Attack strategy automatic generation method facing adversarial training

By building an initial attack strategy library and using feature fusion layer and multi-scale attention layer to generate diverse attack strategies, the problem of lack of diversity in existing adversarial training methods is solved, which significantly improves the effectiveness of adversarial training and the robustness of the target network.

CN120146148APending Publication Date: 2025-06-13XIHUA UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510271226.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing adversarial training methods rely on predefined attack strategies, lack diversity, and cannot fully cover all the fragile points of the model, resulting in limited training effects.

Method used

By building an initial attack strategy library and using feature fusion layers for feature fusion, including hybrid convolutions combining spatial domains and frequency domains, and multi-scale attention layers, a diverse attack strategy is generated.

Benefits of technology

The generated attack strategy can more comprehensively cover the vulnerabilities of the target network, significantly improve the effectiveness of adversarial training and the robustness of the target network, and improve the accuracy of clean sample classification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120146148A_ABST
    Figure CN120146148A_ABST
Patent Text Reader

Abstract

The invention discloses an attack strategy automatic generation method for adversarial training, and the method achieves the purpose of automatically generating an efficient attack strategy through the construction of an initial attack strategy library, the acquisition of a clean sample, the initial processing and the feature fusion processing. According to the method, the effect of adversarial training and the robustness of the model can be remarkably improved, and meanwhile, the precision of clean sample classification can also be improved. The method is suitable for security enhancement of various machine learning models.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of artificial intelligence, and particularly relates to a method for automatically generating an attack strategy for adversarial training. Background Art

[0002] In recent years, the wide application of deep learning models has covered multiple fields such as image classification, speech recognition, and natural language processing. A large number of studies have shown that while the multi-layer non-linear structure of deep learning endows it with powerful feature expression capabilities and the ability to model complex tasks, there are certain vulnerabilities hidden behind it, which will cause security threat problems such as software implementation vulnerabilities, adversarial sample attacks, contamination of training data (data poisoning), and model stealing. Among them, adversarial samples are adding carefully constructed or imperceptible subtle noises to the input samples, resulting in deep learning being effectively deceived and outputting incorrect prediction results. Especially in some key fields, such as autonomous driving and financial security, adversarial sample attacks may bring huge risks, highlighting the urgency and importance of resisting adversarial sample attacks.

[0003] Currently, the academic community and the industrial community have conducted in-depth research on the security issues of deep learning models and achieved fruitful results. In terms of resisting image adversarial sample attacks, defensive distillation is a method of compressing the model under the condition of ensuring training accuracy. In addition, various adversarial sample detection and defense methods have been proposed: feature learning (principal component analysis, feature compression, etc.), distribution statistics (softmax distribution, kernel density, and uncertainty estimation, etc.), input reconstruction, etc. From the perspective of image denoising, defensive methods such as feature denoising, JPEG compression, total variance minimization, HGD denoiser, and Defense-GAN have been proposed for image preprocessing and feature transformation.

[0004] Adversarial training is an important method to improve the robustness of deep learning models. Its core idea is to introduce adversarial samples during the training process so that the model can better resist adversarial attacks. Typical adversarial training methods include PGD-AT, TRADES, LBGAT, etc., and some progress has been made in improving the robustness of the model. However, these adversarial training methods also have limitations: most existing methods usually rely on predefined attack strategies, which generally generate adversarial samples by manually specifying attack parameters, lack diversity, may not be able to comprehensively cover all the vulnerable points of the model, resulting in limited training effects. In addition, manually designing attack strategies requires a lot of professional knowledge and experience, is difficult to meet the needs of different tasks and models, may affect the generalization performance, and limits the improvement of the model's robustness.

