Adversarial sample generation method and system based on dynamic advanced iteration
By dynamically adjusting the leading factor and optimizing the gradient direction of the adversarial sample generation method, the problem that the adversarial sample generation method in the prior art is easily trapped in local optimality, improving the performance and migration effect of the adversarial sample, and reducing resource consumption.
Patent Information
- Application Number
- CN202510510088.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-23
AI Technical Summary
The existing adversarial sample generation methods are prone to falling into local optimization, resulting in poor performance of generated adversarial samples, unsatisfactory migration effect, and the fixed offset cannot adapt to the optimization process at different stages, affecting the accuracy of gradient estimation.
Adversarial sample generation method based on dynamic advance iteration is adopted, and the advance factor is dynamically adjusted according to the different stages of the iteration process to adapt to the optimization process at different stages, and the accuracy of gradient estimation is improved by optimizing the gradient direction utilization.
It effectively avoids the negative effects of initial momentum instability or local gradient noise, improves the robustness and smoothness of the update process, improves the performance and migration effect of the countermeasures, and reduces resource consumption.
Smart Images

Figure CN120032191A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of artificial intelligence security technology, and in particular relates to a method and system for generating adversarial samples based on dynamic advance iteration. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] In recent years, image classification models based on deep learning have been widely studied in academia and widely used in industry. However, deep learning is inherently vulnerable to adversarial attacks. Adversarial samples are carefully designed images that are generated by adding tiny and imperceptible non-random perturbations to the input image, which will cause the deep learning model to produce incorrect prediction results, posing a serious threat to the application of deep learning models. In order to protect people's safety and artificial intelligence systems from malicious attacks and misleading, in-depth research on adversarial samples is urgent and of great significance.
[0004] In the process of adversarial sample generation, existing adversarial sample generation methods, such as MI-FSGM (Momentum Iterative Fast Gradient Sign Method) and NIFGSM (Nesterov Iterative Fast Gradient Sign Method), all generate adversarial samples by iteratively calculating gradients and accumulating momentum. Among them, NIFGSM introduces accelerated gradient (NAG) based on MIFGSM, using a forward-looking strategy with a fixed step size, and calculates the gradient after pre-shifting along the momentum direction based on the current adversarial sample to improve the forward-looking nature and attack mobility of the gradient. However, the inventors found that the above methods still have the following problems: The adversarial samples generated by existing adversarial sample generation methods often overfit the network parameters of the alternative model, and then fall into a poor local optimum, resulting in poor performance of the adversarial samples found and unsatisfactory migration effects, making the adversarial samples generated on the alternative model less effective when attacking other models. This is specifically reflected in the following three aspects.
[0005] (1) Fixed offsets have limitations. NIFGSM uses a fixed look-ahead distance to obtain offset points in each iteration. This fixed offset cannot adapt to the optimization process at different stages. In the early stage when the momentum is not yet stable, directly using a fixed offset may lead to inaccurate gradient estimation. In the later stage, the fixed offset may not be sufficient to fully capture the trend of future updates, limiting the efficiency and portability of the attack.
[0006] (2) Momentum stability is not fully considered. In the early stages of iteration, the accumulated momentum may be unstable due to large changes in the gradient direction. At this time, the fixed advance offset is likely to introduce noise, affecting the reliability of the gradient estimate. In the later stages of iteration, when the momentum tends to be stable, there is an opportunity to use a larger advance to obtain more forward-looking gradient information. However, the fixed offset cannot be adjusted based on this stability.
[0007] (3) Insufficient accuracy of gradient estimation. Since adversarial samples, gradients, and momentum change in each iteration, a fixed offset may cause the calculated gradient to deviate from the actual optimal update direction. If the advance offset is too large, the gradient calculation position may deviate far from the actual state; if the offset is too small, the "future" information cannot be fully utilized. Summary of the invention
[0008] In order to overcome the shortcomings of the above-mentioned prior art, the present invention provides an adversarial sample generation method and system based on dynamic advance iteration, which effectively avoids the negative impact of initial momentum instability or local gradient noise, and at the same time reduces the overall resource consumption by optimizing the gradient direction utilization while maintaining a fixed perturbation step size to control the attack intensity, thereby providing a more efficient, stable and more generalized adversarial attack solution for practical applications.
