Image recognition model construction method, electronic equipment and storage medium

Through the autoencoder model and adversarial training technology, adversarial samples are generated to improve the adversarial robustness and privacy of the image recognition model, solving the problem of difficulty in improving adversarial robustness and privacy in the existing technology, and achieving a wider range of application scenarios.

CN120125971APending Publication Date: 2025-06-10CIVIL AVIATION UNIV OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510298418.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The prior art is difficult to improve adversarial robustness and privacy in image recognition models in the field of autonomous driving. Traditional methods to improve adversarial robustness will lead to reduced privacy and vice versa.

Method used

The image recognition model is constructed by using the autoencoder model, and the adversarial training is performed by generating adversarial samples. The overall average of the classification is used as the adversarial attack target, low-dimensional adversarial samples are generated and decoded to improve the adversarial robustness and privacy of the model.

Benefits of technology

The confrontational robustness and privacy of image recognition models in the field of autonomous driving have been improved, and the practical application scope of image recognition technology has been expanded.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120125971A_ABST
    Figure CN120125971A_ABST
Patent Text Reader

Abstract

The invention relates to the field of information technology processing, in particular to an image recognition model construction method, electronic equipment and a storage medium, and the method comprises the steps: constructing an auto-encoder model for an image data set, the auto-encoder model comprising an encoder and a decoder; performing coding processing on the high-dimensional feature vector corresponding to each type of data set to obtain a corresponding low-dimensional feature vector; taking an average value of the low-dimensional feature vectors corresponding to each class as an average vector of the class; based on the average vector of each type, adding disturbance in the corresponding low-dimensional feature vector to generate a corresponding low-dimensional confrontation sample; performing decoding processing on the corresponding low-dimensional adversarial samples of each type to obtain corresponding high-dimensional adversarial samples; and training the initial image recognition model based on all the high-dimensional adversarial samples and the sample image data set to obtain a trained image recognition model. According to the invention, the anti-robustness and privacy of the image recognition model can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology processing, and particularly to a method for constructing an image recognition model, an electronic device, and a storage medium. Background Art

[0002] With the increasing popularity of autonomous driving applications, image recognition technology has been widely used in the field of autonomous driving. The principle of image recognition is to recognize corresponding images by training an image recognition model. For the image recognition model in the field of autonomous driving, the need to ensure the security and privacy of the model is increasing. With the increasing potential threat of adversarial attacks to autonomous driving systems, it has become particularly crucial to improve the adversarial robustness of the model. At the same time, since autonomous driving scenarios involve the protection of the privacy of driving data, protecting privacy has also become necessary. Currently, adversarial robustness and privacy are two main directions in the field of artificial intelligence model security, but the improvement of the adversarial robustness of the model will lead to a decrease in the privacy of the model, restricting the application scope of the image recognition model in real-world scenarios. Traditional methods such as differential privacy can effectively improve the level of privacy protection, but they are insufficient in improving adversarial robustness. Adversarial robustness refers to the ability of a machine learning model to maintain correct predictions and stable performance when facing carefully designed adversarial examples. Adversarial examples are a type of artificially generated malicious samples that cause the model to make incorrect predictions by adding tiny imperceptible noise to the original data. Existing technologies are difficult to significantly improve adversarial robustness while ensuring privacy, and this contradiction is particularly prominent in the field of autonomous driving. Due to the following two key reasons, traditional methods for improving adversarial robustness and privacy protection cannot be directly applied to autonomous driving models: (1) Improving adversarial robustness will lead to a decrease in model privacy: Most traditional methods for improving adversarial robustness enhance the anti-interference ability of the model through data augmentation or generating adversarial examples, etc. However, these methods require a large amount of computation on the data, making it difficult to guarantee the privacy of the model. (2) Privacy protection methods will lead to a decrease in model prediction performance: Using traditional privacy protection methods such as differential privacy on the basis of an adversarial robust model can improve the privacy of the model, but it will significantly reduce the prediction accuracy of the adversarial robust model, and even cause the model to be unusable, greatly damaging the performance of the model. Therefore, for the image recognition technology in the field of autonomous driving, studying a mechanism to improve the privacy of the model while ensuring adversarial robustness is of great significance for further expanding the practical application scope of image recognition technology. Summary of the Invention

[0003] In view of the above technical problems, the technical solution adopted by the present invention is as follows:

[0004] According to a first aspect of the present invention, there is provided a method for constructing an image recognition model, the method comprising the following steps:

[0005] S100. Obtain an N-class sample image dataset, where the class label of the i-th class sample image dataset is Tag i , where the value range of i is from 1 to N, and N > 1.