[0005] LAS-AT, as an adversarial training framework based on learnable attack strategies, consists of a target network trained with adversarial samples to improve robustness and a policy network that generates attack strategies to control the generation of adversarial samples. It has been found that although LAS-AT performs well in improving the robustness of the target network compared to previous adversarial training methods, due to the relatively simple ResNet-18 network structure and residual blocks used in the policy network of LAS-AT, its ability to learn and represent multi-level complex features is limited, resulting in poor regularity in the percentage change of the perturbation intensity values of the attack strategies generated at different training stages and obvious jitter. In addition, a large proportion of strong attacks will be generated in the early stage of training, which is not conducive to the adversarial training of the target network and affects the improvement of robustness. Generally, a good attack strategy is to use weak attacks in the early stage of training and strong attacks in the later stage. If strong attacks are applied in the early stage of training, it will cause the target network to be difficult to converge or the learning time to become longer. Therefore, there is an urgent need for a method that can automatically generate efficient attack strategies to improve the effect of adversarial training. Summary of the Invention

[0006] The object of the present invention is to provide an automatic generation method for attack strategies for adversarial training, which can improve the effect of adversarial training and the robustness of the target network by automatically generating diverse attack strategies.

[0007] To achieve the above object of the invention, the embodiments of the present invention provide the following technical solutions: An automatic generation method for attack strategies for adversarial training, comprising the following steps: Step S1, constructing an initial attack strategy library; obtaining clean samples X, where the clean samples are image samples; Step S2, first, passing the clean sample X into an initial layer, which consists of a 7x7 convolution, batch normalization, and a Relu activation function, to obtain input features Xin; Step S3, then, passing the input features Xin into a feature fusion layer, dividing it into local features Xin-l and global features Xin-g according to the hyperparameter alpha in terms of feature dimensions, and successively performing feature fusion processing through convolution stage 1, convolution stage 2, a multi-scale attention layer, convolution stage 3, and convolution stage 4; Step S4, finally, generating an attack strategy through full connection layer processing.

[0008] In the automatic generation method for attack strategies for adversarial training, step S1 further includes: The initial attack strategy library contains various attack methods and sets the range of adjustable parameters for each attack method.

[0009] In the method for automatically generating attack strategies for adversarial training, step S3 further includes: The convolution stage 1 is composed of three mixed convolution cascades with the same structure; The convolution stage 2 is composed of 4 mixed convolution cascades with the same structure, and the mixed convolution has the same structure as the mixed convolution in the convolution stage 1; The convolution stage 3 is composed of 6 mixed convolution cascades with the same structure; The convolution stage 4 is composed of three mixed convolution cascades with the same structure, and the mixed convolution has the same structure as the mixed convolution in the convolution stage 3; The multi-scale attention layer is composed of a multi-scale convolution block, an efficient additive attention module and linearization.

[0010] In the method for automatically generating attack strategies for adversarial training, the convolution stage 1 further includes: The mixed convolution first sends the local feature Xin-1 to the two channels Tll and Tlg respectively, and at the same time, sends the global feature Xin-g to the two channels Tgl and Tgg respectively, wherein the three channels Tll, Tlg and Tgl are processed in the spatial domain, and the Tgg channel is processed in the frequency domain; then, the local feature Xin-1 is processed by the T11 channel and the global feature Xin-g is processed by the Tgl channel, and then the sum is obtained to obtain Xout-1; the local feature Xin-1 is processed by the T1g channel and the global feature Xin-g is processed by the Tgg channel, and then the sum is obtained to obtain Xout-g; The spatial domain convolution, based on the bottleneck residual structure idea, first uses a 1x1 convolution structure instead of a 3x3 convolution structure to reduce the amount of calculation, and after batch normalization and Relu activation function processing, uses a 3x3 convolution structure to extract features, and then after batch normalization and Relu activation function, finally uses a 1x1 convolution structure to restore the number of channels; In the frequency domain convolution, after the global feature Xin-g is passed into the Tgg channel, it is transformed into the real part Y_R and the imaginary part Y_I through fast Fourier transformation, and then spliced ​​in the channel dimension, and then a 1x1 convolution is performed to extract the fusion features of the real part and the imaginary part, and then processed by batch normalization and Relu activation function, and finally the inverse Fourier transformation is performed.

