An Adversarial Sample Generation Method and System Based on Dynamic Advanced Iteration
By introducing dynamic leading iteration strategies into the adversarial sample generation method and dynamically adjusting the leading factor, the problems of overfitting and local optimization of adversarial sample generation methods in the existing technology are solved, and more efficient and stable adversarial sample generation is achieved.
Patent Information
- Application Number
- CN202510510088.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-04-23
AI Technical Summary
The adversarial samples generated by existing adversarial sample generation methods often overfit the network parameters of the alternative model, resulting in local optimal problems, poor performance and unsatisfactory migration results.
Using a method based on dynamic advance iteration, dynamically adjust the advance factor, dynamically adjust the advance offset according to the iteration process stage, optimize the gradient direction, and generate more efficient and stable adversarial samples.
It effectively avoids the negative effects of initial momentum instability or local gradient noise, improves the robustness and smoothness of the update process, and improves the performance and migration effect of the countermeasures.
Smart Images

Figure CN120032191B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of artificial intelligence security, and in particular relates to an adversarial sample generation method and system based on dynamic advanced iteration. Background Technique
[0002] The statements in this part only provide background technical information related to the present invention and do not necessarily constitute prior art.
[0003] In recent years, image classification models based on deep learning have been widely studied in the academic community and widely applied in industry. However, deep learning is inherently vulnerable to adversarial attacks. Adversarial samples are a type of carefully designed images generated by adding tiny and imperceptible non-random perturbations to the input images, which can cause deep learning models to produce incorrect prediction results, posing a serious threat to the application of deep learning models. To protect people's safety and artificial intelligence systems from malicious attacks and misguidance, in-depth research on adversarial samples is imminent and of great significance.
[0004] In the process of generating adversarial samples, existing adversarial sample generation methods, such as MI-FSGM (Momentum Iterative Fast Gradient Sign Method) and NIFGSM (Nesterov Iterative Fast Gradient Sign Method), generate adversarial samples by iteratively calculating gradients and accumulating momentum. Among them, NIFGSM, on the basis of MIFGSM, introduces accelerated gradient (NAG) and uses a fixed-step forward-looking strategy to calculate the gradient after advancing and offsetting along the momentum direction on the basis of the current adversarial sample, so as to improve the forward-looking and attack transferability of the gradient. However, the inventor found that the above methods still have the following problems:
[0005] The adversarial samples generated by existing adversarial sample generation methods often overfit the network parameters of the surrogate model, and then fall into a poor local optimum, resulting in poor performance and unsatisfactory transfer effect of the found adversarial samples, so that the adversarial samples generated on the surrogate model have a poor attack effect when attacking other models. It is specifically reflected in the following three aspects.
[0006] (1) The fixed offset has limitations. NIFGSM uses a fixed forward-looking distance to obtain the offset point in each iteration. This fixed offset cannot adapt to the optimization process at different stages. When the momentum is not yet stable in the initial stage, directly using a fixed offset may lead to inaccurate gradient estimation. In the later stage, the fixed offset may not be sufficient to fully capture the trend of future updates, limiting the efficiency and transferability of the attack.
[0007] (2) Insufficient consideration of momentum stability. In the initial stage of iteration, due to large changes in the gradient direction, the accumulated momentum may be unstable. At this time, a fixed forward offset is likely to introduce noise, affecting the reliability of gradient estimation. In the later stage of iteration, when the momentum tends to be stable, there is an opportunity to utilize a larger forward offset to obtain more forward-looking gradient information. However, the fixed offset cannot be adjusted according to this stability.
[0008] (3) Insufficient accuracy of gradient estimation. Since the adversarial samples, gradients, and momenta change in each iteration step, a fixed offset may lead to a deviation between the calculated gradient and the actual optimal update direction. If the forward offset is too large, it may cause the gradient calculation position to deviate far from the true state; if the offset is too small, the "future" information cannot be fully utilized. Summary of the Invention
[0009] To overcome the deficiencies of the above-mentioned prior art, the present invention provides an adversarial sample generation method and system based on dynamic forward iteration, effectively avoiding the negative impacts caused by unstable momentum or local gradient noise in the initial stage. At the same time, while maintaining a fixed perturbation step size to control the attack intensity, by optimizing the utilization of the gradient direction, the overall resource consumption is reduced, providing a more efficient, stable, and stronger generalization ability adversarial attack solution for practical applications.
