Adversarial patch defense model evaluation method and related device
Through unified experimental settings and data amplification technology, a standardized test platform is formed, which solves the defects of the anti-patch defense model evaluation method in the existing technology, and realizes a comprehensive and systematic evaluation of the anti-patch defense model, ensuring the reliability and reproducibility of the evaluation results.
Patent Information
- Application Number
- CN202510342441.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-24
AI Technical Summary
The existing anti-patch defense model evaluation method has flaws, focusing on testing under a single attack condition, neglecting the adaptability and real-time nature of the defense strategy in multiple scenarios, and it is difficult to comprehensively evaluate the actual effect of the anti-patch defense model.
Through preset training data sets, preset amplification data sets and preset test data sets, unified experimental settings are achieved, and a standardized test platform is formed to ensure fair comparisons between different adversarial patch defense models. Different scenarios are simulated through data amplification technology, and diverse attack scenarios and target objects are introduced.
A comprehensive and systematic evaluation of the adversarial patch defense model is achieved, ensuring the reliability and reproducibility of the evaluation results, and can more comprehensively reflect the robustness and adaptability of the defense strategy in complex and dynamic environments, and provide a scientific basis for optimizing the adversarial patch defense model.
Smart Images

Figure CN120196525A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of image processing, and relates to a method and related device for evaluating an adversarial patch defense model. Background Art
[0002] In recent years, deep learning technology has made remarkable progress in the field of computer vision, and has been widely applied in tasks such as image classification, object detection, and autonomous driving. However, with the popularization of deep learning models, researchers have found that these models are often vulnerable to carefully designed adversarial samples and are easily attacked. Adversarial attacks impose tiny perturbations on the input data, causing the model to output incorrect predictions, thereby threatening the security and reliability of the model. In computer vision, adversarial patches, as a common adversarial attack method, have been widely applied to image processing tasks such as image classification and object detection. An adversarial patch is a pattern that has nothing to do with the image content. Through careful design, the attacker can make it induce an image processing model to make incorrect predictions when added to any position of the image. Compared with traditional adversarial samples, adversarial patches do not require pixel-level tiny perturbations to the image, but adopt a more intuitive and easy-to-implement method, that is, by adding obvious patch patterns to deceive the model.
[0003] To cope with adversarial patch attacks, adversarial patch defense models have emerged. Such adversarial patch defense models are specifically designed for adversarial patch attacks, aiming to improve the robustness of image processing and computer vision systems when facing such attacks. The development and application of adversarial patch defense models provide new ideas and methods for protecting image processing models from the interference of adversarial patches. However, with the continuous progress of adversarial attack technology, the evaluation of adversarial patch defense models has become particularly important. The evaluation not only concerns the accuracy of the adversarial patch defense model itself, but also comprehensively examines its performance under different attack scenarios and environmental conditions. An effective evaluation method can objectively reflect the advantages and disadvantages of the adversarial patch defense model, provide a scientific basis for the optimization and improvement of the adversarial patch defense model, and thus promote the continuous development of image processing technology.
[0004] However, there are many defects in the existing evaluation methods for adversarial patch defense models. On the one hand, these evaluation methods often focus on testing under single attack conditions, ignoring the adaptability and real-time performance of defense strategies in multiple scenarios. On the other hand, with the rapid development of adversarial attack technologies, it has become difficult to comprehensively evaluate the actual effectiveness of adversarial patch defense models solely relying on traditional defense evaluation methods. Therefore, it is particularly urgent to develop a comprehensive and systematic evaluation method for adversarial patch defense models to provide strong support for the optimization of adversarial patch defense technologies. Through scientific evaluation, the development of adversarial patch defense technologies can be better promoted, the robustness and security of image processing models in practical applications can be improved, and high-quality image processing results can be obtained. Summary of the Invention
[0005] An object of the present invention is to overcome the above-mentioned disadvantages of the prior art and provide an evaluation method and related device for an adversarial patch defense model.
[0006] To achieve the above object, the present invention adopts the following technical solutions:
[0007] In the first aspect of the present invention, an evaluation method for an adversarial patch defense model is provided, including: training an adversarial patch defense model according to a preset training data set to obtain a preliminarily trained adversarial patch defense model; wherein, the training data set includes adversarial patch samples based on different generation types; training the preliminarily trained adversarial patch defense model according to a preset augmented data set to obtain a finally trained adversarial patch defense model; wherein, the augmented data set is obtained by simulating different scenarios through data augmentation techniques based on the training data set; based on a preset test data set, obtaining the accuracy index value, generalization index value, robustness index value, and defense efficiency index value of the finally trained adversarial patch defense model and weighted superposition to obtain the evaluation value of the finally trained adversarial patch defense model.