[0011] In the method for automatically generating attack strategies for adversarial training, the convolution stage 3 further includes: The spatial domain convolution in the hybrid convolution in the convolution stage 3 has the same structure as that in the convolution stage 1. The difference is that the frequency domain convolution in the hybrid convolution in the convolution stage 3 adopts a frequency domain convolution based on a bottleneck structure, that is, when performing frequency domain convolution processing, a 1x1 convolution processing is added before the inverse Fourier transform.

[0012] The described method for automatically generating an attack strategy for adversarial training, the multi-scale attention layer further includes: For the multi-scale attention layer, first, the multi-scale convolution block extracts multi-scale features of the sample through convolution kernels of three different sizes: 1x1, 3x3, and 5x5. After each size of convolution operation, ReLU activation is performed to increase non-linearity. The outputs of the three sizes of convolution operations are concatenated in the channel dimension to obtain the final output feature map. Then, it is passed into the efficient additive attention module, and by decomposing the calculation process of the attention weight, the high-dimensional dot product operation is transformed into a low-dimensional additive operation. Finally, linearization processing is performed, and its structure consists of 2 1x1 pointwise convolution layers, batch normalization, and a ReLU activation function.

[0013] The described method for automatically generating an attack strategy for adversarial training, the step S4 further includes: The attack strategy is a combination of optional values of the adjustable parameters of the attack method.

[0014] Compared with the prior art, the present invention has the following advantages: (1) First, for the method for automatically generating an attack strategy for adversarial training proposed by the present invention, the feature fusion layer adopts a hybrid convolution combining the spatial domain and the frequency domain. The frequency domain convolution can capture the global structure that is not easily perceived in the spatial domain by processing the frequency components of the sample; while the spatial domain convolution pays more attention to the local details of the sample. Therefore, through the combination of the spatial domain and frequency domain convolutions, the compensatory effect between local features and global features enables the policy network to learn and represent richer features, thereby generating an attack strategy with both global structure and local details; (2) Second, the feature fusion layer adopts multi-scale attention, which consists of a multi-scale convolution block, an efficient additive attention module, etc., and can transform the high-dimensional dot product operation into a low-dimensional additive operation, thereby reducing the computational amount. At the same time, it maintains the core characteristics of the self-attention mechanism, can effectively capture the dependencies between pixels at different distances (i.e., multi-scale) in the sample, represent multi-level complex features, and learn the association information between different regions, thereby generating more complex, diverse, and accurate attack strategies, comprehensively covering the vulnerable points of the target network; In addition, for the method proposed by the present invention, the change in the percentage of the perturbation intensity value of the attack strategies generated in different training stages has an obvious pattern: as the adversarial training progresses, the percentage of strong attacks gradually increases, and conversely, the percentage of weak attacks gradually decreases, showing a good trend of "weak first and then strong", and the change process is relatively smooth without obvious jitters. Therefore, by using the method proposed by the present invention to perform adversarial training on the target network, the problems of slow learning and non-convergence caused by strong attacks in the early stage of training can be avoided, and while significantly improving the effect of adversarial training and the robustness of the target network, the accuracy of clean sample classification is also improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0016] Figure 1 It is a flowchart of the method of the present invention.

[0017] Figure 2 It is a schematic structural diagram of the hybrid convolution of the present invention.

[0018] Figure 3 It is a schematic structural diagram of the spatial domain convolution of the present invention.

[0019] Figure 4 It is a schematic structural diagram of the frequency domain convolution of the present invention.

[0020] Figure 5 It is a schematic structural diagram of the frequency domain convolution based on the bottleneck structure of the present invention.

[0021] Figure 6 It is a schematic diagram of the application of the method of the present invention in adversarial training.

[0022] Figure 7 It is the comparative test result of the method of the present invention and other methods on the CIFAR-10 dataset.

[0023] Figure 8 It is the comparative test result of the method of the present invention and other methods on the CIFAR-100 dataset.

[0024] Figure 9 It is the ablation test result of the method of the present invention.

[0025] Figure 10 It is a change diagram of the percentage of the perturbation intensity value in different training stages of the present invention. Detailed implementation manners

[0026] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Usually, the components of the embodiments of the present invention described and illustrated herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents the selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts fall within the protection scope of the present invention.