[0010] To achieve the above object, one or more embodiments of the present invention provide the following technical solutions:
[0011] The first aspect of the present invention provides an adversarial sample generation method based on dynamic forward iteration;
[0012] An adversarial sample generation method based on dynamic forward iteration includes:
[0013] Step S1, obtaining the original image and performing preprocessing to generate an initial adversarial sample;
[0014] Step S2, initializing the running parameters, where the running parameters include accumulated momentum, delayed start iteration times, gradually increasing iteration times, forward factor, maximum preset forward factor, iteration times, and momentum coefficient;
[0015] Step S3, inputting the running parameters and the initial adversarial sample into the surrogate model for iterative calculation. The surrogate model calculates the forward factor before each iteration, determines the iteration process stage according to the current iteration times, and dynamically adjusts the forward factor according to the judgment result;
[0016] Step S4, obtaining the accumulated momentum of the current iteration process stage, calculating the forward position based on the accumulated momentum and the dynamically adjusted forward factor, calculating the loss function gradient according to the forward position, and updating the accumulated momentum based on the loss function gradient;
[0017] Step S5: Update the adversarial example according to the updated cumulative momentum, and clip the updated adversarial example using a clipping function to obtain a clipped adversarial perturbation.
[0018] Step S6: Determine whether the current iteration number has reached the maximum iteration number. If so, the obtained clipped adversarial perturbation is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate a final adversarial example. If the maximum iteration number has not been reached, repeat Steps S3 to S6.
[0019] As a further technical solution, the process of obtaining the original image and performing preprocessing to generate an initial adversarial example in Step S1 is as follows:
[0020] Convert the original image to a tensor and perform normalization processing to reduce the pixel range of the original image to obtain a processed original image tensor.
[0021] Construct a zero tensor with the same shape as the original image tensor, use the zero tensor as the initial adversarial perturbation, and add it to the original image tensor to generate an initial adversarial example.
[0022] As a further technical solution, the process of determining the iteration process stage according to the current iteration number and dynamically adjusting the leading factor according to the judgment result is as follows:
[0023] When , it is determined that the iteration process is in the delayed start stage, where is the iteration number, is the delayed start iteration number; set the leading factor to 0, indicating that the leading factor is not used in the initial stage and wait for the momentum to stabilize before enabling it.
[0024] When , it is determined that the iteration process is in the progressive increase stage. First, calculate the basic leading factor based on the iteration steps as follows:
[0025] ;
[0026] In the formula, is the basic leading factor; is the maximum preset leading factor; is the progressive increase iteration number;
[0027] When the iteration number , perform adaptive adjustment based on momentum stability, and calculate the cosine similarity of the momentum vectors of two consecutive steps as follows:
[0028] ;
[0029] In the formula, is the cosine similarity; is the historical momentum accumulated in the previous t - 1 iterations; is the historical momentum accumulated in the previous t - 2 iterations; is a constant used to avoid division by zero;
[0030] Finally, the dynamically adjusted leading factor is as follows:
[0031] ;
[0032] In the formula, is the dynamically adjusted leading factor.
[0033] As a further technical solution, calculate the leading position based on the cumulative momentum and the dynamically adjusted leading factor, calculate the loss function gradient according to the leading position, and the process of updating the cumulative momentum based on the loss function gradient is:
[0034] The process of calculating the leading position based on the cumulative momentum and the dynamically adjusted leading factor is as follows:
[0035] ;
[0036] In the formula, is the leading position; is the adversarial sample generated in the (t - 1)-th iteration; is the dynamically adjusted leading factor; is the historical momentum accumulated in the previous t - 1 iterations.