[0008] Optionally, the adversarial patch samples based on different generation types include: adversarial patch samples generated based on a generative adversarial network, adversarial patch samples generated based on an autoencoder, adversarial patch samples generated based on a graphical generation method, and adversarial patch samples generated based on an optimization algorithm.
[0009] Optionally, the augmented data set is obtained through the following method: processing the adversarial patch samples of the preset training data set through one or a combination of several preset data augmentation processing methods to obtain a preset augmented data set; wherein, the preset data augmentation processing methods include: changing the perspective of the target object in the adversarial patch samples, modifying the lighting conditions of the adversarial patch samples, and modifying the background environment of the adversarial patch samples.
[0010] Optionally, the accuracy metric values include: classification accuracy, recall rate, F1 score, and defense success rate; the generalization metric values include: accuracy error and defense success rate error under adversarial patch samples of different generation types; the robustness metric values include: defense success rate error and defense accuracy error under adversarial patch samples of different physical interference factors; the defense efficiency metric values include: inference time, throughput, memory usage, power consumption, defense success rate per unit time, defense cost ratio, and deployment scenario performance difference.
[0011] Optionally, the physical interference factors include two or more of the following: light intensity change, shadow coverage, Gaussian blur, noise addition, and camera view shift.
[0012] Optionally, when obtaining the accuracy metric values, generalization metric values, robustness metric values, and defense efficiency metric values of the finally trained adversarial patch defense model and performing weighted superposition, the weights for weighting are determined according to the application scenario of the adversarial patch defense model or by means of sensitivity analysis.
[0013] Optionally, it further includes: based on a preset actual adversarial patch sample, obtaining the accuracy metric values, generalization metric values, robustness metric values, and defense efficiency metric values of the finally trained adversarial patch defense model under the actual adversarial patch sample and performing weighted superposition to obtain the actual application performance evaluation value of the finally trained adversarial patch defense model; wherein, the actual adversarial patch sample is obtained by performing an adversarial attack on the image to be attacked captured by the camera.
[0014] In a second aspect of the present invention, there is provided an adversarial patch defense model evaluation system, including: a preliminary training module for training an adversarial patch defense model according to a preset training data set to obtain a preliminarily trained adversarial patch defense model; wherein, the training data set includes adversarial patch samples based on different generation types; a final training module for training the preliminarily trained adversarial patch defense model according to a preset augmented data set to obtain a finally trained adversarial patch defense model; wherein, the augmented data set is obtained by simulating different scenarios through a data augmentation technique; an evaluation module for obtaining the accuracy metric values, generalization metric values, robustness metric values, and defense efficiency metric values of the finally trained adversarial patch defense model based on a preset test data set and performing weighted superposition to obtain an evaluation value of the finally trained adversarial patch defense model.
[0015] In a third aspect of the present invention, there is provided a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the above-mentioned adversarial patch defense model evaluation method are implemented.
[0016] In the fourth aspect of the present invention, there is provided a computer-readable storage medium storing a computer program which, when executed by a processor, implements the steps of the above-mentioned evaluation method for the adversarial patch defense model.
[0017] Compared with the prior art, the present invention has the following beneficial effects:
[0018] The evaluation method for the adversarial patch defense model of the present invention first realizes unified experimental settings through a preset training data set, a preset augmented data set, and a preset test data set, provides a standardized test platform for different adversarial patch defense models, ensures fair comparison between different adversarial patch defense models, eliminates biases in the testing process, and ensures the reliability and reproducibility of the evaluation results. Secondly, based on adversarial patch samples of different generation types, a training data set is formed, and an augmented data set is obtained by simulating different scenarios through data augmentation techniques, introducing diverse attack scenarios and target objects, simulating different attack perspectives, object surface characteristics, and environmental conditions, further improving the applicable scope of the experimental settings, and enabling it to more comprehensively reflect the robustness and adaptability of the defense strategy in complex and dynamic environments. In addition, the evaluation value is obtained by weighted superposition of the accuracy index value, generalization index value, robustness index value, and defense efficiency index value, not only paying attention to the effectiveness of the defense effect, but also considering the defense efficiency index value, ensuring that the defense system can respond to adversarial attacks in real time while operating efficiently, revealing the potential vulnerabilities of the defense strategy in the face of adversarial attacks, and providing data support for further optimizing the adversarial patch defense model. By comprehensively considering experimental settings, attack scenarios, and diverse tests, the present invention comprehensively improves the evaluation effect of the adversarial patch defense model and provides scientific and systematic guidance for the research and optimization of future adversarial patch defense models. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a flowchart of the evaluation method for the adversarial patch defense model according to an embodiment of the present invention.