[0027] As Figure 1 shown, this embodiment provides an automatic generation method for attack strategies for adversarial training, including the following steps: Step S1, construct an initial attack strategy library; obtain clean samples X, where the clean samples are image samples; In the initial stage, construct a strategy library containing various attack methods, such as FGSM, PGD, C&W, etc., and set the range of adjustable parameters for each attack method. For example, for the PGD attack method, three adjustable parameters can be set, namely the step size, the number of iterations, and the perturbation strength (or perturbation amplitude). A combination of the optional values of these parameters is an attack strategy. In this embodiment, unlabeled images are obtained from the CIFAR-10 and CIFAR-100 datasets as clean samples. The CIFAR-10 dataset covers 10 classes of images with a size of 32×32, and CIFAR-100 covers 100 classifications, with a total of 50,000 images in the training set and 10,000 images in the test set.

[0028] Step S2, first, input the clean sample X into the initial layer, where the initial layer consists of a 7x7 convolution, batch normalization (BN), and a Relu activation function to obtain the input feature Xin; The initial layer extracts low-level features in the clean sample X, such as edges and textures, through a 7x7 convolution kernel and a convolution operation with a stride of 2 to obtain the input feature Xin.

[0029] Step S3, then, input the input feature Xin into the feature fusion layer, and divide it into local feature Xin-l and global feature Xin-g according to the hyperparameter alpha in the feature dimension, and then perform feature fusion processing through convolution stage 1 (Conv1), convolution stage 2 (Conv2), multi-scale attention layer, convolution stage 3 (Conv3), and convolution stage 4 (Conv4) in sequence; In this embodiment, it is assumed that the dimension of the input feature Xin is 10 and the hyperparameter alpha is equal to 0.5. Then, the dimensions 1-5 of the input feature Xin are used as the local feature Xin-l, and the dimensions 6-10 are used as the global feature Xin-g; The first convolutional stage consists of three cascaded hybrid convolutions with the same structure; the hybrid convolution is as Figure 2 shown. First, the local feature Xin-l is respectively fed into two channels, Tll and Tlg. At the same time, the global feature Xin-g is respectively fed into two channels, Tgl and Tgg. Among them, the three channels Tll, Tlg, and Tgl perform spatial domain convolution processing, while the Tgg channel performs frequency domain convolution processing; then, after the local feature Xin-l is processed by the T11 channel and the global feature Xin-g is processed by the Tgl channel, they are summed to obtain Xout-l; after the local feature Xin-l is processed by the T1g channel and the global feature Xin-g is processed by the Tgg channel, they are summed to obtain Xout-g; The spatial domain convolution is as Figure 3 shown. Based on the idea of the Bottleneck Residual Structure, first use a 1x1 convolutional structure to replace the 3x3 convolutional structure to reduce the computational amount. After batch normalization and Relu activation function processing, use a 3x3 convolutional structure to extract features, and then after batch normalization and Relu activation function, finally use a 1x1 convolutional structure to restore the number of channels; The frequency domain convolution is as Figure 4 shown. After the global feature Xin-g is fed into the Tgg channel, it is transformed into the real part Y_R and the imaginary part Y_I by the Fast Fourier Transform (FFT). Subsequently, they are concatenated in the channel dimension, and then a 1x1 convolution is performed to extract the fused features of the real part and the imaginary part. After batch normalization and Relu activation function processing, finally, the Inverse Fourier Transform (IFFT) is performed; The frequency domain convolution can capture the global structure that is not easily perceived in the spatial domain by processing the frequency components of the samples, while the spatial domain convolution pays more attention to the local details of the samples. Through the combination of the spatial domain and frequency domain convolutions, the compensation effect between the global feature and the local feature enables the policy network to learn and represent richer features, so that an attack strategy with both global structure and local details can be generated; The second convolutional stage consists of four cascaded hybrid convolutions with the same structure, and the structure of the hybrid convolution is the same as that of the hybrid convolution in the first convolutional stage; The convolution stage 3 is composed of 6 cascaded hybrid convolutions with the same structure; the convolution stage 4 is composed of 3 cascaded hybrid convolutions with the same structure; the spatial domain convolution in the hybrid convolution in the convolution stages 3 and 4 has the same structure as that in the convolution stage 1. The difference is that the frequency domain convolution in the hybrid convolution in the convolution stages 3 and 4 uses a frequency domain convolution based on a bottleneck structure, as Figure 5 shown, that is, when performing frequency domain convolution processing, a 1x1 convolution processing is added before the inverse Fourier transform (IFFT). The reason for this is that as the network depth increases, relying solely on a single 1x1 convolution processing cannot better capture the increasingly rich global features, which is not conducive to the generation of subsequent high-quality attack strategies; The multi-scale attention layer, as Figure 1 shown, is composed of a multi-scale convolution block, an efficient additive attention module, and linearization. First, the multi-scale convolution block extracts multi-scale features of the sample through three different sizes of convolution kernels, namely 1x1, 3x3, and 5x5, which can effectively capture the dependencies between pixels at different distances in the sample and represent multi-level complex features. After each size of convolution operation, ReLU activation is performed to increase non-linearity. The outputs of the three sizes of convolution operations are concatenated in the channel dimension to obtain the final output feature map. Then, it is passed into the efficient additive attention module. The core idea of the efficient additive attention (EA) is to reduce the computational complexity by decomposing the calculation process of the attention weights and converting the high-dimensional dot product operation into a low-dimensional additive operation. Specifically, EA divides the calculation of the attention weights into two steps: (1) low-dimensional mapping, mapping the input sequence to a low-dimensional space; (2) additive attention, calculating the additive attention weights in the low-dimensional space instead of directly calculating the high-dimensional dot product. Therefore, EA can significantly reduce the computational complexity while maintaining the core characteristics of the self-attention mechanism, and can learn the correlation information between different regions to generate more complex, diverse, and accurate attack strategies. Finally, linearization processing is performed. The structure of the linearization consists of 2 1x1 pointwise convolution layers, batch normalization, and a ReLU activation function.