[0037] Calculate the classifier loss using the Logit loss function, and calculate the loss function gradient at the leading position, as follows:
[0038] ;
[0039] In the formula, is the loss function gradient; represents gradient calculation, represents the loss function; represents the correct classification label of the source image;
[0040] Normalize the loss function gradient to obtain the normalized gradient of the current iteration; combine the current normalized gradient with the current cumulative momentum to update the cumulative momentum, and the updated cumulative momentum is:
[0041]
[0042] In the formula, is the updated cumulative momentum; is the momentum coefficient, is the historical momentum accumulated in the previous t-1 iterations; is the gradient after normalization in the current iteration.
[0043] As a further technical solution, the Logit loss function includes a classification loss for non-targeted attacks and a classification loss for targeted attacks; among them, the classification loss for non-targeted attacks is:
[0044] ;
[0045] In the formula, represents the classification model, represents the adversarial sample after being offset by a dynamic lead factor during the progressive increase of iterations; represents the correct category of the original image;
[0046] The classification loss for targeted attacks is:
[0047] ;
[0048] In the formula, represents the target category that misleads the classification model in the targeted attack.
[0049] As a further technical solution, the updated adversarial sample in step S5 is:
[0050] ;
[0051] In the formula, is the updated cumulative momentum, is the adversarial sample generated in the current iteration, is the adversarial sample generated in the previous iteration; is the perturbation step size; is the sign function.
[0052] As a further technical solution, the updated adversarial sample is cropped using a cropping function, and the cropping process is shown in the following formula:
[0053] ;
[0054] In the formula, is the adversarial sample generated in the current t-th iteration; is the cropping function; is the perturbation step size; is the adversarial sample generated in the previous iteration; is the sign function.
[0055] The second aspect of the present invention provides an adversarial sample generation system based on dynamic lead iteration.
[0056] An adversarial sample generation system based on dynamic advanced iteration, comprising:
[0057] An initial adversarial sample generation module, configured to: obtain an original image and perform preprocessing to generate an initial adversarial sample;
[0058] An operating parameter initialization module, configured to: initialize operating parameters, where the operating parameters include cumulative momentum, delayed start iteration times, progressive increase iteration times, advanced factor, maximum preset advanced factor, iteration times, and momentum coefficient;
[0059] An advanced factor adjustment module, configured to: input the operating parameters and the initial adversarial sample into a surrogate model for iterative calculation. The surrogate model calculates the advanced factor before each iteration, determines the iterative process stage according to the current iteration times, and dynamically adjusts the advanced factor according to the determination result;
[0060] A cumulative momentum update module, configured to: obtain the cumulative momentum of the current iterative process stage, calculate the advanced position based on the cumulative momentum and the dynamically adjusted advanced factor, calculate the loss function gradient according to the advanced position, and update the cumulative momentum based on the loss function gradient;
[0061] A final adversarial perturbation generation module, configured to: update the adversarial sample according to the updated cumulative momentum, and use a clipping function to clip the updated adversarial sample to obtain a clipped adversarial perturbation;
[0062] A final adversarial sample generation module, configured to: determine whether the current iteration times reach the maximum iteration times. If so, the obtained clipped adversarial perturbation is the final adversarial perturbation, and add the final adversarial perturbation to the original image to generate a final adversarial sample; if the maximum iteration times are not reached, repeat the steps in the advanced factor adjustment module, the cumulative momentum update module, the final adversarial perturbation generation module, and the final adversarial sample generation module.
[0063] The third aspect of the present invention provides a computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, the steps in an adversarial sample generation method based on dynamic advanced iteration as described in the first aspect of the present invention are implemented.
[0064] The fourth aspect of the present invention provides an electronic device, including a memory, a processor, and a program stored on the memory and executable on the processor. When the processor executes the program, the steps in an adversarial sample generation method based on dynamic advanced iteration as described in the first aspect of the present invention are implemented.
