Attack and defense method based on automatic machine learning

Through automatic machine learning technology, we define the search space and evaluation criteria for adversarial attacks and defenses, and automatically design a robust network architecture and a combination of adversarial attack algorithms, solving the problem that it is difficult to fairly compare the advantages and disadvantages of the algorithm in the existing technology and the separation of adversarial attacks and defense research, improving the robustness of the model and the effectiveness of adversarial attacks.

CN120047770APending Publication Date: 2025-05-27NAT INNOVATION INST OF DEFENSE TECH PLA ACAD OF MILITARY SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510089621.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

There are differences in search space, search strategies and evaluation criteria in existing automatic machine learning in adversarial attacks and defenses, which makes it difficult to compare the advantages and disadvantages of the algorithm fairly, and the research on adversarial attacks and defenses is separated, resulting in insufficient robustness of the model.

Method used

A method of adversarial attack and defense based on automatic machine learning is proposed. By defining the combined adversarial attack search space and the neural network architecture search space, the robust network architecture and combined adversarial attack algorithm are adopted to achieve coordinated optimization of automatic adversarial attack and defense.

Benefits of technology

It realizes the coordinated optimization of automatic adversarial attacks and defense, improves the robustness of the model and the effectiveness of adversarial attacks, and provides a benchmark for fair comparison of automatic adversarial attack algorithms and robust network architectures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120047770A_ABST
    Figure CN120047770A_ABST
Patent Text Reader

Abstract

The invention discloses an attack resisting and defending method based on automatic machine learning. The attack resisting method comprises the steps that all possible attack operators, step length ranges and threshold value sets of attack units in a search space are determined; selecting an initial parameter for each attack unit in the search space; combining the attack units into an attack sequence; executing the attack sequence on any model, and evaluating an input and output effect after the model executes the attack sequence; and according to the evaluation result, adjusting the parameters of the attack units or the sequence of the units in the attack sequence so as to search a better combined attack resisting method in the search space. The confrontation defense method comprises the steps of defining a model search space; evaluating the robustness of the neural network architecture by adopting different types of criteria; the robust neural network architecture is searched in a predefined search space by adopting a neural architecture search algorithm, and through the attack-resisting and defense method disclosed by the invention, attack and defense can be integrated, and respective performances can be cooperatively promoted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of adversarial attacks and defenses, and particularly to an adversarial attack and defense method based on automated machine learning. Background Art

[0002] As a core component of deep learning, deep neural networks have achieved great success in various applications, such as image classification, object recognition, semantic segmentation, etc. However, some studies have revealed the vulnerability of deep neural networks, indicating that the output of deep neural networks is highly sensitive to small changes in the input. For image classification tasks, adding some imperceptible perturbations to clean images can cause deep neural networks to produce incorrect output results. Images with perturbations are called adversarial examples. The adversarial attacks and defenses caused by adversarial examples have become a research hotspot in the field of adversarial robustness. Adversarial attacks are to study how to generate effective perturbations for existing models to make the model predictions incorrect, in order to conduct a more accurate and reliable robustness evaluation of the model, while adversarial defenses are to study how to improve the robustness of the model against adversarial examples. Research shows that adversarial attack or defense algorithms often tend to fall into local optima, which not only consumes time and effort but also results in poor performance of the designed algorithms or models. To solve such problems, automated machine learning technology is a feasible and effective technical path.

[0003] Automated machine learning defines a search space, formulates evaluation criteria, and designs search strategies to automatically search for efficient machine learning algorithms. Compared with traditional machine learning, it can not only reduce the burden of human participation but also improve the performance of algorithms or models. Automated machine learning technology has gradually been used in designing robust network architectures and efficient combined adversarial attack algorithms to more accurately evaluate and improve the robustness of models. In the application of automated machine learning to adversarial defense, existing methods use Neural Architecture Search (NAS) technology to achieve automated design of more robust network architectures. For example, using a two-stage neural architecture search technology, the model robustness is the accuracy after fast adversarial training, and a more robust model architecture is obtained. Another example is to search for robust structures under various types of attacks using a multi-objective evolutionary algorithm. The designed robustness metric considers the balance under multiple attack algorithms. Similarly, there is also the use of a multi-objective evolutionary algorithm to search for robust structures, but the search space is different from that defined by predecessors. Instead of the node definition of a directed acyclic graph, it is a simpler stacking of convolutional modules, which also proves the feasibility of NAS in searching for adversarial robust structures. In addition, some people combine the quantitative metrics for model robustness analysis with differentiable neural architecture search technology, greatly improving the efficiency of searching for robust structures. For example, some research combines regularization technology with the differentiable neural architecture search technology to evaluate the model robustness, achieving the goal of more efficient and stable search for robust architectures. In the application of automated machine learning to adversarial attacks, some people use the integration of four attack algorithms to achieve better attack performance than a single attack algorithm. Some people propose combined attacks. After constructing a large pool of adversarial attack algorithms, they search for attack operators, attack step sizes, and attack thresholds among them to obtain a more diverse and efficient combined adversarial attack algorithm. Some people also propose joint search of targeted / untargeted attacks, network transformation, attack loss functions, and attack algorithms. However, due to the characteristics of automated machine learning technology that do not require precise mathematical models and are flexible in optimization, it has become a feasible solution in automatically designing adversarial attack algorithms and robust network architectures. However, existing research at least still faces the following problems.