[0006] S200. Construct an autoencoder model for the sample image dataset. The autoencoder model includes an encoder and a decoder.

[0007] S300. Input the high-dimensional feature vector corresponding to the i-th class sample image dataset into the encoder for encoding to obtain the corresponding low-dimensional feature vector.

[0008] S400. Take the average value of the low-dimensional feature vectors corresponding to the i-th class sample image dataset as the average vector of Tag i .

[0009] S500. Take the average vector of Tag i as the generation target of the adversarial sample of the i-th class sample image dataset, and add perturbations to the low-dimensional feature vectors corresponding to the i-th class sample image dataset to generate the corresponding low-dimensional adversarial samples.

[0010] S600. Input the low-dimensional adversarial samples corresponding to the i-th class sample image dataset into the corresponding decoder for decoding to obtain the corresponding high-dimensional adversarial samples.

[0011] S700. Train the initial image recognition model based on the N-class high-dimensional adversarial samples and the N-class sample image datasets to obtain a trained image recognition model.

[0012] According to the second aspect of the present invention, there is provided an electronic device, including a processor and a memory; the processor is configured to execute the steps of the method according to the first aspect of the present invention by calling a program or instruction stored in the memory.

[0013] According to the third aspect of the present invention, there is provided a computer-readable storage medium storing a program or instruction, and the program or instruction causes a computer to execute the steps of the method according to the first aspect of the present invention.

[0014] The present invention has at least the following beneficial effects:

[0015] An image recognition model construction method provided by an embodiment of the present invention includes: constructing an autoencoder model based on image recognition requirements, where the autoencoder includes two parts, an encoder and a decoder; generating the overall average value of each classification of the dataset as the generation target based on the encoder; obtaining the corresponding adversarial samples of the current sample points based on the generation target; and performing adversarial training on the model based on the current adversarial samples. When the image recognition model constructed by the present invention is actually applied, it can improve the adversarial robustness and privacy of the image recognition model in fields such as autonomous driving.

[0016] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0018] Figure 1 It is a flowchart of a method for constructing an image recognition model provided by an embodiment of the present invention;

[0019] Figure 2 It is a comparison diagram of the effects of the model constructed by the method provided by the embodiment of the present invention and the models constructed by other methods. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.

[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs. The terms used in the description of the present invention in this specification are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0022] It should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the steps as sequential processes, many of the steps can be implemented in parallel, concurrently, or simultaneously. In addition, the order of the steps can be rearranged. The process can be terminated when its operation is completed, but there can also be additional steps not included in the drawings. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.

[0023] An embodiment of the present invention provides a method for constructing an image recognition model, as Figure 1 shown, the method includes the following steps:

[0024] S100. Obtain an N-class sample image dataset, where the class label of the i-th class sample image dataset is Tag i , where i ranges from 1 to N, and N > 1.

[0025] In an embodiment of the present invention, N can be set according to actual needs. The class label can be determined based on image recognition requirements. In one embodiment, the image data in the sample image dataset can be image data captured during the process of autonomous driving. In this case, the class label can include speed limit classification signs, traffic signs, pedestrians, etc.

[0026] S200. Construct an autoencoder model for the sample image dataset, where the autoencoder model includes an encoder and a decoder.

[0027] In an embodiment of the present invention, the encoder can include an input layer, multiple hidden layers, and a bottleneck layer. The input layer is used to receive sample data. The number of hidden layers can be 2 to 3 layers, and each hidden layer can be composed of a series of fully connected layers, and the number of neurons in each layer gradually decreases. The decoder is used to perform an inverse operation on the encoder structure, including an input layer, multiple hidden layers, and an output layer. The input layer of the decoder receives the low-dimensional representation. The hidden layer of the decoder is composed of a series of fully connected layers, and the number of neurons gradually increases. The output layer of the decoder is used to restore the low-dimensional representation to the original data dimension.

[0028] In an embodiment of the present invention, the hyperparameters and model parameters of the autoencoder model can be set according to actual needs, for example, they can be empirical values that result in good classification effects.

[0029] S300. Input the high-dimensional feature vector corresponding to the i-th class sample image dataset into the encoder for encoding processing to obtain the corresponding low-dimensional feature vector.

[0030] In an embodiment of the present invention, the encoder encodes through the following conditions:

[0031] Z = Relu(W enc ×x + b enc );

[0032] where Z represents the low-dimensional feature vector, W enc is the weight matrix of the encoder, b enc is the bias matrix of the encoder, x is the input sample image data, and Relu() is the Relu activation function. That is, each fully connected layer of the encoder performs the encoding operation defined by the above conditions.