[0009] To achieve the above objectives, one or more embodiments of the present invention provide the following technical solutions: The first aspect of the present invention provides a method for generating adversarial samples based on dynamic advance iteration; A method for generating adversarial samples based on dynamic advance iteration, comprising: Step S1, obtaining the original image and preprocessing it to generate an initial adversarial sample; Step S2, initializing operating parameters, wherein the operating parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, lead factor, maximum preset lead factor, iteration number and momentum coefficient; Step S3, inputting the operating parameters and the initial adversarial sample into the substitution model for iterative calculation, wherein the substitution model calculates the lead factor before each iteration, determines the stage of the iteration process according to the current number of iterations, and dynamically adjusts the lead factor according to the determination result; Step S4, obtaining the cumulative momentum of the current iterative process stage, calculating the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculating the loss function gradient according to the lead position, and updating the cumulative momentum based on the loss function gradient; Step S5, updating the adversarial sample according to the updated cumulative momentum, and using the clipping function to clip the updated adversarial sample to obtain a clipped adversarial perturbation; Step S6, determine whether the current number of iterations reaches the maximum number of iterations. If so, the cropped adversarial perturbation obtained is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat steps S3 to S6.
[0010] As a further technical solution, the process of obtaining the original image and preprocessing it in step S1 to generate the initial adversarial sample is as follows: The original image is converted into a tensor and normalized to reduce the pixel range of the original image to obtain the processed original image tensor; Construct an all-zero tensor with the same shape as the original image tensor, and use the all-zero tensor as the initial adversarial perturbation, add it to the original image tensor, and generate an initial adversarial sample.
[0011] As a further technical solution, the process of judging the stage of the iteration process according to the current number of iterations and dynamically adjusting the lead factor according to the judgment result is as follows: when When , the iteration process is judged to be in the delayed start phase, where is the number of iterations, To delay the number of iterations; set the advance factor to 0, which means that the advance factor calculation will not be used in the initial stage, and it will be enabled after the momentum stabilizes; when When , the iterative process is judged to be in the gradual increase stage. First, the basic advance factor based on the number of iteration steps is calculated as follows: ; In the formula, is the basic leading factor; is the maximum preset lead factor; Increase the number of iterations for gradual progress; When the number of iterations , adaptively adjust based on momentum stability and calculate the cosine similarity of momentum vectors of two consecutive steps, as shown in the following formula: ; In the formula, is the cosine similarity; is the historical momentum accumulated for the previous t-1 iterations; is the historical momentum accumulated for the previous t-2 iterations; is a constant used to avoid division by zero; Finally, the dynamically adjusted lead factor is as follows: ; In the formula, is the dynamically adjusted lead factor.
[0012] As a further technical solution, the lead position is calculated based on the accumulated momentum and the dynamically adjusted lead factor, the loss function gradient is calculated according to the lead position, and the cumulative momentum is updated based on the loss function gradient. The process is: The process of calculating the lead position based on the accumulated momentum and the dynamically adjusted lead factor is as follows: ; In the formula, is the advanced position; The adversarial sample generated for the t-1th iteration; is the dynamically adjusted lead factor; is the historical momentum accumulated over the previous t-1 iterations.
[0013] The classifier loss is calculated using the Logit loss function by calculating the loss function gradient at the leading position as follows: ; In the formula, is the gradient of the loss function; represents the gradient calculation, represents the loss function; Indicates the correct classification label of the source image; The loss function gradient is normalized to obtain the normalized gradient of the current iteration; the current normalized gradient is combined with the current accumulated momentum to update the accumulated momentum, and the updated accumulated momentum is:
[0014] In the formula, is the updated cumulative momentum; is the momentum coefficient, is the historical momentum accumulated for the previous t-1 iterations; is the normalized gradient of the current iteration.