[0004] First, when automated machine learning is used for adversarial attacks and defenses, the search spaces, search strategies, and evaluation criteria of existing research vary from each other, making it impossible to fully and fairly compare the advantages and disadvantages of algorithms. Second, existing research on automated adversarial attacks and defenses is fragmented, resulting in the models obtained by automated adversarial defenses being not robust enough to handle stronger attacks, and the stronger adversarial attacks obtained by automated adversarial attacks performing poorly against more robust network architectures. Summary of the Invention

[0005] To solve some or all of the technical problems existing in the above-mentioned prior art, the present invention provides an adversarial attack and defense method based on automated machine learning, which can achieve automated adversarial attacks, automated adversarial defenses, and automated integrated attack and defense robustness evaluation.

[0006] The technical solution of the present invention is as follows:

[0007] In a first aspect, the present invention discloses an adversarial attack method based on automated machine learning, the method comprising:

[0008] Determine a combined adversarial attack search space, the combined adversarial attack search space including all possible attack operators, step sizes, and thresholds in the attack units;

[0009] Select initial parameters for each attack unit in the search space to complete the initialization of the attack units;

[0010] Combine the attack units into an attack sequence, and each attack unit in the attack sequence is executed in a preset order and jointly acts on the input data to generate an adversarial sample;

[0011] Execute the attack sequence on any model and evaluate the input-output effect of the model after executing the attack sequence;

[0012] According to the evaluation results, adjust the parameters of the attack units or the order of the units in the attack sequence to search for a better attack method in the search space, and during the search process, continuously evaluate the effects of different attack sequences using the adopted search method and adjust the search direction according to the evaluation results until the most effective combined adversarial attack method is found.

[0013] Further, in the above-mentioned adversarial attack method based on automated machine learning, the attack units include:

[0014] Attack operator: The attack operator is used to determine the gradient update method during the optimization iteration to generate an adversarial sample;

[0015] Attack step size: The attack step size is used to determine the step size in each optimization iteration;

[0016] Attack threshold: The attack threshold is used to determine the perturbation size of the final adversarial sample generated after using the combined attack compared to the original input sample.

[0017] Further, in the above-mentioned adversarial attack method based on automated machine learning, combining the attack units into an attack sequence includes:

[0018] Arrange multiple attack units including combinations of attack operators and their step size or threshold parameters to form an attack sequence, and obtain the optimal combined adversarial attack sequence through an optimization search method.

[0019] In a second aspect, the present invention further provides an adversarial defense method based on automated machine learning, including:

[0020] Define a model search space, search for a neural network architecture in the defined model search space. The neural network architecture is composed of a stack of several block units, and each block unit contains a permutation and combination of several operation operators. Find the optimal combination of several operation operators through a search algorithm to construct a robust neural network architecture;

[0021] Evaluate the robustness of the neural network architecture using different types of criteria;

[0022] Use a neural architecture search algorithm to search for a robust neural network architecture within a predefined search space.

[0023] Furthermore, in the above-mentioned adversarial defense method based on automated machine learning, by using the combined adversarial attack obtained from the search as the robustness evaluation criterion in automated adversarial defense, and using the searched robust network architecture as a new model to be attacked, conduct an automated adversarial attack to obtain a better adversarial attack and adversarial defense.

[0024] Furthermore, in the above-mentioned adversarial defense method based on automated machine learning, the predefined search space includes multiple operation operators, and the multiple operation operators at least include sep_conv_3x3, sep_conv_5x5, dil_conv_3x3, dil_conv_5x5, none, skip_connection, max_pool, and avg_pool. That is, the architecture search expects to search for the optimal combination of these eight operation operators to form block units, and further stack them into the entire network.

