and generate adversarial samples will lead to over-reliance of adversarial samples on a certain feature; and using only synthetic samples to calculate adversarial noise and generate adversarial samples will cause adversarial samples to deviate from the natural distribution. To further improve the transferability of adversarial attacks, the method of updating the first image dataset according to the synthetic samples to obtain the second dataset is:

[0010] Sampling the first data set to obtain a second sample image;

[0011] Calculating a synthetic sample, mixing the second sample image and the synthetic sample to obtain a third sample image;

[0012] The third sample image is added to the first data set to obtain a second data set.

[0013] Furthermore, in order to obtain a synthetic image different from the original image and to maintain a high degree of visual similarity between the synthetic image and the original image, the method for calculating the synthetic sample is:

[0014] Obtaining an image to be processed;

[0015] Superimposing noise data on the image to be processed to obtain first data;

[0016] The first data is subjected to denoising processing to obtain a synthetic sample.

[0017] The method of mixing the second sample image and the synthetic sample is as follows:

[0018] x′=λ·x+(1-λ)·S(x)

[0019] Wherein, x is the second sample image, S(x) is the synthesized sample, x′ is the mixed image, and λ is the mixing ratio of the sample image and the synthesized sample.

[0020] Furthermore, according to the study by Wang et al. on comparing the semantic similarity between the original image and the image after data enhancement using the similarity of learned perceptual image blocks, it can be known that: without damaging the semantic information of the image, as the diversity of the image after data enhancement increases and the similarity between the image after data enhancement and the original image decreases, the transferability of the adversarial attack increases. Therefore, this method enhances the image by dividing the image into blocks to improve the image diversity, and the method for performing data enhancement on the second data set is:

[0021] Traversing the second data set to obtain a fourth sample image;

[0022] Partitioning the fourth sample image to obtain n image blocks, where n is a non-zero natural number;

[0023] Data enhancement is performed on the image block to obtain a third data set.

[0024] Furthermore, the number of image blocks determines the diversity of the image after data enhancement. The larger the number of image blocks after segmentation, the better the transferability against attacks. However, when the number of image blocks is greater than the critical value, the diversity of samples will introduce more variance into the gradient calculation, causing the attack performance to slightly decrease. At the same time, the semantic information content of different regions of the same image is different, and the distribution of image semantic information can be obtained through fine-grained saliency mapping calculation. Therefore, after calculating the fine-grained saliency mapping of the sample, this method segments more image blocks in areas with large image semantic information content, and segments fewer image blocks in irrelevant areas to ensure attack performance. The method for data enhancement of the second image dataset is:

[0025] Traversing the second data set to obtain a fifth sample image;

[0026] Calculating a first fine-grained saliency map corresponding to the fifth sample image;

[0027] Partitioning the fifth sample image according to the first fine-grained saliency map to obtain m image blocks, where m is a non-zero natural number;

[0028] Data enhancement is performed on the image block to obtain a third data set.

[0029] Furthermore, in order to improve the diversity of image data after enhancement, different image methods are randomly applied to the segmented image blocks. The method for performing data enhancement on the image blocks is:

[0030] Generate an image transformation set, wherein the image transformation set includes a displacement transformation set and a pixel transformation set;

[0031] The image blocks are respectively input into the displacement transformation set and / or the pixel transformation set to obtain a third data set.

[0032] Furthermore, in order to optimize the disturbance added to the original sample according to the distribution of the semantic information of the original sample and improve the concealment and effectiveness of the adversarial attack, the adversarial noise corresponding to the third data set is calculated and the first sample image is processed according to the adversarial noise. The method for generating the adversarial sample is:

[0033] Calculating a second fine-grained saliency map corresponding to the first sample image;

[0034] Traversing the third data set to obtain a sixth sample image;

[0035] calculating adversarial noise corresponding to the sixth sample image, and optimizing the adversarial noise according to the second fine-grained saliency map;

[0036] The first sample image is attacked according to the optimized adversarial noise to obtain an adversarial sample.

[0037] To achieve the above object, the present invention further provides an adversarial sample generation system, the system comprising:

[0038] The sample acquisition unit is used to: obtain a first data set, wherein the first data set includes a plurality of first sample images;

[0039] A sample processing unit, configured to: calculate a synthetic sample, and update the first data set according to the synthetic sample to obtain a second data set;

[0040] A sample enhancement unit, used to: perform data enhancement on the second data set to obtain a third data set;

[0041] The sample generating unit is used to calculate the adversarial noise corresponding to the third data set and process the first sample image according to the adversarial noise to generate an adversarial sample.