[0015] As a further technical solution, the Logit loss function includes the classification loss of non-targeted attack and the classification loss of targeted attack; wherein the classification loss of non-targeted attack is: ; In the formula, represents the classification model, represents the adversarial sample after using the dynamic lookahead factor offset in the progressively increasing iteration process; Indicates the correct category of the original image; The target attack classification loss is: ; In the formula, Represents the target category of the targeted attack to mislead the classification model.
[0016] As a further technical solution, the adversarial sample updated in step S5 is: ; In the formula, is the updated cumulative momentum, is the adversarial sample generated in the current iteration, is the adversarial sample generated in the last iteration; is the perturbation step length; is a sign function.
[0017] As a further technical solution, the updated adversarial sample is pruned using a pruned function. The pruned process is shown in the following formula: ; In the formula, The adversarial sample generated for the current t iterations; is the clipping function; is the perturbation step length; is the adversarial sample generated in the last iteration; is a sign function.
[0018] A second aspect of the present invention provides an adversarial sample generation system based on dynamic advance iteration.
[0019] A system for generating adversarial samples based on dynamic advance iteration, comprising: The initial adversarial sample generation module is configured to: obtain the original image and perform preprocessing to generate the initial adversarial sample; An operation parameter initialization module is configured to: initialize operation parameters, wherein the operation parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, lead factor, maximum preset lead factor, iteration number and momentum coefficient; A lead factor adjustment module is configured to: input the operating parameters and the initial adversarial sample into a substitution model for iterative calculation, wherein the substitution model calculates the lead factor before each iteration, determines the stage of the iteration process according to the current iteration number, and dynamically adjusts the lead factor according to the determination result; The cumulative momentum update module is configured to: obtain the cumulative momentum of the current iterative process stage, calculate the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculate the loss function gradient according to the lead position, and update the cumulative momentum based on the loss function gradient; The final adversarial perturbation generation module is configured to: update the adversarial sample according to the updated cumulative momentum, and use the clipping function to clip the updated adversarial sample to obtain the clipped adversarial perturbation; The final adversarial sample generation module is configured to: determine whether the current number of iterations reaches the maximum number of iterations. If so, the obtained cropped adversarial perturbation is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat the steps in the lead factor adjustment module, the cumulative momentum update module, the final adversarial perturbation generation module and the final adversarial sample generation module.
[0020] A third aspect of the present invention provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the steps in a method for generating adversarial samples based on dynamic advance iteration as described in the first aspect of the present invention.
[0021] The fourth aspect of the present invention provides an electronic device, comprising a memory, a processor, and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps in the method for generating adversarial samples based on dynamic advance iteration as described in the first aspect of the present invention are implemented.
[0022] One or more of the above technical solutions have the following beneficial effects: (1) The present invention introduces a look-ahead factor and dynamically adjusts it. In the early stage of iteration, due to unstable momentum, the look-ahead factor can be set to a small value or even 0 (delayed start). After the momentum stabilizes, the look-ahead factor is gradually increased to obtain a more accurate gradient estimate. The adaptive offset distance is then used to solve the limitation of the fixed offset, ensuring the momentum stability at different stages of the iteration process and enhancing the accuracy of the gradient estimate. This effectively avoids the negative impact of initial momentum instability or local gradient noise, and improves the robustness and smoothness of the update process.
[0023] (2) The gradient obtained by advance calculation in the present invention is more in line with the global update trend, so the generated adversarial perturbation is not only effective on the current model, but also improves the cross-model transferability, making the attack more universal; while maintaining a fixed perturbation step size to control the attack intensity, the overall resource consumption is reduced by optimizing the gradient direction utilization, providing a more efficient, stable and more generalized adversarial attack solution for practical applications.
[0024] (3) The present invention can be flexibly combined with existing adversarial attack improvement strategies (such as data enhancement-based adversarial attacks and feature-based adversarial attacks) to form a new "ahead + X" attack method. The ahead iteration method has no special requirements for the model structure and loss function, as long as the gradient can be calculated or estimated. Therefore, it is not only applicable to the field of image classification, but also can be applied to adversarial attacks in various scenarios (images, texts, audio) and various models (CNN, Transformer, etc.).