[0025] Furthermore, in the above-mentioned adversarial defense method based on automated machine learning, the neural architecture search algorithm includes:

[0026] One or more of evolutionary algorithms, reinforcement learning, and gradient-based search.

[0027] In a third aspect, the present invention provides an adversarial attack and defense method based on automated machine learning, including:

[0028] Define a model search space. The neural network architecture is composed of a stack of several block units, and each block unit contains a permutation and combination of several operation operators. Find the optimal combination of several operation operators through a search algorithm to construct a robust neural network architecture;

[0029] Evaluate the robustness of the neural network architecture using different types of criteria;

[0030] Use a neural architecture search algorithm to search for a robust neural network architecture within a predefined search space;

[0031] Take the searched robust network architecture as a new model to be attacked and conduct an automatic adversarial attack;

[0032] Determine the combined adversarial attack search space, which includes all possible attack operators, step sizes, and thresholds in the attack unit;

[0033] Select initial parameters for each attack unit in the search space to complete the initialization of the attack unit;

[0034] Combine the attack units into an attack sequence, and each attack unit in the attack sequence is executed in a certain order and acts together on the input data to generate adversarial samples;

[0035] Execute the attack sequence on any model and evaluate the input-output effect of the model after executing the attack sequence;

[0036] According to the evaluation results, adjust the parameters of the attack unit or the order of the units in the attack sequence to search for a better attack method in the search space. During the search process, the search method continuously evaluates the effects of different attack sequences and adjusts the search direction according to the evaluation results until the most effective combined adversarial attack method is found.

[0037] The main advantages of the technical solution of the present invention are as follows:

[0038] The adversarial attack and defense method based on automatic machine learning of the present invention. The adversarial attack obtained through automatic adversarial attack search can be used as a new auxiliary for evaluating the robustness against adversarial noise for robust network architecture search. At the same time, the robust network architecture searched by automatic adversarial defense can be used as a new model to be attacked to conduct automatic adversarial attack and obtain a better adversarial attack method. At the same time, by using the combined adversarial attack obtained through search as the robustness evaluation criterion in automatic adversarial defense and using the network architecture obtained through search as the model to be attacked in automatic adversarial attack, the integration of offense and defense is achieved, and their respective performances are synergistically promoted. In addition, since different search spaces, search strategies, and performance evaluation methods will all affect the final result, the framework can provide a benchmark environment to fairly compare the performance advantages and disadvantages of subsequent developed automatic adversarial attack algorithms and robust network architecture search algorithms. Description of the Drawings

[0039] The drawings described herein are used to provide a further understanding of the embodiments of the present invention and constitute a part of the present invention. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0040] Figure 1Schematic diagram of the adversarial attack and defense method based on automated machine learning according to an embodiment of the present invention;

[0041] Figure 2 Schematic diagram of an adversarial sample containing natural noise in the adversarial attack and defense method based on automated machine learning provided by an embodiment of the present invention;

[0042] Figure 3 Schematic diagram containing system noise in the adversarial attack and defense method based on automated machine learning provided by an embodiment of the present invention;

[0043] Figure 4 Visualization schematic diagram of normal units obtained by neural network architecture search in the adversarial attack and defense method based on automated machine learning provided by an embodiment of the present invention;

[0044] Figure 5 Visualization schematic diagram of reduced units obtained by neural network architecture search in the adversarial attack and defense method based on automated machine learning provided by an embodiment of the present invention;

[0045] Figure 6 Pareto front effect diagram obtained by multi-objective evolutionary algorithm searching for an approximate optimal combination of adversarial attacks in the adversarial attack and defense method based on automated machine learning provided by an embodiment of the present invention. Detailed implementation manners

[0046] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with specific embodiments of the present invention and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0047] The following combines the attached Figure 1-6 , and details the technical solutions provided by the embodiments of the present invention.

[0048] First, to more clearly illustrate the technical solutions provided by the embodiments of the present invention, the technical terms involved in the embodiments of the present invention are further described below. Specifically, the technical terms involved in the present invention include:

[0049] Robustness, which is a transliteration of "robustness" and is often also expressed as "robustness" and "strongness". Generally speaking, it can be used to reflect the ability of a system to maintain the stable operation of its functions when facing changes in its internal structure or external environment.