[0042] Among them, the principle of this system is: after obtaining the first image data set corresponding to the original input sample, first calculate the synthetic sample corresponding to the first sample image, update the first data set through the synthetic sample, perform data enhancement on the updated image data set, and use the fully transformed image gradient to update the adversarial sample. The adversarial sample generated based on the system provided by the present invention can make the adversarial attack have good transferability.

[0043] To achieve the above objectives, the present invention also provides an adversarial sample generation device, including a memory, a processor, and a computer program stored in the memory and can be executed on the processor, wherein when the processor executes the computer program, the steps of any one of the above-mentioned adversarial sample generation methods are implemented.

[0044] One or more technical solutions provided by the present invention have at least the following technical effects or advantages:

[0045] 1. After obtaining the original input sample, the synthetic sample is calculated and the original sample is updated, which avoids the generation of adversarial samples being limited to the original data and improves the transferability of adversarial attacks.

[0046] 2. Perform partition data enhancement on image samples so that the enhanced samples have good diversity and improve the transferability of adversarial attacks.

[0047] 3. The distribution of image semantic information is calculated using fine-grained saliency mapping, and data enhancement is performed on the image in a targeted manner based on the distribution of image semantic information, which reduces the perceptibility of disturbances and improves the effectiveness of adversarial attacks while maintaining their concealment. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The drawings described herein are used to provide a further understanding of the embodiments of the present invention, constitute a part of the present invention, and do not constitute a limitation on the embodiments of the present invention;

[0049] Figure 1 A schematic diagram of the process flow of the adversarial sample generation method provided by the present invention;

[0050] Figure 2 A schematic diagram of the structure of the adversarial sample generation system provided by the present invention;

[0051] Figure 3 Schematic diagram of fine-grained saliency calculation;

[0052] Figure 4 The shallow class activation map corresponding to the fine-grained saliency calculation diagram;

[0053] Figure 5 The middle-level class activation map corresponding to the fine-grained saliency calculation diagram;

[0054] Figure 6 Deep class activation maps corresponding to the fine-grained saliency calculation diagram;

[0055] Figure 7 The fine-grained saliency calculation result corresponding to the fine-grained saliency calculation diagram. DETAILED DESCRIPTION

[0056] In order to more clearly understand the above-mentioned purpose, features and advantages of the present invention, the present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that the embodiments of the present invention and the features in the embodiments can be combined with each other without conflict.

[0057] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those within the scope of this description. Therefore, the protection scope of the present invention is not limited to the specific embodiments disclosed below.

[0058] Embodiment 1

[0059] Please refer to Figure 1 , Embodiment 1 of the present invention provides an adversarial sample generation method, the adversarial sample generation method comprising: obtaining a first data set, the first data set comprising a plurality of first sample images;

[0060] Calculating a synthetic sample, and updating the first data set according to the synthetic sample to obtain a second data set;

[0061] Performing data enhancement on the second data set to obtain a third data set;

[0062] Traversing the third data set, inputting the images in the third data set into the neural network model and calculating the model gradient, and obtaining the adversarial noise corresponding to the third data set according to the model gradient;

[0063] The adversarial noise is added to the first sample image to generate an adversarial sample.

[0064] Among them, this method adds the adversarial noise to the first sample image. After generating the adversarial sample, in order to improve the effect of the adversarial attack, the generated adversarial sample is re-calculated as the output synthetic sample and the subsequent steps are executed. The number of iterations is determined according to actual needs, and the method is iteratively executed to finally obtain an adversarial sample with good migration.

[0065] Among them, the method for data enhancement of the second data set can be image grayscale transformation, geometric correction, image pixel transformation or image filtering processing, or it can be any image processing method that can make the image different from the original image and retain the visual similarity of the image. The specific method for data enhancement of the second data set is determined according to actual needs, and this embodiment does not make any specific limitation here.

[0066] The synthetic sample is an image generated by an image generation model that has visual similarity to the original image. The method of calculating the synthetic sample and updating the first data set according to the synthetic sample to obtain the second data set is:

[0067] Sampling the first data set to obtain a second sample image;

[0068] Calculating a synthetic sample corresponding to the second sample image, and mixing the second sample image and the synthetic sample to obtain a third sample image;

[0069] The third sample image is added to the first data set to obtain a second data set.