[0033] In the embodiments of the present invention, the output dimension of the bottleneck layer of the encoder can be set according to actual needs, as long as it is less than the dimension of the original image data. In one exemplary embodiment, the dimension of the high-dimensional feature vector can be 784 dimensions, and the output dimension of the bottleneck layer of the encoder can be 64 dimensions.

[0034] In the embodiments of the present invention, by calculating the image data in the low-dimensional space through the encoder, the protection performance of data privacy can be improved.

[0035] S400, taking the average value of the low-dimensional feature vectors corresponding to the i-th class of sample image datasets as the average vector of Tag. i of.

[0036] In the embodiments of the present invention, the average vector AvgF of Tag i =(F 1 , F 2 , ……, F r , ……, F g ), F r is the r-th eigenvalue in AvgF, where r ranges from 1 to g, and g is the dimension of the low-dimensional feature vector; F r =(F 1r +F 2r +……+F dr +……+F h(i)r ) / h(i), F dr is the r-th eigenvalue in the low-dimensional feature vector corresponding to the d-th image data in the i-th class of sample image datasets, where d ranges from 1 to h(i), and h(i) is the number of image data in the i-th class of sample image datasets.

[0037] S500, adding perturbations to the low-dimensional feature vectors corresponding to the i-th class of sample image datasets based on the average vector of Tag i to generate corresponding low-dimensional adversarial samples.

[0038] Further, S500 specifically includes:

[0039] S510, setting the perturbation addition times counter t = 1.

[0040] S511, adding δ t to the current low-dimensional feature vectors corresponding to the i-th class of sample image datasets to obtain the t-th candidate adversarial sample corresponding to the i-th class of sample image datasets; where the initial value of the current low-dimensional feature vectors is the low-dimensional feature vectors corresponding to the i-th class of sample image datasets without added perturbations.

[0041] S512, obtaining the t-th candidate adversarial sample and Tag iThe loss between the average vectors is used as the current loss. If the current loss meets the preset condition, the t-th candidate adversarial sample is used as the low-dimensional adversarial sample corresponding to the i-th class of sample image dataset; otherwise, S513 is executed.

[0042] In the embodiment of the present invention, the preset condition may be that the current loss no longer decreases, that is, the current loss is the same as multiple losses before the current loss.

[0043] S513, set t = t + 1, and obtain the t-th perturbation δ based on the current loss t ; Use the t-th candidate adversarial sample as the current low-dimensional feature vector corresponding to the i-th class of sample image dataset, and execute S511.

[0044] Further, in the embodiment of the present invention, δ t satisfies the following condition: δ t = ε × sign(▽L c ); where ε is the set perturbation intensity, L c represents the current loss, and ▽L c represents the gradient of L c . ε can be set according to actual needs. sign() is the sign function used to determine the positive and negative of the gradient.

[0045] In the embodiment of the present invention, the loss between the t-th candidate adversarial sample and the average vector of Tag i can be calculated through the loss function. The loss function can be an existing loss function. In a schematic embodiment, the loss function can be the cross-entropy loss function, that is, the loss is the cross-entropy loss.

[0046] Further, in the embodiment of the present invention, the t-th candidate adversarial sample satisfies the following condition: Z t = Z t-1 + δ t ; where Z t is the t-th candidate adversarial sample, and Z t-1 is the (t - 1)-th candidate adversarial sample. Those skilled in the art know that if t = 1, then Z 0 is the low-dimensional feature vector corresponding to the i-th class of sample image dataset without adding perturbation.

[0047] In the embodiment of the present invention, using the overall average value of each classification to replace the individual sample points as the adversarial attack target can protect the feature information of the individual sample points and reduce the data privacy risk.

[0048] S600, input the low-dimensional adversarial sample corresponding to the i-th class of sample image dataset into the corresponding decoder for decoding processing to obtain the corresponding high-dimensional adversarial sample.

[0049] In an embodiment of the present invention, the decoder decodes through the following conditions:

[0050] H = Sigmoid(W dec ×Z + b dec );

[0051] where H represents a high-dimensional adversarial sample, W dec is the weight matrix of the decoder, b dec is the bias matrix of the decoder, and Sigmoid() is the Sigmoid activation function.

[0052] S700. Train the initial image recognition model based on N types of high-dimensional adversarial samples and an N-class sample image dataset to obtain a trained image recognition model.

[0053] Further, S700 may specifically include:

[0054] S710. Divide N types of high-dimensional adversarial samples into multiple batches of first training sample data, and divide the N-class sample image dataset into multiple batches of second test sample data.

[0055] S720. Input the current batch of first training sample data into the current image recognition model for training to obtain a corresponding first prediction result; the initial value of the current image recognition model is the initial image recognition model.