[0065] The above one or more technical solutions have the following beneficial effects:
[0066] (1) By introducing an advance factor and dynamically adjusting it, in the initial stage of iteration, due to unstable momentum, the advance factor can be set to a small value or even 0 (delayed start); after the momentum stabilizes, the advance factor is gradually increased to obtain a more accurate gradient estimate, and then the adaptive offset distance is used to solve the limitation of the fixed offset, ensuring the momentum stability in different stages of the iteration process and enhancing the accuracy of gradient estimation. Furthermore, it effectively avoids the negative impacts brought by unstable initial momentum or local gradient noise, improving the robustness and smoothness of the update process.
[0067] (2) The gradient obtained by advance calculation in the present invention is more in line with the global update trend, so the generated adversarial perturbations not only have significant effects on the current model, but also can improve the cross-model transferability, making the attack more universal; while maintaining a fixed perturbation step size to control the attack intensity, by optimizing the utilization of the gradient direction, the overall resource consumption is reduced, providing a more efficient, stable and more generalization-capable adversarial attack scheme for practical applications.
[0068] (3) The present invention can be flexibly combined with existing improved strategies for adversarial attacks (such as adversarial attacks based on data augmentation, adversarial attacks based on features) to form a new attack method of "advance + X". And the advance iteration method has no special requirements for the model structure and loss function, as long as the gradient can be calculated or estimated. Therefore, it can not only be applied to the field of image classification, but also can be applied to adversarial attacks in a variety of scenarios (images, texts, audios) and a variety of models (CNNs, Transformers, etc.).
[0069] The advantages of additional aspects of the present invention will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present invention. Brief Description of the Drawings
[0070] The accompanying drawings forming a part of this specification are used to provide a further understanding of the present invention, and the schematic embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation to the present invention.
[0071] Figure 1 It is a flowchart of the method for the first embodiment.
[0072] Figure 2 It is a system structure diagram for the second embodiment. Detailed Description of the Specific Embodiment
[0073] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0074] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention.
[0075] In the case of no conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0076] The present invention first processes the original image to generate an initial adversarial sample, and then sends the initial adversarial sample into a surrogate model. A dynamic leading strategy with adaptive adjustment is introduced into the surrogate model. Specifically, a dynamically adjustable leading factor is introduced to calculate the loss value according to the output of the model, and the adversarial perturbation is iteratively updated through gradient calculation to generate the final adversarial sample.
[0077] Embodiment 1
[0078] This embodiment discloses an adversarial sample generation method based on dynamic leading iteration;
[0079] As Figure 1 shown, an adversarial sample generation method based on dynamic leading iteration includes:
[0080] Step S1, obtaining the original image and performing preprocessing to generate an initial adversarial sample;
[0081] Step S11, converting the original image into a tensor, normalizing or standardizing the pixels of the original image, reducing the pixel range from [0, 255] to within [0, 1], and obtaining the processed original image tensor.
[0082] Step S12, constructing a zero tensor with the same shape as the original image tensor, using the zero tensor as the initial adversarial perturbation, adding it to the original image tensor, and generating an initial adversarial sample . By iteratively updating the initial adversarial perturbation, when the maximum number of iterations is reached, the final adversarial perturbation is generated.
[0083] Step S2, initializing the running parameters, where the running parameters include cumulative momentum , delayed start iteration number , gradually increasing iteration number , leading factor , maximum preset leading factor , iteration number and momentum coefficient ;
[0084] Step S3: Input the operating parameters and the initial adversarial sample into the surrogate model for iterative calculation. The surrogate model calculates the lead factor before each iteration, determines the stage of the iterative process based on the current iteration number, and dynamically adjusts the lead factor according to the judgment result. Specifically, the surrogate model calculates the lead factor for the current iterative process before each iterative process , and determines the stage of the iterative process based on the current iteration number.