[0070] It can be understood that when the unprocessed first data set is input into the unattacked first neural network model, the first neural network model can classify the images contained in the data set according to the semantic information to obtain the classification result. When sampling the first data set, the second sample image can be obtained by sampling according to the classification result, or random sampling can be performed. The specific sampling method and sampling amount are determined according to the amount of data and actual needs, and this embodiment does not make specific limitations here.

[0071] Preferably, the method for calculating the synthetic sample is:

[0072] Obtaining an image to be processed;

[0073] Superimposing noise data on the image to be processed to obtain first data;

[0074] The first data is subjected to denoising processing to obtain a synthetic sample.

[0075] Specifically, generating synthetic samples based on the image to be processed includes a forward diffusion process and a reverse denoising process. Among them, for the image to be processed from the real image distribution, the forward diffusion process gradually adds Gaussian noise to the image to be processed in T steps to generate a series of noise samples [x1, x2, ..., x t ,...,x T ], its Markov process can be expressed as:

[0076]

[0077] Where t is the number of diffusion steps, is a Gaussian distribution, representing the data sample of the diffusion process at the time step, q(x t ;x t-1 ) represents the conditional probability distribution of the forward diffusion process. t ∈(0,1) is a hyperparameter that obeys a Gaussian distribution, and I represents an identity matrix with the same dimension as the image to be processed.

[0078] The reverse process is to use reverse diffusion to obtain the Gaussian noise sample x T ~N(0,I) to reconstruct the real sample. This process requires the reverse model p φ (x t-1 |x t ) is trained to approximate the conditional probability. The process of sampling with back diffusion and obtaining high fidelity x0 can be formulated as:

[0079]

[0080] Among them, p(x 0:T ) represents the joint probability distribution of the state sequence during the entire diffusion process, p(x T ) means that at time step T x T The probability distribution of It is the conditional probability product in the reverse diffusion process.

[0081] In the inverse denoising process, a Parameterized As x t The denoising function, then the next sample value is expressed as Perform the above forward diffusion steps K times for the sample to be processed, and the diffusion is x K ~q(x K |x0) and then run the above reverse denoising process K times A natural and realistic synthetic sample can be obtained. The execution times K are determined according to actual needs, and the present invention does not make any specific limitation here. This process can be formulated as:

[0082]

[0083] Wherein, S(x,K) represents a synthetic sample obtained after performing the above forward diffusion step K times and the above reverse denoising process K times on the sample to be processed.

[0084] Since deleting real data or synthetic data will reduce the generalization ability of adversarial samples, the present invention solves this limitation by mixing real data with synthetic data. Specifically, the method of mixing the second sample image and the synthetic sample is:

[0085] x′=λ·x+(1-λ)·S(x)

[0086] Wherein, x is the second sample image, S(x) is the synthesized sample, x′ is the mixed image, and λ is the mixing ratio of the sample image and the synthesized sample, preferably 0.7.

[0087] Specifically, when calculating the synthetic sample, the same sample to be processed can be calculated multiple times to obtain multiple synthetic samples, and the second sample is mixed with the multiple synthetic samples obtained by calculation to obtain multiple mixed images. The specific number of synthetic samples generated is determined according to actual needs, and this embodiment does not make a specific limitation here. After obtaining the multiple mixed images, the image gradients corresponding to the multiple mixed images are calculated respectively, and the adversarial noise is obtained after calculating the average gradient, and the first sample image is attacked to obtain the adversarial sample.

[0088] When generating synthetic samples based on the image to be processed, the number of executions K of the forward diffusion process and the reverse denoising process controls the balance between the generation error of the synthetic samples and the sample difference. A too large K value will introduce more errors and completely distort the synthetic samples, while a too small K value will not provide enough difference to distinguish the synthetic samples from the image to be processed. Generally, the forward diffusion step is performed K times on the sample to be processed, and then the reverse denoising process is run K times to obtain a natural and realistic synthetic sample.

[0089] Preferably, in order to improve the difference between the synthetic sample and the image to be processed on the basis of ensuring the authenticity of the synthetic sample, the forward diffusion step and the reverse denoising step can be performed alternately, which can effectively avoid excessive noise accumulation and further improve the authenticity of the synthetic sample. Specifically, when the execution process K=1000 of the forward diffusion process or the reverse denoising process (i.e., the total number of executions K′=2000), if the forward diffusion step is performed 1000 times and then the reverse denoising process is performed 1000 times, the image details will be lost. At this time, Q=200 is selected as the alternating step number, and the forward diffusion step and the reverse denoising process are performed alternately until the predetermined total number of executions is completed. In the process of generating the synthetic sample, denoising is gradually performed to avoid the loss of image details caused by excessive diffusion, and the generation and authenticity of the synthetic sample are effectively balanced.