[0056] In an embodiment of the present invention, the image recognition model may be an existing neural network model, and the hyperparameters of the image recognition model can be set based on actual needs. The hyperparameters include model structure, model learning rate, model training rounds, etc.

[0057] S730. Obtain the current loss value of the current image recognition model based on the first prediction result corresponding to the current batch of first training sample data and the corresponding true result, and update the parameters of the current image recognition model based on the current loss value; execute S740.

[0058] In an embodiment of the present invention, the prediction result is the predicted class label. The true result is the true class label.

[0059] S740. Input the current batch of second test sample data into the current image recognition model for testing to obtain a corresponding second test result; execute S750.

[0060] S750. Obtain the current loss value of the current image recognition model based on the second test result corresponding to the current batch of second test sample data and the corresponding true result, and determine whether the current loss value meets the preset model training end condition. If it meets, execute S770; otherwise, execute S760.

[0061] In an embodiment of the present invention, the test result is a predicted class label.

[0062] S760, update the parameters of the current image recognition model based on the current loss value corresponding to the second test sample data of the current batch, and use the first training sample data of the next batch as the first training sample data of the current batch, and execute S720.

[0063] S770, regard the current image recognition model as a trained image recognition model.

[0064] The trained image recognition model in the embodiment of the present invention can be used as an image recognition model for actual applications. In an actual application scenario, the image data to be recognized can be input into the trained image recognition model, and the obtained image recognition result can be obtained.

[0065] In an embodiment of the present invention, the loss value can be calculated based on an existing loss function, such as a cross-entropy loss function. The preset model training end condition can be set according to actual needs. For example, the loss value is less than or less than or equal to a set loss threshold and remains unchanged within a set time period.

[0066] In the embodiment of the present invention, adversarial training can improve the adversarial robustness of the image recognition model and ensure the model prediction performance.

[0067] Membership inference attack is a common privacy attack method used to evaluate whether a model reveals information about the data participating in training. The main goal of a membership inference attack is to determine whether a specific sample belongs to the training set of the model. The principle of the attack is based on the difference in the performance of the model on training samples and non-training samples. When the model shows higher prediction accuracy or confidence in training samples, this performance difference becomes the basis for the privacy challenger to infer whether a sample belongs to the training set. In a membership inference attack, the privacy challenger first needs to access the target model, either through black-box access, i.e., only being able to obtain the input-output results of the model, or through white-box access, i.e., obtaining the internal parameters of the model. Subsequently, the privacy challenger prepares a set of candidate samples, including training samples and data that did not participate in training. By inputting these samples into the model, the attacker records the prediction results of the model. The prediction results of the model for training samples will show higher confidence or smaller prediction errors, while for non-trained samples, they will be relatively lower. This performance difference becomes the key feature of the attack. Next, the privacy challenger trains an auxiliary classifier using these recorded response data. The task of the auxiliary classifier is to predict whether a sample belongs to the training set of the target model. The input features include the prediction confidence distribution of the model, the prediction loss value, and other relevant statistical information. By analyzing the different performances of the model on training and non-training samples, the auxiliary classifier can better identify the samples that participated in training. The success rate of the membership inference attack is usually used to measure the privacy protection ability of the model, as a measure of the privacy of the model. If the attack success rate is significantly higher than random guessing, it indicates that the model has a strong memory of training samples and a high risk of privacy leakage.

[0068] To verify the performance of the image recognition model, in the embodiments of the present invention, the same image dataset is used to test the training accuracy, test accuracy, and privacy attack success rate of the image recognition model obtained by the image recognition model construction method provided by the embodiments of the present invention, the image recognition model obtained by the PGD (Projected Gradient Descent) method, and the image recognition model obtained by the AdvGAN (Generative Adversarial Networks) method. The test results are as Figure 2 shown. Through Figure 2 it can be seen that the training accuracy and test accuracy of the image recognition model provided by the embodiments of the present invention are higher than those of the other two models, and the privacy attack success rate is lower than those of the other two models. This shows that the image recognition model provided by the present invention has good performance in terms of privacy protection performance, evaluation accuracy, and ensuring adversarial robustness.

[0069] An embodiment of the present invention further provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are configured to execute the method according to the embodiment of the present invention.

[0070] An embodiment of the present invention further provides a computer-readable storage medium storing computer-executable instructions for executing the method according to the embodiment of the present invention.

[0071] It should be understood that the various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions disclosed in the present invention can be achieved, which is not limited herein.