[0025] Advantages of additional aspects of the present invention will be given in part in the following description, and in part will become obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0027] Figure 1 This is a flow chart of the method of the first embodiment.
[0028] Figure 2 It is a system structure diagram of the second embodiment. DETAILED DESCRIPTION
[0029] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.
[0030] It should be noted that the terms used herein are for describing specific embodiments only and are not intended to be limiting of exemplary embodiments according to the present invention.
[0031] In the absence of conflict, the embodiments of the present invention and the features of the embodiments may be combined with each other.
[0032] The present invention first processes the original image to generate an initial adversarial sample, and then sends the initial adversarial sample to a substitution model. An adaptive dynamic advance strategy is introduced in the substitution model. Specifically, a dynamically adjustable advance factor is introduced to calculate the loss value according to the output of the model, and the adversarial disturbance is iteratively updated through gradient calculation to generate the final adversarial sample.
[0033] Embodiment 1 This embodiment discloses a method for generating adversarial samples based on dynamic advance iteration; like Figure 1 As shown, a method for generating adversarial samples based on dynamic advance iteration includes: Step S1, obtaining the original image and preprocessing it to generate an initial adversarial sample; Step S11: the original image Convert to a tensor, normalize or standardize the original image pixels, reduce the pixel range from [0, 255] to [0, 1], and obtain the processed original image tensor.
[0034] Step S12: construct an all-zero tensor with the same shape as the original image tensor, and use the all-zero tensor as the initial adversarial perturbation, add it to the original image tensor, and generate an initial adversarial sample. By iteratively updating the initial adversarial perturbation, when the maximum number of iterations is reached, the final adversarial perturbation is generated.
[0035] Step S2, initializing operating parameters, the operating parameters include cumulative momentum , Delay start iterations , gradually increase the number of iterations , Lead Factor , Maximum preset lead factor , Iterations and momentum coefficient ; Step S3, input the operating parameters and the initial adversarial sample into the substitution model for iterative calculation, the substitution model calculates the lead factor before each iteration, determines the stage of the iteration process according to the current iteration number, and dynamically adjusts the lead factor according to the judgment result; wherein the substitution model calculates the lead factor of the current iteration process before each iteration process , and determine the stage of the iteration process based on the current number of iterations.
[0036] Specifically, when , it is judged that the iteration process is in the delayed start stage; at this time, the advance factor is set to 0, indicating that the advance factor calculation is not used in the initial stage, and it is enabled again after the momentum is stable; when When , the iteration process is judged to be in the gradual increase stage. In the gradual increase stage, the basic advance factor based on the number of iteration steps is first calculated. , as shown below: ; In the formula, is the basic leading factor; is the maximum preset lead factor; Increase the number of iterations for gradual progress; When the number of iterations , adaptively adjust based on momentum stability and calculate the cosine similarity of momentum vectors of two consecutive steps, as shown in the following formula: ; In the formula, is the cosine similarity; is the current accumulated momentum; is the cumulative momentum of the previous iteration process; is a constant used to avoid the problem of division by zero; by calculating the cosine similarity of the momentum vector in consecutive iterations, we can determine whether the current momentum is stable. and If the direction is consistent, it means that the cosine similarity is high and the momentum is stable. At this time, you can safely increase the advance amount and quickly find adversarial samples that meet the global optimal solution; on the contrary, if the momentum is unstable, it means that the current update direction has changed a lot. If the advance amount is increased, it will cause gradient oscillation, causing the gradient update to deviate from the attack target. At this time, reduce the advance factor.
[0037] Finally, the basic advance factor is multiplied by the obtained cosine similarity to obtain the dynamically adjusted advance factor, as shown in the following formula: ; In the formula, is the dynamically adjusted lead factor.
[0038] Step S4, obtaining the cumulative momentum of the current iterative process stage, calculating the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculating the loss function gradient according to the lead position, and updating the cumulative momentum based on the loss function gradient; Step S41, calculating the lead position based on the accumulated momentum of the current iteration process stage obtained in step S3 and the dynamically adjusted lead factor, the calculation formula is as follows: ; In the formula, is the advanced position; is the adversarial sample generated in the t-1 iteration; is the dynamically adjusted lead factor; is the current accumulated momentum.