[0085] Specifically, when , it is determined that the iterative process is in the delayed start stage. At this time, the lead factor is set to 0, indicating that the lead factor is not used in the initial stage for calculation, and it will be enabled after the momentum stabilizes;
[0086] When , it is determined that the iterative process is in the progressive increase stage. In the progressive increase stage, first calculate the basic lead factor based on the number of iterative steps , as follows:
[0087] ;
[0088] In the formula, is the basic lead factor; is the maximum preset lead factor; is the number of iterations for progressive increase;
[0089] When the iteration number , perform adaptive adjustment based on momentum stability, and calculate the cosine similarity of the momentum vectors for two consecutive steps, as shown in the following formula:
[0090] ;
[0091] In the formula, is the cosine similarity; is the current cumulative momentum; is the cumulative momentum of the previous iterative process; is a constant used to avoid division by zero problems. By calculating the cosine similarity of the momentum vectors in consecutive iterations, determine whether the current momentum is stable. If and have the same direction, it indicates that the cosine similarity is high and the momentum is stable. At this time, the lead amount can be safely increased to quickly find the adversarial sample that meets the global optimal solution. Otherwise, if the momentum is unstable, it means that the current update direction changes greatly. If the lead amount is increased further, it will cause gradient oscillation, resulting in the gradient update deviating from the attack target. At this time, reduce the lead factor.
[0092] Finally, multiply the basic lead factor by the obtained cosine similarity to obtain the dynamically adjusted lead factor, as shown in the following formula:
[0093] ;
[0094] In the formula, is the leading factor after dynamic adjustment.
[0095] Step S4: Obtain the cumulative momentum in the current iteration process stage, calculate the leading position based on the cumulative momentum and the dynamically adjusted leading factor, calculate the loss function gradient according to the leading position, and update the cumulative momentum based on the loss function gradient;
[0096] Step S41: Calculate the leading position based on the cumulative momentum in the current iteration process stage obtained in Step S3 and the dynamically adjusted leading factor. The calculation formula is as follows:
[0097] ;
[0098] In the formula, is the leading position; is the adversarial sample generated in the (t - 1)th iteration; is the dynamically adjusted leading factor; is the current cumulative momentum.
[0099] Step S42: Calculate the loss function gradient according to the leading position.
[0100] In Step S42, first calculate the classifier loss using the Logit loss function. The Logit loss function includes the classification loss for non-targeted attacks and the classification loss for targeted attacks; among them, the classification loss for non-targeted attacks is:
[0101] ;
[0102] In the formula, represents the classification model, represents the adversarial sample offset by using the dynamic leading factor during the progressive increase of the iteration process; represents the correct category of the original image;
[0103] The classification loss for targeted attacks is:
[0104] ;
[0105] In the formula, represents the target category for misleading the classification model in a targeted attack. If in the delayed start stage, replace in the above loss function with That's it.
[0106] Secondly, calculate the loss function gradient at the leading position, as follows:
[0107] ;
[0108] In the formula, is the gradient of the loss function; represents gradient calculation, represents the loss function; represents the correct classification label of the source image;
[0109] The gradient of the loss function is normalized to obtain the normalized gradient. The normalization process is shown in the following formula:
[0110] ;
[0111] In the formula, represents the gradient after the current iteration of normalization; represents gradient calculation, represents the correct classification label of the source image, represents the L1 norm of the gradient calculation.
[0112] Step S43: Combine the current normalized gradient with the current cumulative momentum to update the cumulative momentum. The updated cumulative momentum is shown in the following formula:
[0113] ;
[0114] In the formula, is the updated cumulative momentum; is the decay factor of the momentum term, is the historical momentum accumulated in the previous t - 1 iterations, is the gradient after the current iteration of normalization. Along the gradient direction of the loss function, the cumulative velocity vector is used to accelerate the gradient descent, and then escape from the local extreme point as soon as possible under the correction of the historical momentum to find the global optimum.
[0115] Step S5: Update the adversarial example according to the updated cumulative momentum, and use the clipping function to clip the updated adversarial example to obtain the clipped adversarial perturbation;
[0116] Step S51: Adjust the adversarial example using the updated momentum direction. The updated generated adversarial example is shown in the following formula:
[0117] ;
[0118] In the formula, is the updated cumulative momentum, is the adversarial example generated in the current iteration, is the adversarial example generated in the previous iteration; is the perturbation step size; is the sign function.