[0030] Step S4, finally, after being processed by the fully connected layer (i.e., the FC layer), an attack strategy is generated.

[0031] Figure 6 shows the application scenario of the attack strategy automatic generation method proposed in this embodiment in adversarial training. As Figure 6As shown in the figure, the adversarial training framework consists of a policy network and a target network, and the two networks have a competitive relationship. For the policy network, when given a clean sample, the policy network generates a corresponding attack strategy for the sample according to the method proposed in this embodiment; for the target network, the adversarial sample generator generates an adversarial sample according to the attack strategy and the target network for training the target network. At the same time, the target network also gives a supervision signal to the adversarial sample generator and the policy network respectively. In summary, the policy network takes the vulnerability points and training status of the target network as inputs and outputs the optimal attack strategy. The specific steps of applying the automatic attack strategy generation method in adversarial training are as follows: First, evaluate the performance of the target network on the validation set (such as changes in the loss function, improvement effect of robustness, etc.) and identify its vulnerability points (that is, the target network performs poorly on a certain type of adversarial sample); then, generate candidate attack strategies according to the vulnerability points and select the optimal strategy through the policy network; finally, use the optimal attack strategy to generate adversarial samples and add them to the training set for training the target network.

[0032] To verify the effectiveness of the method, this embodiment adopts a robustness evaluation method with single-step update of the target network. The target network uses WRN34-10, and its architecture is a wide residual network (WRN, Wide Residual Networks) improved on the basis of the residual network ResNet. Specifically, WRN34-10 represents a wide residual network with 34 layers in depth and a width factor of 10. This network structure mainly improves the performance of the model by increasing the width of the network (i.e., the number of channels in each layer) rather than simply increasing the depth of the network. The specific steps of the test are as follows: First, generate an attack strategy using the method proposed in this embodiment; then, generate an adversarial sample through the adversarial sample generator, and the adversarial sample adjusts the parameters of the target network step by step through the first-order gradient descent method; finally, if the updated target network can correctly predict the label of the adversarial sample generated by other attack strategies, it means that the attack strategy is effective. At the same time, a good attack strategy should not only improve the robustness of the target network but also maintain the accuracy of predicting clean samples. Therefore, this embodiment also evaluates the performance of the target network when predicting clean samples with single-step update. As Figure 7 、 Figure 8 shown, they respectively represent the performance test results of different adversarial training methods on different datasets such as CIFAR-10 and CIFAR-100. It can be found that in attack scenarios such as FGSM, PGD-10, PGD-20, PGD-50, and C&W, after using the method proposed in this embodiment to perform adversarial training on the target network, its performance is better than other methods, not only improving the robustness of the target network but also improving the accuracy of clean sample classification.