[0050] Adversarial examples are samples that cause the model to make misjudgments through adversarial attacks. Adversarial examples are generally generated by small perturbations of the original dataset.

[0051] As an example, as Figure 2 shown, adding noise that looks natural to the human eye to the original clean image, such as the snow pattern for snow, and the sample with such natural noise is called a natural adversarial example.

[0052] The present invention proposes an adversarial attack and defense method based on automated machine learning, aiming to automatically optimize the model architecture, improve robustness, and be able to automatically optimize the combination method of adversarial attacks to enhance the adversarial attack effect. The present invention can not only provide a benchmark study for the subsequent application research of automated machine learning in adversarial robustness, but also be used as a tool for users to evaluate and optimize the robustness of neural network models.

[0053] Adversarial attack is to generate effective perturbations against an existing model to make the model's prediction incorrect, so as to conduct a more accurate and reliable robustness assessment of the model.

[0054] Embodiment 1

[0055] This embodiment provides an adversarial attack method based on automated machine learning, and the method includes:

[0056] Determine the combined adversarial attack search space, and the combined adversarial attack search space includes all possible attack operators, step sizes, and thresholds in the attack units;

[0057] Select initial parameters for each attack unit in the search space to complete the initialization of the attack unit;

[0058] Combine the attack units into an attack sequence, and each attack unit in the attack sequence is executed in a preset order and acts together on the input data to generate adversarial examples;

[0059] Execute the attack sequence on any model and evaluate the input-output effect of the model after executing the attack sequence;

[0060] According to the evaluation results, adjust the parameters of the attack unit or the order of the units in the attack sequence to search for a better attack method in the search space, and during the search process, continuously evaluate the effects of different attack sequences with the adopted search method and adjust the search direction according to the evaluation results until the most effective combined adversarial attack method is found.

[0061] In some optional implementation manners of this embodiment, the above-mentioned any model includes any deep learning classification model, such as VGG, ResnNet, DenseNet models, etc.

[0062] Specifically, the preset order in which each attack unit in the attack sequence executes is set according to actual needs.

[0063] How the adversarial attack based on automated machine learning in the present invention is adopted in this embodiment will be specifically described below:

[0064] In the present invention, the method for generating adversarial samples includes:

[0065] Given a combined adversarial attack sequence, an input image is input into this sequence and attacked sequentially until all attacks are completed, and then adversarial samples can be generated. The purpose of the automated adversarial attack in the embodiments of the present invention is to search for a relatively optimal combined attack sequence.

[0066] Specifically, the automated adversarial attack is an automated method for generating adversarial samples that can deceive machine learning models. The following are the steps of the automated adversarial attack:

[0067] Step 1: Define the attack search space

[0068] To achieve efficient combined adversarial attack search, it is first necessary to define an attack search space that contains all possible attack methods and parameters, and then construct attack units and attack sequences, and use an automated search algorithm to optimize the combination and order of these attack units. Among them, the attack units include:

[0069] Attack operator: Define the gradient update method that can be used to determine the process of optimizing and iteratively generating adversarial samples, such as the Fast Gradient Sign Method (FGSM), Projected Gradient Descent (PGD), C&W attack, etc.

[0070] Attack step size: Used to determine the step size in each optimization iteration.

[0071] Attack threshold: Used to determine the perturbation size of the final adversarial sample generated after using the combined attack compared to the original input sample.

[0072] In the embodiments of the present invention, combining the attack units into an attack sequence includes:

[0073] Arrange multiple attack units that combine an attack operator and its step size or threshold parameters to form an attack sequence, and obtain the optimal combined adversarial attack sequence through an optimized search. Among them, each attack unit is a combination of an attack operator and its related parameters (step size, threshold). The attack sequence is an arrangement of a series of attack units, and each attack unit can be executed in a certain order to generate the final adversarial sample.

[0074] In some alternative implementation manners of this embodiment, the efficient combined adversarial attack search includes:

[0075] Initialization: Initialize a set of attack sequences randomly or based on some heuristic method.

[0076] Evaluation: Evaluate each attack sequence using metrics such as attack success rate and adversarial sample quality.

[0077] Selection: Select the better-performing attack sequences based on the evaluation results.

[0078] Update: Update the attack sequences through operations such as crossover and mutation.

[0079] Iteration: Repeat the evaluation, selection, and update steps until a stopping condition is reached (such as the maximum number of iterations, satisfactory attack effect, etc.).