[0119] Step S52: Crop the adversarially generated samples iteratively to obtain the cropped adversarial perturbation and ensure that the perturbation is limited within a specified size. The cropping process is shown as follows:
[0120] ;
[0121] In the formula, is the adversarially generated sample at the current t-th iteration; is the cropping function; is the perturbation step size; is the adversarially generated sample from the previous iteration; is the sign function.
[0122] Step S6: Determine whether the current iteration number has reached the maximum iteration number. If so, the obtained cropped adversarial perturbation is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample. If the maximum iteration number has not been reached, repeat Steps S3 to S6.
[0123] Furthermore, the adversarial sample generation method based on dynamic early iteration proposed by the present invention can seamlessly expand other attack methods on it to improve the upper limit of other methods. For example, if a data augmentation method is added, data augmentation operations can be performed on the adversarial sample tensor. Specifically, here DI input transformation is used as an example when adding a data augmentation method. At each iteration, the input is transformed by the image transformation T(·) with a probability of p to alleviate the overfitting phenomenon. Random resizing (resizing the input image to a random size) and random padding (padding zeros around the input image in a random manner) are used as instantiations of the image transformation T(·). If the iteration belongs to the delayed start phase, it is T( ), and if the iteration is in the progressive increase phase, it is T( ).
[0124] Embodiment 2
[0125] This embodiment discloses an adversarial sample generation system based on dynamic early iteration;
[0126] As Figure 2 shown, an adversarial sample generation system based on dynamic early iteration includes:
[0127] An initial adversarial sample generation module, configured to: obtain the original image and perform preprocessing to generate an initial adversarial sample;
[0128] A running parameter initialization module, configured to: initialize the running parameters, where the running parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, early factor, maximum preset early factor, iteration number, and momentum coefficient;
[0129] An advanced factor adjustment module, configured to: input the operating parameters and the initial adversarial sample into a surrogate model for iterative calculation, where the surrogate model calculates an advanced factor before each iteration, determines the stage of the iterative process based on the current iteration number, and dynamically adjusts the advanced factor according to the determination result;
[0130] An accumulated momentum update module, configured to: obtain the accumulated momentum at the current stage of the iterative process, calculate an advanced position based on the accumulated momentum and the dynamically adjusted advanced factor, calculate the loss function gradient according to the advanced position, and update the accumulated momentum based on the loss function gradient;
[0131] A final adversarial perturbation generation module, configured to: update the adversarial sample according to the updated accumulated momentum, and use a clipping function to clip the updated adversarial sample to obtain a clipped adversarial perturbation;
[0132] A final adversarial sample generation module, configured to: determine whether the current iteration number reaches the maximum iteration number. If so, the obtained clipped adversarial perturbation is the final adversarial perturbation, and add the final adversarial perturbation to the original image to generate a final adversarial sample; if the maximum iteration number is not reached, repeat the steps in the advanced factor adjustment module, the accumulated momentum update module, the final adversarial perturbation generation module, and the final adversarial sample generation module.
[0133] Embodiment III
[0134] The purpose of this embodiment is to provide a computer-readable storage medium.
[0135] A computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the steps in an adversarial sample generation method based on dynamic advanced iteration as described in Embodiment 1.
[0136] Embodiment IV
[0137] The purpose of this embodiment is to provide an electronic device.
[0138] An electronic device, including a memory, a processor, and a program stored on the memory and executable on the processor, and when the processor executes the program, it implements the steps in an adversarial sample generation method based on dynamic advanced iteration as described in Embodiment 1.
[0139] In the devices of the above Second, Third, and Fourth Embodiments, the steps involved correspond to those of the First Method Embodiment. For specific implementation details, please refer to the relevant description part of the First Embodiment. The term "computer-readable storage medium" should be understood to include a single medium or multiple media containing one or more instruction sets; it should also be understood to include any medium that can store, encode, or carry an instruction set for execution by a processor and cause the processor to execute any method of the present invention.