[0039] Step S42, calculating the loss function gradient according to the advance position.
[0040] In step S42, the classifier loss is first calculated using the Logit loss function, which includes the classification loss of the untargeted attack and the classification loss of the targeted attack; wherein the classification loss of the untargeted attack is: ; In the formula, represents the classification model, represents the adversarial sample after using the dynamic lookahead factor offset in the progressively increasing iteration process; Indicates the correct category of the original image; The target attack classification loss is: ; In the formula, Indicates the target category of the target attack misleading the classification model. If it is in the delayed start phase, the above loss function Replace with That's it.
[0041] Secondly, the loss function gradient is calculated at the advanced position as follows: ; In the formula, is the gradient of the loss function; represents the gradient calculation, represents the loss function; Indicates the correct classification label of the source image; The loss function gradient is normalized to obtain the normalized gradient. The normalization process is shown in the following formula: ; In the formula, Represents the normalized gradient of the current iteration; represents the gradient calculation, represents the correct classification label of the source image, Represents the L1 norm of the gradient.
[0042] Step S43, combining the current normalized gradient with the current accumulated momentum, and updating the accumulated momentum. The updated accumulated momentum is shown in the following formula: ; In the formula, is the updated cumulative momentum; is the decay factor of the momentum term, is the historical momentum accumulated in the first t-1 iterations, is the normalized gradient of the current iteration. Along the gradient direction of the loss function, the velocity vector is accumulated to accelerate the gradient descent, and then escape from the local extreme point as quickly as possible under the correction of historical momentum to find the global optimum.
[0043] Step S5, updating the adversarial sample according to the updated cumulative momentum, and using the clipping function to clip the updated adversarial sample to obtain a clipped adversarial perturbation; Step S51, using the updated momentum direction to adjust the adversarial sample, the updated adversarial sample is shown as follows: ; In the formula, is the updated cumulative momentum, is the adversarial sample generated in the current iteration, is the adversarial sample generated in the last iteration; is the perturbation step length; is a sign function.
[0044] Step S52, the iteratively generated adversarial samples are pruned to obtain pruned adversarial perturbations and ensure that the perturbations are limited within a specified size; the pruned process is shown in the following formula: ; In the formula, The adversarial sample generated for the current t iterations; is the clipping function; is the perturbation step length; is the adversarial sample generated in the last iteration; is a sign function.
[0045] Step S6, determine whether the current number of iterations reaches the maximum number of iterations. If so, the cropped adversarial perturbation obtained is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat steps S3 to S6.
[0046] Furthermore, the adversarial sample generation method based on dynamic advance iteration proposed in the present invention can seamlessly expand other attack methods on it and improve the upper limit of other methods. If a data enhancement method is added, the adversarial sample tensor can be enhanced. Specifically, the DI input transformation is used as an example of adding a data enhancement method. In each iteration, the input is transformed into an image T(·) with a probability of p to alleviate the overfitting phenomenon. Random resizing (resize the input image to a random size) and random padding (randomly fill zeros around the input image) are used as instantiations of the image transformation T(·). If the iteration belongs to the delayed start phase, it is T( ), if the iteration is in the gradual increase phase, it is T( ).
[0047] Embodiment 2 This embodiment discloses an adversarial sample generation system based on dynamic advance iteration; like Figure 2 As shown, a system for generating adversarial samples based on dynamic advance iteration includes: The initial adversarial sample generation module is configured to: obtain the original image and perform preprocessing to generate the initial adversarial sample; An operation parameter initialization module is configured to: initialize operation parameters, wherein the operation parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, lead factor, maximum preset lead factor, iteration number and momentum coefficient; A lead factor adjustment module is configured to: input the operating parameters and the initial adversarial sample into a substitution model for iterative calculation, wherein the substitution model calculates the lead factor before each iteration, determines the stage of the iteration process according to the current iteration number, and dynamically adjusts the lead factor according to the determination result; The cumulative momentum update module is configured to: obtain the cumulative momentum of the current iterative process stage, calculate the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculate the loss function gradient according to the lead position, and update the cumulative momentum based on the loss function gradient; The final adversarial perturbation generation module is configured to: update the adversarial sample according to the updated cumulative momentum, and use the clipping function to clip the updated adversarial sample to obtain the clipped adversarial perturbation; The final adversarial sample generation module is configured to: determine whether the current number of iterations reaches the maximum number of iterations. If so, the obtained cropped adversarial perturbation is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat the steps in the lead factor adjustment module, the cumulative momentum update module, the final adversarial perturbation generation module and the final adversarial sample generation module.