[0080] In this way, the optimal attack strategy for a specific robust network architecture can be automatically searched. This search process can reveal the weaknesses of the model and help improve the robustness of the model.

[0081] Step 2: Define the evaluation criteria for attack effects

[0082] To evaluate the effect of automatic adversarial attacks, some evaluation criteria need to be defined. These criteria may include:

[0083] Number of gradient calculations: Evaluate how many times gradient calculations are required during the attack process, which can be used as an indicator of attack complexity.

[0084] Attack success rate: Measure the probability that the attack can successfully deceive the model, usually referring to the proportion of incorrect predictions made by the model for adversarial samples.

[0085] Invisibility of adversarial samples: Evaluate the difference between the generated adversarial samples and the original samples. The smaller the difference, the more invisible the adversarial samples are.

[0086] Transferability of adversarial samples: Evaluate the attack effect of adversarial samples on other models, that is, the generality of adversarial samples.

[0087] Step 3: Search for efficient combined adversarial attacks

[0088] Based on the defined search space and evaluation criteria, the following search strategies can be used to find efficient combined adversarial attack methods:

[0089] Evolutionary algorithm: Optimize the attack sequences by simulating the process of natural selection.

[0090] Reinforcement learning: Use reinforcement learning algorithms to learn the optimal attack strategy.

[0091] Gradient descent: For differentiable attack objectives, gradient descent can be used to optimize the attack parameters.

[0092] Bayesian optimization: By constructing a probability model to predict which attack parameters are most likely to be optimal.

[0093] During the search process, the algorithm continuously evaluates the effects of different attack sequences and adjusts the search direction according to the evaluation results until the most effective attack strategy is found. This process may require a large amount of computing resources and it is necessary to ensure that the search process does not violate any preset security or ethical constraints.

[0094] Adversarial defense, on the other hand, focuses on how to improve the robustness of the model against adversarial examples, and designing a robust network architecture is one of the important aspects.

[0095] Embodiment 2

[0096] This embodiment provides an adversarial defense method based on automated machine learning, which includes:

[0097] Define the model search space, search for a neural network architecture within the defined model search space. The neural network architecture is composed of a stack of several block units (cells), and each block unit contains a permutation and combination of several operation operators. Through a search algorithm, find the optimal combination of several operation operators to construct a robust neural network architecture;

[0098] Evaluate the robustness of the neural network architecture using different types of criteria;

[0099] Use a neural architecture search algorithm to search for a robust neural network architecture within a predefined search space.

[0100] It should be noted that adversarial defense, that is, robust network architecture search, within a predefined search space and under a well-defined robustness evaluation criterion, automatically searches for a robust network architecture based on a neural architecture search algorithm.

[0101] In addition, there are many types of neural network architectures, and it is necessary to pre-define a more appropriate range, that is, the search space. The output of neural network architecture search is two types of units, normal units and reduction units. These two diagrams are the corresponding visualizations respectively, and the entire network is formed by stacking normal units and reduction units. As Figure 4 and Figure 5 shown, Figure 4 is the visualization of the normal unit obtained by search, Figure 5 is the visualization of the reduction unit obtained by search. The entire network architecture is formed by stacking two types of units (normal units and reduction units).

[0102] How to adopt the adversarial defense based on automated machine learning in this invention in this embodiment will be specifically described below:

[0103] In some alternative implementation manners of this embodiment, each block unit may include the following permutations and combinations of operation operators:

[0104] Convolution operations (such as standard convolution, depthwise separable convolution, etc.), pooling operations (such as max pooling, average pooling, etc.), normalization operations (such as batch normalization, etc.), activation functions (such as ReLU, Sigmoid, etc.), and skip connections (such as residual connections, etc.).

[0105] The goal of this step is to find the optimal combination of these operation operators through a search algorithm to construct a robust network architecture.

[0106] By using the combination of adversarial attacks obtained from the search as the robustness evaluation criterion in automatic adversarial defense, and taking the searched robust network architecture as the new model to be attacked, conduct automatic adversarial attacks to obtain better adversarial attacks and adversarial defenses.

[0107] Step 2: Define the robustness evaluation criterion. The robustness evaluation criterion is used to measure the performance of the network architecture when dealing with different types of noise.

[0108] In some alternative implementation manners of this embodiment, the following robustness evaluation metrics may be adopted:

[0109] Adversarial noise: Used to evaluate the robustness of the network against adversarial attacks (such as FGSM, PGD, etc.).