[0140] Those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented using a general-purpose computer device. Optionally, they can be implemented using program code executable by a computing device, so that they can be stored in a storage device for execution by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple of them can be fabricated into a single integrated circuit module. The present invention is not limited to any specific combination of hardware and software.
[0141] Although the specific implementation of the present invention has been described above in conjunction with the accompanying drawings, it is not a limitation on the protection scope of the present invention. Those skilled in the art should understand that based on the technical solution of the present invention, various modifications or deformations that can be made without creative efforts by those skilled in the art are still within the protection scope of the present invention.
Claims
1. A method for generating adversarial samples based on dynamic advance iteration, characterized in that: include: Step S1, obtaining the original image and preprocessing it to generate an initial adversarial sample; Step S2, initializing operating parameters, wherein the operating parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, lead factor, maximum preset lead factor, iteration number and momentum coefficient; Step S3, input the operating parameters and the initial adversarial sample into the substitution model for iterative calculation. The substitution model calculates the lead factor before each iteration, determines the iteration process stage according to the current iteration number, and dynamically adjusts the lead factor according to the judgment result, specifically: when When , the iteration process is judged to be in the delayed start phase, where is the number of iterations, The number of delay start iterations; Set the lead factor to 0, which means that the lead factor calculation will not be used in the initial stage, and it will be enabled after the momentum stabilizes; when When , the iterative process is judged to be in the gradual increase stage. First, the basic advance factor based on the number of iteration steps is calculated as follows: ; In the formula, is the basic leading factor; is the maximum preset lead factor; Increase the number of iterations for gradual progress; When the number of iterations , adaptively adjust based on momentum stability and calculate the cosine similarity of momentum vectors of two consecutive steps, as shown in the following formula: ; In the formula, is the cosine similarity; is the historical momentum accumulated for the previous t-1 iterations; is the historical momentum accumulated for the previous t-2 iterations; is a constant used to avoid division by zero; Finally, the dynamically adjusted lead factor is as follows: ; In the formula, is the dynamically adjusted lead factor; Step S4, obtaining the cumulative momentum of the current iterative process stage, calculating the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculating the loss function gradient according to the lead position, and updating the cumulative momentum based on the loss function gradient; Step S5, updating the adversarial sample according to the updated cumulative momentum, and using the clipping function to clip the updated adversarial sample to obtain a clipped adversarial perturbation; Step S6, determine whether the current number of iterations reaches the maximum number of iterations. If so, the cropped adversarial perturbation obtained is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat steps S3 to S6.
2. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The process of obtaining the original image and preprocessing it in step S1 to generate the initial adversarial sample is as follows: The original image is converted into a tensor and normalized to reduce the pixel range of the original image to obtain the processed original image tensor; Construct an all-zero tensor with the same shape as the original image tensor, and use the all-zero tensor as the initial adversarial perturbation, add it to the original image tensor, and generate an initial adversarial sample.
3. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The process of calculating the lead position based on the accumulated momentum and the dynamically adjusted lead factor, calculating the loss function gradient according to the lead position, and updating the accumulated momentum based on the loss function gradient is as follows: The process of calculating the lead position based on the accumulated momentum and the dynamically adjusted lead factor is as follows: ; In the formula, is the advanced position; The adversarial sample generated for the t-1th iteration; is the dynamically adjusted lead factor; The historical momentum accumulated for the previous t-1 iterations The classifier loss is calculated using the Logit loss function by calculating the loss function gradient at the leading position as follows: ; In the formula, is the gradient of the loss function; represents the gradient calculation, represents the loss function; Indicates the correct classification label of the source image; The loss function gradient is normalized to obtain the normalized gradient of the current iteration; the current normalized gradient is combined with the current accumulated momentum to update the accumulated momentum, and the updated accumulated momentum is: In the formula, is the updated cumulative momentum; is the momentum coefficient, is the historical momentum accumulated for the previous t-1 iterations; is the normalized gradient of the current iteration.