[0033] To verify the effectiveness of the hybrid convolution and multi-scale attention in the feature fusion layer, in this embodiment, the policy network is divided into four cases: "no hybrid convolution / no multi-scale attention", "with hybrid convolution / no multi-scale attention", "no hybrid convolution / with multi-scale attention", and "with hybrid convolution / with multi-scale attention". The target network adopts the ResNet-18 structure, and the robustness of the single-step update of the target network is evaluated on the dataset CRFAR-10. At the same time, the performance of the single-step update target network in predicting clean samples is evaluated. The test results show that, as Figure 9 shown, in attack scenarios such as FGSM and PGD-10, when the policy network uses hybrid convolution or multi-scale attention alone, the robustness of the target network and the performance of predicting clean samples are both improved; while when the policy network uses hybrid convolution and multi-scale attention simultaneously, the robustness of the target network and the performance of predicting clean samples reach the best.

[0034] Generally, the attack strategy will affect the effect of adversarial training. A good attack strategy is to use weak attacks in the early stage of training and strong attacks in the later stage. For this reason, this embodiment analyzes the distribution of the perturbation intensity of the attack strategies generated by the proposed method at different training stages. Preferably, in this embodiment, the range of the PGD perturbation intensity is set to 3-15. The test results show that in the early stage of adversarial training, the distribution covers all optional values of the perturbation intensity, and each value has a chance to be selected, which ensures the diversity of adversarial samples. As the adversarial training progresses, the percentage of small perturbation intensities decreases. In the later stage of training, the distribution of the perturbation intensity is occupied by several large values. This phenomenon indicates that the policy network gradually increases the percentage of large perturbation intensities to generate stronger adversarial perturbations, and thus the robustness of the target network is gradually enhanced by training with strong adversarial samples. At the same time, the change of the perturbation intensity of the attack strategies generated by the method proposed in this embodiment at different training stages has an obvious pattern, as Figure 10 shown, which shows the change graph of the percentages of the perturbation intensity values of 5 (representing weak attacks), 8 (medium), and 12 (representing strong attacks) at different training stages. It can be seen that as the adversarial training progresses, the percentage of the strong attack with a perturbation intensity value of 12 gradually increases, and conversely, the percentage of the weak attack with a perturbation intensity value of 5 gradually decreases, showing a good trend of "weak first and then strong", and the change process is relatively smooth without obvious jitter, indicating that the method proposed in this embodiment can avoid the problems of slow learning and non-convergence caused by strong attacks in the early stage of training, thereby effectively improving the effect of adversarial training.

[0035] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. Those skilled in the art can make various modifications to the above content without departing from the spirit and scope of the present invention defined by the claims. Therefore, the scope of the present invention is not limited to the above description but is determined by the scope of the claims.

Claims

1. A method for automatically generating attack strategies for adversarial training, characterized in that: include: Step S1, constructing an initial attack strategy library; Obtain a clean sample X, where the clean sample is an image sample; Step S2: First, the clean sample X is passed into the initial layer, which consists of 7x7 convolution, batch normalization and Relu activation function to obtain the input feature Xin; Step S3, then, the input feature Xin is passed into the feature fusion layer, and it is divided into local feature Xin-1 and global feature Xin-g according to the feature dimension according to the hyperparameter alpha, and is sequentially processed through convolution stage 1, convolution stage 2, multi-scale attention layer, convolution stage 3 and convolution stage 4 for feature fusion processing; Step S4, finally, after being processed by the fully connected layer, an attack strategy is generated.