[0110] System noise: Used to evaluate the performance of the network under hardware or system-level noise (such as quantization error, clock offset, etc.).

[0111] As Figure 3 shown, Figure 3 different from Figure 2 , Figure 2 is the sample with added noise directly shown, so it is the visualization of adversarial samples. Here Figure 3 is the noise directly visualized. Since this type of noise is invisible to the naked eye, the visualization of adversarial samples is not shown. Therefore, it needs to be distinguished from Figure 3 . Figure 3 The (a)-(h) in

[0112] show different types of system noise.

[0113] Natural noise: Used to evaluate the robustness of the network in a natural environment (such as light changes, occlusion, etc.).

[0114] Quantifiable metrics: Such as accuracy, loss function value, etc., used to quantify the network performance.

[0115] Step 3: Search for a robust network architecture. After defining the search space and the robustness evaluation criterion, the following search strategies can be adopted:

[0116] One or more of gradient-based search (such as DARTS), reinforcement learning (such as REINFORCE, Proximal Policy Optimization, PPO), evolutionary algorithms (such as NEAT), and greedy search (such as Random Search, Grid Search).

[0117] During the search process, the algorithm will iteratively evaluate the robustness of different network architectures and adjust the search direction according to the evaluation results until a network architecture that meets the robustness requirements is found.

[0118] It should be noted that a large amount of computing resources may be required during the above Step 3. Therefore, some optimization techniques, such as shared weights, early stopping strategies, etc., are usually adopted to improve the search efficiency.

[0119] Embodiment III

[0120] This embodiment provides an adversarial attack and defense method based on automated machine learning. How the adversarial attack and adversarial defense based on automated machine learning in the present invention are adopted in this embodiment will be specifically described below:

[0121] Define the model search space. The neural network architecture consists of several block units stacked together. Each block unit contains a permutation and combination of several operation operators. An optimal combination of several operation operators is found through a search algorithm to construct a robust neural network architecture;

[0122] Evaluate the robustness of the neural network architecture using different types of criteria;

[0123] Use a neural architecture search algorithm to search for a robust neural network architecture within the predefined search space;

[0124] Take the searched robust network architecture as a new model to be attacked and conduct an automated adversarial attack;

[0125] Determine the combined adversarial attack search space, where the combined adversarial attack search space includes all possible attack operators, step sizes, and thresholds in the attack unit;

[0126] Select initial parameters for each attack unit in the search space to complete the initialization of the attack unit;

[0127] Combine the attack units into an attack sequence. Each attack unit in the attack sequence is executed in a preset order and acts together on the input data to generate adversarial samples;

[0128] Execute an attack sequence on any model and evaluate the input-output effect of the model after executing the attack sequence;

[0129] According to the evaluation results, adjust the parameters of the attack unit or the order of the units in the attack sequence to search for a better attack method in the search space. During the search process, the adopted search method continuously evaluates the effects of different attack sequences and adjusts the search direction according to the evaluation results until the most effective combined adversarial attack method is found.

[0130] Combined with Figure 1 , including three modules: robust neural network architecture search, model retraining, and evolutionary search for efficient combined adversarial attacks. Robust neural network architecture search is automatic adversarial defense, and evolutionary search for efficient combined adversarial attacks is automatic adversarial attack. Automatic defense can search within a predefined search space to obtain a more robust network architecture, and automatic attack can search within a predefined search space to obtain a more efficient combined attack. The two modules are connected in series by using the searched attack as the robustness evaluation in automatic defense and the searched model as the model to be attacked in automatic attack. More specifically, Figure 1 From top to bottom in [], the upper rectangular block is automatic adversarial defense, that is, robust network architecture search, and the goal is to search for a more robust network architecture. The middle rectangular block is to retrain the searched model. The bottom rectangular block is automatic adversarial attack, that is, to obtain an efficient combined adversarial attack sequence through evolutionary search.

[0131] The present invention proposes an adversarial attack and defense method based on automated machine learning. In automatic adversarial defense, the method of the present invention provides comprehensive model robustness evaluations such as systematic noise, natural noise, adversarial noise, and quantifiable metrics, and designs loss functions for searching for robustness for each type of evaluation. In addition, the present invention also provides a variety of search algorithms to search for robust network architectures under the corresponding robustness evaluation methods. In automatic adversarial attack, the method of the present invention provides a variety of optimization algorithms to assist in searching for better adversarial attacks. Finally, using the noise generated by the automatic adversarial attack module as the robustness criterion, a more suitable robust network architecture can be further searched on this basis. At the same time, using the searched robust network architecture as the target of the model to be attacked, a more suitable automatic adversarial attack search can be further carried out, so as to realize the scheme adaptation and iterative upgrade of automatic attack and automatic defense in the same framework.