4. The method for generating adversarial samples based on dynamic advance iteration according to claim 3, characterized in that: The Logit loss function includes the classification loss of non-targeted attack and the classification loss of targeted attack; wherein, the classification loss of non-targeted attack is: ; In the formula, represents the classification model, represents the adversarial sample after using the dynamic lookahead factor offset in the progressively increasing iteration process; Indicates the correct category of the original image; The target attack classification loss is: ; In the formula, Represents the target category of the targeted attack to mislead the classification model.
5. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The adversarial sample updated in step S5 is: ; In the formula, is the updated cumulative momentum, is the adversarial sample generated in the current iteration, is the adversarial sample generated in the last iteration; is the perturbation step length; is a sign function.
6. The method for generating adversarial samples based on dynamic advance iteration according to claim 1, characterized in that: The updated adversarial sample is pruned using the pruned function. The pruned process is shown in the following formula: ; In the formula, The adversarial sample generated for the current t iterations; is the clipping function; is the perturbation step length; is the adversarial sample generated in the last iteration; is a sign function.
7. A system for generating adversarial samples based on dynamic advance iteration, characterized in that: include: The initial adversarial sample generation module is configured to: obtain the original image and perform preprocessing to generate the initial adversarial sample; An operation parameter initialization module is configured to: initialize operation parameters, wherein the operation parameters include cumulative momentum, delayed start iteration number, progressive increase iteration number, lead factor, maximum preset lead factor, iteration number and momentum coefficient; The lead factor adjustment module is configured to: input the operating parameters and the initial adversarial sample into the substitution model for iterative calculation, the substitution model calculates the lead factor before each iteration, judges the iteration process stage according to the current iteration number, and dynamically adjusts the lead factor according to the judgment result, specifically: when When , the iteration process is judged to be in the delayed start phase, where is the number of iterations, The number of delay start iterations; Set the lead factor to 0, which means that the lead factor calculation will not be used in the initial stage, and it will be enabled after the momentum stabilizes; when When , the iterative process is judged to be in the gradual increase stage. First, the basic advance factor based on the number of iteration steps is calculated as follows: ; In the formula, is the basic leading factor; is the maximum preset lead factor; Increase the number of iterations for gradual progress; When the number of iterations , adaptively adjust based on momentum stability and calculate the cosine similarity of momentum vectors of two consecutive steps, as shown in the following formula: ; In the formula, is the cosine similarity; is the historical momentum accumulated for the previous t-1 iterations; is the historical momentum accumulated for the previous t-2 iterations; is a constant used to avoid division by zero; Finally, the dynamically adjusted lead factor is as follows: ; In the formula, is the dynamically adjusted lead factor; The cumulative momentum update module is configured to: obtain the cumulative momentum of the current iterative process stage, calculate the lead position based on the cumulative momentum and the dynamically adjusted lead factor, calculate the loss function gradient according to the lead position, and update the cumulative momentum based on the loss function gradient; The final adversarial perturbation generation module is configured to: update the adversarial sample according to the updated cumulative momentum, and use the clipping function to clip the updated adversarial sample to obtain the clipped adversarial perturbation; The final adversarial sample generation module is configured to: determine whether the current number of iterations reaches the maximum number of iterations. If so, the obtained cropped adversarial perturbation is the final adversarial perturbation, and the final adversarial perturbation is added to the original image to generate the final adversarial sample; if the maximum number of iterations is not reached, repeat the steps in the lead factor adjustment module, the cumulative momentum update module, the final adversarial perturbation generation module and the final adversarial sample generation module.
8. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the steps in the adversarial sample generation method based on dynamic advance iteration as described in any one of claims 1 to 6 are implemented.
9. An electronic device comprising a memory, a processor, and a program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps in the adversarial sample generation method based on dynamic advance iteration as described in any one of claims 1-6 are implemented.
Citation Information
Patent Citations
Image model testing method and apparatus, electronic device and storage medium
WO2021056746A1
Biorobot robust motion prediction method incorporating adversarial training
WO2025050351A1