[0072] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for constructing an image recognition model, characterized in that: The method comprises the following steps: S100, obtaining N types of sample image datasets, where the category label of the i-th type of sample image dataset is Tag i , the value of i ranges from 1 to N, N>1; S200, constructing an autoencoder model for a sample image dataset, wherein the autoencoder model includes an encoder and a decoder; S300, inputting the high-dimensional feature vector corresponding to the i-th type sample image data set into the encoder for encoding processing to obtain the corresponding low-dimensional feature vector; S400, taking the average value of the low-dimensional feature vector corresponding to the i-th type sample image data set as Tag i The average vector of S500, the Tag i The average vector of is used as the generation target of the adversarial sample of the i-th sample image dataset, and perturbations are added to the low-dimensional feature vector corresponding to the i-th sample image dataset to generate the corresponding low-dimensional adversarial sample; S600, inputting the low-dimensional adversarial sample corresponding to the i-th type sample image data set into the corresponding decoder for decoding processing to obtain the corresponding high-dimensional adversarial sample; S700, training an initial image recognition model based on N types of high-dimensional adversarial samples and N types of sample image data sets to obtain a trained image recognition model.

2. The method according to claim 1, characterized in that S700 specifically includes: S710, dividing N types of high-dimensional adversarial samples into multiple batches of first training sample data, and dividing N types of sample image data sets into multiple batches of second test sample data; S720, inputting the first training sample data of the current batch into the current image recognition model for training to obtain a corresponding first prediction result; the initial value of the current image recognition model is the initial image recognition model; S730, obtaining a current loss value of the current image recognition model based on the first prediction result corresponding to the first training sample data of the current batch and the corresponding true result, and updating the parameters of the current image recognition model based on the current loss value; executing S740; S740, input the second test sample data of the current batch into the current image recognition model for testing, and obtain a corresponding second test result; execute S750; S750, based on the second test result corresponding to the second test sample data of the current batch and the corresponding true result, obtain the current loss value of the current image recognition model, and determine whether the current loss value meets the preset model training end condition. If so, execute S770, otherwise, execute S760; S760, updating the parameters of the current image recognition model based on the current loss value corresponding to the second test sample data of the current batch, and using the first training sample data of the next batch as the first training sample data of the current batch, and executing S720; S770: Use the current image recognition model as a trained image recognition model.

3. The method according to claim 1, characterized in that S500 specifically includes: S510, setting the disturbance addition times counter t=1; S511, add δ to the current low-dimensional feature vector corresponding to the i-th type sample image data set t , obtain the t-th candidate adversarial sample corresponding to the i-th type sample image dataset; wherein the initial value of the current low-dimensional feature vector is the low-dimensional feature vector corresponding to the i-th type sample image dataset without adding disturbance; S512, obtain the tth candidate adversarial sample and Tag i The loss between the average vectors of is taken as the current loss. If the current loss meets the preset condition, the t-th candidate adversarial sample is taken as the low-dimensional adversarial sample corresponding to the i-th type sample image data set. Otherwise, execute S513. S513, set t = t + 1, and obtain the tth disturbance δ based on the current loss t ; Take the tth candidate adversarial sample as the current low-dimensional feature vector corresponding to the i-th type sample image data set and execute S511.

4. The method according to claim 3, characterized in that δ t Satisfy the following conditions: t =ε×sign(▽L c ), where ε is the set disturbance intensity, L c Represents the current loss, sign() is the sign function, ▽L c Indicates L c gradient.

5. The method according to claim 4, characterized in that The tth candidate adversarial example satisfies the following conditions: t =Z t-1 +δ t ; Among them, Z t is the tth candidate adversarial sample, Z t-1 is the t-1th candidate adversarial sample.

6. The method according to claim 3, characterized in that The loss is the cross entropy loss.

7. The method according to claim 1, characterized in that The image data in the sample image data set are image data taken during the autonomous driving process.

8. The method according to claim 1, characterized in that: The encoder encodes according to the following conditions: From=Relu(In enc ×x+b enc ); Among them, Z represents the low-dimensional feature vector, W enc is the weight matrix of the encoder, b enc is the bias matrix of the encoder, x is the input sample image data, and Relu() is the Relu activation function; The decoder decodes according to the following conditions: H=Sigmoid(W dec ×Z+b dec ); Among them, H represents a high-dimensional adversarial sample, W dec is the weight matrix of the decoder, b dec is the bias matrix of the decoder, and Sigmoid() is the Sigmoid activation function.

9. An electronic device, characterized in that: including a processor and a memory; The processor is used to execute the steps of the method according to any one of claims 1 to 8 by calling the program or instruction stored in the memory.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store a program or an instruction, wherein the program or the instruction enables a computer to execute the steps of the method according to any one of claims 1 to 8.