[0090] Embodiment 2

[0091] Please refer to Figure 1 Embodiment 2 of the present invention provides a method for generating adversarial samples. Based on Embodiment 1, the method for performing data enhancement on the second data set is as follows:

[0092] Traversing the second data set to obtain a fourth sample image;

[0093] Partitioning the fourth sample image to obtain n image blocks, where n is a non-zero natural number;

[0094] Data enhancement is performed on the image block to obtain a third data set.

[0095] The fourth sample image can be partitioned by horizontally partitioning, vertically partitioning, etc. The specific partitioning method is determined according to actual needs, and this embodiment does not make any specific limitations here. After the fourth sample image is partitioned, the number of image blocks obtained is determined according to actual needs, and this embodiment does not make any specific limitations here.

[0096] Among them, the method for data enhancement of the second data set can be image grayscale transformation, geometric correction, image pixel transformation or image filtering processing, or it can be any image processing method that can make the image different from the original image and retain the visual similarity of the image. The specific method for data enhancement of the second data set is determined according to actual needs.

[0097] Specifically, the method for performing data enhancement on the second image data set may be:

[0098] Traversing the second data set to obtain a fifth sample image;

[0099] Calculating a first fine-grained saliency map corresponding to the fifth sample image;

[0100] Partitioning the fifth sample image according to the first fine-grained saliency map to obtain m image blocks, where m is a non-zero natural number;

[0101] Data enhancement is performed on the image block to obtain a third data set.

[0102] Specifically, the semantic information content of different regions of the same image is different, and the semantic distribution of the image can be obtained by calculating the fine-grained saliency map. The fine-grained saliency map is obtained by fusing the class activation maps of the shallow layer, the middle layer and the deep layer of the model. For the class activation map of a certain layer of the model, LayerCAM is used to obtain the relationship between the feature map and its corresponding gradient. The specific implementation formula is as follows:

[0103]

[0104] Among them, f represents the image classifier, θ represents its parameters, I is the given image, c is the target category, A k represents the feature map of the kth layer, represents the activation value corresponding to the k-th layer feature map at the spatial position (i, j), Represents the target category c to feature map A k The gradient at position (i, j); ReLU means that the weights are calculated based on the gradient of the feature map using the rectified linear unit (ReLU) algorithm, and the weights are multiplied by the corresponding feature activation values ​​to obtain the weighted activation values ​​for each spatial position. K is the total number of feature maps, To map all weighted features The sum is performed to merge the features learned by different layers in the network, and finally the ReLU function is applied to the sum result to remove the negative response to obtain the class activation map M of this layer cSince the class activation maps between different layers are quite different, in order to effectively retain the class activation values ​​of the shallow layer and achieve effective fusion of each layer, this method processes the class activation map of the shallow layer. The process formula is as follows:

[0105]

[0106] in, is the processed shallow class activation map, M c Activates the mapping for the original shallow class. Normalization and nonlinear transformation using the tanh() function can effectively enhance the contrast of shallow feature maps while reducing the impact of abnormal activation values, thus avoiding their weakening effect relative to deep features.

[0107] Specifically, Figure 3 Schematic diagram of fine-grained saliency calculation. Figure 4-7 The above diagram shows the activation mapping of each layer class corresponding to the image, and the fine-grained saliency mapping result obtained after fusing each layer. It can be understood that after the present invention calculates the fine-grained saliency mapping of the image by the above method, the image blocks are partitioned according to the fine-grained saliency mapping, so that the number of image blocks in the concentrated part of the image semantic distribution is greater than the number of image blocks in the irrelevant part, thereby ensuring the anti-attack performance. The specific number of partitions is determined according to the image size and actual needs, and the present invention does not make specific limitations here.

[0108] Furthermore, the method for performing data enhancement on the image block is:

[0109] Generate an image transformation set, wherein the image transformation set includes a displacement transformation set and a pixel transformation set;

[0110] The image blocks are respectively input into the displacement transformation set and / or the pixel transformation set to obtain a third data set.

[0111] The displacement transformation set includes vertical shift, horizontal shift, vertical flip, horizontal inversion, rotation or scaling of the image block; the pixel transformation set includes discrete cosine transform, adding noise, and randomly discarding pixels of the image block. When the image block is input into the displacement transformation set and / or the pixel transformation set respectively, one or more image processing methods in the displacement transformation set and / or the pixel transformation set are randomly applied. The specific method is determined according to actual needs and is not specifically limited in this embodiment.