[0132] On the other hand of this embodiment, the present invention also proposes an adversarial and defensive attack system based on automated machine learning. The system includes an automatic adversarial module, an automatic defense module, and a co-evolution module, where:

[0133] The automatic adversarial module is used for automatic adversarial operations, including determining the combined adversarial attack search space, which includes all possible attack operators, step sizes, and thresholds in the attack unit; selecting initial parameters for each attack unit in the search space to complete the initialization of the attack unit; combining the attack units into an attack sequence, where each attack unit in the attack sequence is executed in a certain order and acts together on the input data to generate an adversarial sample; executing the attack sequence on any model and evaluating the input-output effect of the model after executing the attack sequence; according to the evaluation result, adjusting the parameters of the attack unit or the order of the units in the attack sequence to search for a better attack method in the search space, and during the search process, the search method continuously evaluates the effects of different attack sequences and adjusts the search direction according to the evaluation result until the most effective combined adversarial attack method is found.

[0134] The automatic adversarial defense module is used for automatic adversarial defense, including defining the model search space. The neural network architecture consists of several block units stacked together, and each block unit contains a permutation and combination of several operation operators. By using a search algorithm to find the optimal combination of several operation operators, a robust neural network architecture is constructed; evaluating the robustness of the neural network architecture using different types of criteria; using a neural architecture search algorithm to search for a robust neural network architecture within the predefined search space.

[0135] The co-evolution module is used to co-evolve the automatic adversarial module and the automatic defense module. By using the combined adversarial attack obtained from the search as the robustness evaluation criterion in the automatic adversarial defense, and using the network architecture obtained from the search as the model to be attacked in the automatic adversarial attack, the integration of offense and defense is achieved, and the performance of each is synergistically promoted.

[0136] As Figure 6 shown, Figure 6 Each scatter point in it refers to a combined adversarial attack scheme. The abscissa is the time required for each combined attack scheme to execute the attack process, and the ordinate is the model robustness accuracy after each combined attack scheme executes the attack. The lower the robustness accuracy and the less time required, the more efficient the combined attack scheme is, which is the solution expected to be optimized.

[0137] The logical relationships and principles among the above three modules include:

[0138] First, perform automatic adversarial defense. Adopt a weaker adversarial attack as the evaluation criterion, embed the neural architecture search algorithm, and automatically search within the predefined search space to obtain a robust network architecture. Then, use the network architecture obtained from the automatic adversarial defense search as the model to be attacked, perform the automatic adversarial attack process, and search for an efficient combined adversarial attack sequence. Thus, a cycle is formed. Use the obtained combined attack sequence as the robustness evaluation criterion in the neural architecture search algorithm to conduct the search, and obtain a more robust network architecture. Iterate this cycle continuously to achieve the coordinated improvement of the attack and defense effects, that is, the searched model architecture becomes more and more robust, and the performance of the searched combined adversarial attack becomes stronger and stronger.

[0139] Therefore, through the system of the present invention, it is possible to achieve an integrated attack and defense and synergistically promote their respective performances.

[0140] It should be understood that the specific features, operations, and details described above regarding the method of the present invention can also be similarly applied to the device and system of the present invention, or vice versa. Additionally, each step of the method of the present invention described above can be executed by the corresponding components or units of the device or system of the present invention.

[0141] It should be understood that each module / unit of the device of the present invention can be implemented in whole or in part by software, hardware, firmware, or a combination thereof. Each module / unit can be embedded in the processor of the electronic device in the form of hardware or firmware or independent of the processor, or stored in the memory of the electronic device in the form of software for the processor to call to execute the operations of each module / unit. Each module / unit can be implemented as an independent component or module, or two or more modules / units can be implemented as a single component or module.

[0142] Those skilled in the art can understand that the method steps of the present invention can be instructed to be completed by relevant hardware such as an electronic device or a processor through a computer program. The computer program can be stored in a non-transitory computer-readable storage medium. When the computer program is executed, the steps of the present invention are caused to be executed. Depending on the situation, any reference to a memory, storage, or other medium in this article may include non-volatile or volatile memory. Examples of non-volatile memory include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, magnetic tape, floppy disk, magneto-optical data storage device, optical data storage device, hard disk, solid state disk, etc. Examples of volatile memory include random access memory (RAM), external cache memory, etc.