[0048] Embodiment 3 The purpose of this embodiment is to provide a computer-readable storage medium.
[0049] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in a method for generating adversarial samples based on dynamic advance iteration as described in Example 1.
[0050] Embodiment 4 The purpose of this embodiment is to provide an electronic device.
[0051] An electronic device comprises a memory, a processor and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps in a method for generating adversarial samples based on dynamic advance iteration as described in Example 1 are implemented.
[0052] The steps involved in the apparatuses of the above embodiments 2, 3 and 4 correspond to the method embodiment 1, and the specific implementation methods can refer to the relevant description part of embodiment 1. The term "computer-readable storage medium" should be understood as a single medium or multiple media including one or more instruction sets; it should also be understood to include any medium that can store, encode or carry an instruction set for execution by a processor and enable the processor to execute any method in the present invention.
[0053] Those skilled in the art should understand that the modules or steps of the present invention described above can be implemented by a general-purpose computer device, or alternatively, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.
[0054] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.
Claims
1. A method for generating adversarial samples based on dynamic advance iteration, characterized in that: include: Step S1, obtaining the original image and preprocessing it to generate an initial adversarial sample; Step S2, initializing operating parameters, wherein the operating parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, lead factor, maximum preset lead factor, iteration number and momentum coefficient; Step S3, inputting the operating parameters and the initial adversarial sample into the substitution model for iterative calculation, wherein the substitution model calculates the lead factor before each iteration, determines the stage of the iteration process according to the current number of iterations, and dynamically adjusts the lead factor according to the determination result; Step S4, obtaining the cumulative momentum of the current iterative process stage, calculating the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculating the loss function gradient according to the lead position, and updating the cumulative momentum based on the loss function gradient; Step S5, updating the adversarial sample according to the updated cumulative momentum, and using the clipping function to clip the updated adversarial sample to obtain a clipped adversarial perturbation; Step S6, determine whether the current number of iterations reaches the maximum number of iterations. If so, the cropped adversarial perturbation obtained is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat steps S3 to S6.
2. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The process of obtaining the original image and preprocessing it in step S1 to generate the initial adversarial sample is as follows: The original image is converted into a tensor and normalized to reduce the pixel range of the original image to obtain the processed original image tensor; Construct an all-zero tensor with the same shape as the original image tensor, and use the all-zero tensor as the initial adversarial perturbation, add it to the original image tensor, and generate an initial adversarial sample.
3. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The process of judging the iteration process stage according to the current iteration number and dynamically adjusting the lead factor according to the judgment result is as follows: when When , the iteration process is judged to be in the delayed start phase, where is the number of iterations, The number of delay start iterations; Set the lead factor to 0, which means that the lead factor calculation will not be used in the initial stage, and it will be enabled after the momentum stabilizes; when When , the iterative process is judged to be in the gradual increase stage. First, the basic advance factor based on the number of iteration steps is calculated as follows: ; In the formula, is the basic leading factor; is the maximum preset lead factor; Increase the number of iterations for gradual progress; When the number of iterations , adaptively adjust based on momentum stability and calculate the cosine similarity of momentum vectors of two consecutive steps, as shown in the following formula: ; In the formula, is the cosine similarity; is the historical momentum accumulated for the previous t-1 iterations; is the historical momentum accumulated for the previous t-2 iterations; is a constant used to avoid division by zero; Finally, the dynamically adjusted lead factor is as follows: ; In the formula, is the dynamically adjusted lead factor.
4. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The process of calculating the lead position based on the accumulated momentum and the dynamically adjusted lead factor, calculating the loss function gradient according to the lead position, and updating the accumulated momentum based on the loss function gradient is as follows: The process of calculating the lead position based on the accumulated momentum and the dynamically adjusted lead factor is as follows: ; In the formula, is the advanced position; The adversarial sample generated for the t-1th iteration; is the dynamically adjusted lead factor; The historical momentum accumulated for the previous t-1 iterations The classifier loss is calculated using the Logit loss function by calculating the loss function gradient at the leading position as follows: ; In the formula, is the gradient of the loss function; represents the gradient calculation, represents the loss function; Indicates the correct classification label of the source image; The loss function gradient is normalized to obtain the normalized gradient of the current iteration; the current normalized gradient is combined with the current accumulated momentum to update the accumulated momentum, and the updated accumulated momentum is: In the formula, is the updated cumulative momentum; is the momentum coefficient, is the historical momentum accumulated for the previous t-1 iterations; is the normalized gradient of the current iteration.
5. The method for generating adversarial samples based on dynamic advance iteration according to claim 4, characterized in that: The Logit loss function includes the classification loss of non-targeted attack and the classification loss of targeted attack; wherein, the classification loss of non-targeted attack is: ; In the formula, represents the classification model, represents the adversarial sample after using the dynamic lookahead factor offset in the progressively increasing iteration process; Indicates the correct category of the original image; The target attack classification loss is: ; In the formula, Represents the target category of the targeted attack to mislead the classification model.
6. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The adversarial sample updated in step S5 is: ; In the formula, is the updated cumulative momentum, is the adversarial sample generated in the current iteration, is the adversarial sample generated in the last iteration; is the perturbation step length; is a sign function.
7. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The updated adversarial sample is pruned using the pruned function. The pruned process is shown in the following formula: ; In the formula, The adversarial sample generated for the current t iterations; is the clipping function; is the perturbation step length; is the adversarial sample generated in the last iteration; is a sign function.
8. A system for generating adversarial samples based on dynamic advance iteration, characterized in that: include: The initial adversarial sample generation module is configured to: obtain the original image and perform preprocessing to generate the initial adversarial sample; An operation parameter initialization module is configured to: initialize operation parameters, wherein the operation parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, lead factor, maximum preset lead factor, iteration number and momentum coefficient; A lead factor adjustment module is configured to: input the operating parameters and the initial adversarial sample into a substitution model for iterative calculation, wherein the substitution model calculates the lead factor before each iteration, determines the stage of the iteration process according to the current iteration number, and dynamically adjusts the lead factor according to the determination result; The cumulative momentum update module is configured to: obtain the cumulative momentum of the current iterative process stage, calculate the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculate the loss function gradient according to the lead position, and update the cumulative momentum based on the loss function gradient; The final adversarial perturbation generation module is configured to: update the adversarial sample according to the updated cumulative momentum, and use the clipping function to clip the updated adversarial sample to obtain the clipped adversarial perturbation; The final adversarial sample generation module is configured to: determine whether the current number of iterations reaches the maximum number of iterations. If so, the obtained cropped adversarial perturbation is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat the steps in the lead factor adjustment module, the cumulative momentum update module, the final adversarial perturbation generation module and the final adversarial sample generation module.
9. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the steps in the adversarial sample generation method based on dynamic advance iteration as described in any one of claims 1 to 7 are implemented.
10. An electronic device comprising a memory, a processor, and a program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps in the adversarial sample generation method based on dynamic advance iteration as described in any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Image confrontation attack method based on gradient correction
CN113392905A
Adversarial sample generation method and system based on data enhancement and maximum absolute difference
CN117934914A
Adversarial sample generation method and system based on AMADam
CN119274014A
Image model testing method and apparatus, electronic device and storage medium
WO2021056746A1
Method and apparatus for generating facial recognition adversarial sample, and storage medium
WO2024041346A1
Cited By
Multi-feature attention adversarial sample generation method and system based on frequency domain guidance
CN121328632A
Anti-attack method fusing frequency domain information and dynamic gradient smoothing
CN121544987A