[0112] Embodiment 3

[0113] Please refer to Figure 1Embodiment 3 of the present invention provides a method for generating an adversarial sample. Based on Embodiment 1 and / or Embodiment 2, the adversarial noise corresponding to the third data set is calculated and the first sample image is processed according to the adversarial noise. The method for generating the adversarial sample is:

[0114] Calculating a second fine-grained saliency map corresponding to the first sample image;

[0115] Traversing the third data set to obtain a sixth sample image;

[0116] calculating adversarial noise corresponding to the sixth sample image, and optimizing the adversarial noise according to the second fine-grained saliency map;

[0117] The first sample image is attacked according to the optimized adversarial noise to obtain an adversarial sample.

[0118] Among them, please refer to Example 2 for the calculation method of the second fine-grained saliency map, which will not be repeated in this embodiment. After obtaining the second fine-grained saliency map, the adversarial noise is optimized using the mean of the obtained mapping as the demarcation value. For strong pixels whose mapping values ​​are greater than the demarcation value, the disturbance is gradually enhanced, and for weak pixels whose mapping values ​​are less than the demarcation value, the disturbance is gradually weakened, so as to reduce the impact of the disturbance on non-critical pixels in the image and achieve precise attack. The calculation form is shown in the formula:

[0119]

[0120] r cur =β (i,j) ·r pre

[0121] Among them, β (i,j) is the perturbation optimization factor calculated from the mapping mean, μ M is the mapping mean, M is the output fine-grained saliency map, (i, j) is the pixel position of the fine-grained saliency map, and r cur is the current optimized perturbation guided by the fine-grained saliency map, r pre The original disturbance.

[0122] Specifically, according to the actual needs of the adversarial attack, the adversarial sample generation method can be iteratively executed, that is, for each iteration, the adversarial sample generated by the previous iteration is used as input, the synthetic sample is repeatedly calculated and the steps of data enhancement, image gradient calculation, etc. are continued. The specific number of iterations is determined according to the actual needs, and this embodiment is not specifically limited here. The adversarial sample generation method provided by the present invention effectively introduces synthetic data to improve the generalization ability of samples; uses block segmentation multi-directional transformation to obtain richer feature information, and performs different image enhancement transformations before calculating the gradient, eliminating the instability introduced by the large transformation difference; finally, based on the image fine-grained saliency mapping results, the perturbation size of different pixels is optimized, so that the perturbation gradient acts on the iterative sample.

[0123] In order to verify the performance comparison between the adversarial sample generation method provided by the present invention and the existing adversarial attack methods, the experiment uses four conventionally trained networks as white-box models to generate adversarial samples, including Inc-v3, Inc-v4, IncRes-v2 and Res-101; and three adversarial training models Inc-v3ens3, Inc-v3ens4, and IncRes-v2ens are selected as black-box models to test the migration performance of adversarial samples.

[0124] Five existing input-based adversarial attack methods (DIM, TIM, SIM, Admix, and PAM) are selected as comparison baselines and analyzed and compared with the adversarial sample generation method. Among them, DIM uses a transition probability p = 0.5; TIM uses a Gaussian kernel of size 7×7; SIM uses a scaling number of 5 and a scaling size of In Admix, the number of mixed images m1=5, the number of sampled images m2=3, and the sampling intensity η=0.2 are set; in PAM, the number of image copies m=4 and the number of enhancement paths are set to 8. In this method, the number of calculated synthetic sample images n=20, the mixing ratio λ=0.7, and the number of segmented image blocks are set to 9. According to the experimental results, when the adversarial sample generation method provided by the present invention is used to attack the adversarial training model, the highest black box attack success rate is achieved. When the adversarial sample generated by the present method is used to attack the adversarial training model using the Res-101 model, the average success rate is 61.5%, which is 29.7%, 31.8%, 25.7%, 20.3%, and 18.6% higher than the other methods, respectively.

[0125] Embodiment 4

[0126] Please refer to Figure 1-2 , Embodiment 4 of the present invention provides an adversarial sample generation system, the system comprising:

[0127] The sample acquisition unit is used to: obtain a first data set, wherein the first data set includes a plurality of first sample images;

[0128] A sample processing unit, configured to: calculate a synthetic sample, and update the first data set according to the synthetic sample to obtain a second data set;

[0129] A sample enhancement unit, used to: perform data enhancement on the second data set to obtain a third data set;

[0130] The sample generation unit is used to calculate the image gradient and obtain the adversarial sample according to the image gradient.