[0143] It should be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. In addition, in this article, "front", "rear", "left", "right", "upper" and "lower" are all referenced with respect to the placement state shown in the drawings.

[0144] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A counterattack method based on automatic machine learning, characterized in that: include: Determining a combined adversarial attack search space, wherein the combined adversarial attack search space includes all possible attack operators, step sizes, and thresholds in the attack unit; Selecting initial parameters for each attack unit in the search space to complete the initialization of the attack unit; The attack units are combined into an attack sequence. Each attack unit in the attack sequence is executed in a preset order and acts together on the input data to generate adversarial samples. Execute attack sequences on any model and evaluate the input and output effects of the model after executing the attack sequence; According to the evaluation results, the parameters of the attack unit or the order of the units in the attack sequence are adjusted to search for a better attack method in the search space. During the search process, the search method used continuously evaluates the effects of different attack sequences and adjusts the search direction according to the evaluation results until the most effective combination of counterattack methods is found.

2. The method for countering attacks based on automatic machine learning according to claim 1, characterized in that: The attack unit comprises: Attack operator: The attack operator is used to determine the gradient update method in the process of optimizing iterative generation of adversarial samples; Attack step size: The attack step size is used to determine the step size in each optimization iteration; Attack threshold: The attack threshold is used to determine the perturbation size of the final adversarial sample generated after the combined attack compared to the original input sample.

3. The method for countering attacks based on automatic machine learning according to claim 1, characterized in that: Combining attack units into attack sequences involves: Arrange multiple attack units containing attack operators and their step sizes or threshold parameter combinations to form an attack sequence, and obtain the optimal combined counterattack sequence through optimization search.

4. An adversarial defense method based on automatic machine learning, characterized in that: include: A model search space is defined, and a neural network architecture is searched in the defined model search space, wherein the neural network architecture includes a plurality of stacked block units, each of which includes a plurality of permutations and combinations of operation operators, and an optimal combination of the plurality of operation operators is found through a search algorithm to construct a robust neural network architecture; Different types of criteria are used to evaluate the robustness of neural network architectures; A neural architecture search algorithm is used to search for robust neural network architectures in a predefined search space.

5. The method for countermeasure defense based on automatic machine learning according to claim 4, characterized in that: By using the combined adversarial attack obtained through search as the robustness evaluation criterion in automatic adversarial defense, and taking the searched robust network architecture as the new model to be attacked, automatic adversarial attack is carried out to obtain better adversarial attack and adversarial defense.

6. The method for countermeasure defense based on automatic machine learning according to claim 4, characterized in that: The predefined search space includes multiple operation operators, and the multiple operation operators include at least sep_conv_3x3, sep_conv_5x5, dil_conv_3x3, dil_conv_5x5, none, skip_connection, max_pool and avg_pool.

7. The method for countermeasure defense based on automatic machine learning according to claim 4, characterized in that: The neural architecture search algorithm includes: One or more of evolutionary algorithms, reinforcement learning, and gradient-based search.

8. A method for adversarial attack and defense based on automatic machine learning, characterized in that: include: A model search space is defined, wherein the neural network architecture includes a plurality of stacked block units, each of which includes a plurality of permutations and combinations of operation operators, and an optimal combination of the plurality of operation operators is found through a search algorithm to construct a robust neural network architecture; Different types of criteria are used to evaluate the robustness of neural network architectures; A neural architecture search algorithm is used to search for robust neural network architectures in a predefined search space; The searched robust network architecture is used as a new model to be attacked, and automatic adversarial attacks are carried out; Determining a combined adversarial attack search space, wherein the combined adversarial attack search space includes all possible attack operators, step sizes, and thresholds in the attack unit; Selecting initial parameters for each attack unit in the search space to complete the initialization of the attack unit; The attack units are combined into an attack sequence. Each attack unit in the attack sequence is executed in a preset order and acts together on the input data to generate adversarial samples. Execute attack sequences on any model and evaluate the input and output effects of the model after executing the attack sequence; According to the evaluation results, the parameters of the attack unit or the order of the units in the attack sequence are adjusted to search for a better attack method in the search space. During the search process, the search method used continuously evaluates the effects of different attack sequences and adjusts the search direction according to the evaluation results until the most effective combination of counterattack methods is found.