2. The method for automatically generating attack strategies for adversarial training according to claim 1, characterized in that: The step S1 comprises: The initial attack strategy library includes multiple attack methods, and sets a range of adjustable parameters for each attack method.

3. The method for automatically generating attack strategies for adversarial training according to claim 1, characterized in that: The step S3 comprises: The convolution stage 1 is composed of three mixed convolution cascades with the same structure; The convolution stage 2 is composed of 4 mixed convolution cascades with the same structure, and the mixed convolution has the same structure as the mixed convolution in the convolution stage 1; The convolution stage 3 is composed of 6 mixed convolution cascades with the same structure; The convolution stage 4 is composed of three mixed convolution cascades with the same structure, and the mixed convolution has the same structure as the mixed convolution in the convolution stage 3; The multi-scale attention layer is composed of a multi-scale convolution block, an efficient additive attention module and linearization.

4. The method for automatically generating attack strategies for adversarial training according to claim 1, characterized in that: The step S4 comprises: The attack strategy is a combination of optional values ​​of adjustable parameters of the attack method.

5. The method for automatically generating attack strategies for adversarial training according to claim 3, characterized in that: The convolution stage 1 includes: The mixed convolution first sends the local feature Xin-1 to the two channels Tll and Tlg respectively, and at the same time, sends the global feature Xin-g to the two channels Tgl and Tgg respectively, wherein the three channels Tll, Tlg and Tgl are processed in the spatial domain, and the Tgg channel is processed in the frequency domain; then, the local feature Xin-1 is processed by the T11 channel and the global feature Xin-g is processed by the Tgl channel, and then the sum is obtained to obtain Xout-1; the local feature Xin-1 is processed by the T1g channel and the global feature Xin-g is processed by the Tgg channel, and then the sum is obtained to obtain Xout-g; The spatial domain convolution, based on the bottleneck residual structure idea, first uses a 1x1 convolution structure instead of a 3x3 convolution structure to reduce the amount of calculation, and after batch normalization and Relu activation function processing, uses a 3x3 convolution structure to extract features, and then after batch normalization and Relu activation function, finally uses a 1x1 convolution structure to restore the number of channels; In the frequency domain convolution, after the global feature Xin-g is passed into the Tgg channel, it is transformed into the real part Y_R and the imaginary part Y_I through fast Fourier transformation, and then spliced ​​in the channel dimension, and then a 1x1 convolution is performed to extract the fusion features of the real part and the imaginary part, and then processed by batch normalization and Relu activation function, and finally the inverse Fourier transformation is performed.

6. The method for automatically generating attack strategies for adversarial training according to claim 3, characterized in that: The convolution stage 3 includes: The spatial domain convolution in the hybrid convolution in the convolution stage 3 has the same structure as that in the convolution stage 1. The difference is that the frequency domain convolution in the hybrid convolution in the convolution stage 3 adopts a frequency domain convolution based on a bottleneck structure, that is, when performing frequency domain convolution processing, a 1x1 convolution processing is added before the inverse Fourier transform.

7. The method for automatically generating attack strategies for adversarial training according to claim 3, characterized in that: The multi-scale attention layer includes: The multi-scale attention layer, first, the multi-scale convolution block extracts the multi-scale features of the sample through three different sizes of convolution kernels: 1x1, 3x3 and 5x5. After each size of convolution operation, ReLU activation is performed to increase nonlinearity. The outputs of the three sizes of convolution operations are spliced ​​in the channel dimension to obtain the final output feature map; then, it is passed to the efficient additive attention module, and the high-dimensional dot product operation is converted into a low-dimensional additive operation by decomposing the calculation process of the attention weight; finally, linearization processing is performed, and the linearization structure consists of 2 1x1 point-by-point convolution layers, batch normalization and ReLU activation function.