[0131] Embodiment 5

[0132] Please refer to Figure 1 Embodiment 5 of the present invention provides an adversarial sample generation device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any one of the adversarial sample generation methods described above when executing the computer program.

[0133] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors, application-specific integrated circuits, field programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0134] The memory can be used to store the computer program and / or module, and the processor implements the steps of the adversarial sample generation method in the invention by running or executing the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory can include a high-speed random access memory and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card, a secure digital card, a flash memory card, at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0135] If the adversarial sample generation device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the process in the above-mentioned embodiment method, and can also be stored in a computer-readable storage medium through a computer program. When the computer program is executed by the processor, the steps of each of the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device that can carry the computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory, random access memory, point carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction.

[0136] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0137] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A method for generating adversarial samples, characterized in that: The adversarial sample generation method comprises: Obtaining a first data set, wherein the first data set includes a plurality of first sample images; Calculating a synthetic sample, and updating the first data set according to the synthetic sample to obtain a second data set; Performing data enhancement on the second data set to obtain a third data set; The adversarial noise corresponding to the third data set is calculated and the first sample image is processed according to the adversarial noise to generate an adversarial sample.

2. The adversarial sample generation method according to claim 1, characterized in that: The method of calculating the synthetic sample and updating the first data set according to the synthetic sample to obtain the second data set is: Sampling the first data set to obtain a second sample image; Calculating a synthetic sample corresponding to the second sample image, and mixing the second sample image and the synthetic sample to obtain a third sample image; The third sample image is added to the first data set to obtain a second data set.

3. The adversarial sample generation method according to claim 1 or 2, characterized in that: The method to calculate the synthetic sample is: Obtaining an image to be processed; Superimposing noise data on the image to be processed to obtain first data; The first data is subjected to denoising processing to obtain a synthetic sample.

4. The adversarial sample generation method according to claim 2, characterized in that: The method of mixing the second sample image and the synthesized sample is: x ′ =λ x+(1-λ) S(x) Wherein, x is the second sample image, S(x) is the synthesized sample, x′ is the mixed image, and λ is the mixing ratio of the sample image and the synthesized sample.

5. The adversarial sample generation method according to claim 1, characterized in that: The method for performing data enhancement on the second data set is: Traversing the second data set to obtain a fourth sample image; Partitioning the fourth sample image to obtain n image blocks, where n is a non-zero natural number; Data enhancement is performed on the image block to obtain a third data set.

6. The adversarial sample generation method according to claim 1, characterized in that: The method for performing data enhancement on the second image data set is: Traversing the second data set to obtain a fifth sample image; Calculating a first fine-grained saliency map corresponding to the fifth sample image; Partitioning the fifth sample image according to the first fine-grained saliency map to obtain m image blocks, where m is a non-zero natural number; Data enhancement is performed on the image block to obtain a third data set.

7. The adversarial sample generation method according to claim 5 or 6, characterized in that: The method for performing data enhancement on the image block is: Generate an image transformation set, wherein the image transformation set includes a displacement transformation set and a pixel transformation set; The image blocks are respectively input into the displacement transformation set and / or the pixel transformation set to obtain a third data set.

8. The adversarial sample generation method according to any one of claims 1, characterized in that: The method of calculating the adversarial noise corresponding to the third data set and processing the first sample image according to the adversarial noise to generate the adversarial sample is: Calculating a second fine-grained saliency map corresponding to the first sample image; Traversing the third data set to obtain a sixth sample image; calculating adversarial noise corresponding to the sixth sample image, and optimizing the adversarial noise according to the second fine-grained saliency map; The first sample image is attacked according to the optimized adversarial noise to obtain an adversarial sample.

9. A system for generating adversarial samples, characterized in that: The system comprises: The sample acquisition unit is used to: obtain a first data set, wherein the first data set includes a plurality of first sample images; A sample processing unit, configured to: calculate a synthetic sample, and update the first data set according to the synthetic sample to obtain a second data set; A sample enhancement unit, used to: perform data enhancement on the second data set to obtain a third data set; The sample generating unit is used to calculate the adversarial noise corresponding to the third data set and process the first sample image according to the adversarial noise to generate an adversarial sample.

10. An adversarial sample generation device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, it implements the adversarial sample generation method as described in any one of claims 1-8.