[0020] Figure 2 It is a structural block diagram of the evaluation system for the adversarial patch defense model according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0022] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.
[0023] The present invention will be further described in detail below with reference to the drawings:
[0024] See Figure 1 , in an embodiment of the present invention, a method for evaluating an adversarial patch defense model is provided, which provides a basis for designing a more robust and efficient adversarial patch defense model, and can be widely applied to the security protection of image processing models in fields such as autonomous driving and security monitoring.
[0025] Specifically, the method for evaluating the adversarial patch defense model of the present invention includes the following steps:
[0026] S1: Train an adversarial patch defense model according to a preset training data set to obtain a preliminary trained adversarial patch defense model; wherein, the training data set includes adversarial patch samples based on different generation types.
[0027] S2: Train the preliminary trained adversarial patch defense model according to a preset augmented data set to obtain a final trained adversarial patch defense model; wherein, the augmented data set is obtained by simulating different scenarios through data augmentation technology based on the training data set.
[0028] S3: Based on a preset test data set, obtain the accuracy index value, generalization index value, robustness index value and defense efficiency index value of the final trained adversarial patch defense model and perform weighted superposition to obtain the evaluation value of the final trained adversarial patch defense model.
[0029] The evaluation method for the adversarial patch defense model of the present invention first realizes unified experimental settings through a preset training dataset, a preset augmented dataset, and a preset test dataset, providing a standardized test platform for different adversarial patch defense models, ensuring fair comparison between different adversarial patch defense models, eliminating biases in the testing process, and ensuring the reliability and reproducibility of the evaluation results. Secondly, training datasets are formed based on adversarial patch samples of different generation types, and augmented datasets are obtained by simulating different scenarios through data augmentation techniques, introducing diverse attack scenarios and target objects, simulating different attack perspectives, object surface characteristics, and environmental conditions, further improving the applicable scope of the experimental settings, and enabling it to more comprehensively reflect the robustness and adaptability of defense strategies in complex and dynamic environments. In addition, the evaluation value is obtained by weighted superposition of the accuracy index value, generalization index value, robustness index value, and defense efficiency index value. It not only focuses on the effectiveness of the defense effect but also considers the defense efficiency index value, ensuring that while the defense system operates efficiently, it can respond to adversarial attacks in real time, revealing the potential vulnerabilities of defense strategies when facing adversarial attacks, and providing data support for further optimizing the adversarial patch defense model. The present invention comprehensively improves the evaluation effect of the adversarial patch defense model by considering experimental settings, attack scenarios, and diverse tests, and provides scientific and systematic guidance for the research and optimization of future adversarial patch defense models.
[0030] Explanatorily, the adversarial patch defense model includes models based on convolutional neural networks, models based on residual networks, and models based on Transformer networks. Convolutional neural network: As a classic computer vision model, it is widely used in object detection and the defense of adversarial samples. When processing image data, it can effectively extract local features, thereby helping to identify and classify patch attacks. Residual network: Utilizes residual connections to solve the problem of gradient disappearance in deep networks, enabling better training of deep neural networks and having advantages in defending against complex adversarial attacks. Transformer network: An emerging architecture in recent years, due to its superior performance in sequence data processing, it has gradually been applied to image processing and adversarial sample defense tasks. The Transformer can capture long-range dependencies in images through self-attention mechanisms, improving the recognition ability of adversarial patches.
[0031] In a possible implementation manner, the adversarial patch samples based on different generation types include: adversarial patch samples generated based on generative adversarial networks, adversarial patch samples generated based on autoencoders, adversarial patch samples generated based on graphical generation methods, and adversarial patch samples generated based on optimization algorithms.
[0032] Explanatory, construct a unified experimental platform, including diverse attack scenarios, target objects, and environmental conditions. Select representative adversarial patch defense models and test them from multiple attack perspectives, object surface characteristics, and environmental factors to ensure that the evaluation covers various complex scenarios in practical applications.
[0033] Adversarial patch samples generated based on generative adversarial networks: Use generative adversarial network models to generate adversarial patch samples and evaluate the challenges posed by this type of adversarial patch samples to the defense capabilities of adversarial patch defense models. Adversarial patch samples generated based on autoencoders: Generate adversarial patch samples through autoencoders to test the impact of adversarial patch samples generated by autoencoders on adversarial patch defense models. Adversarial patch samples generated based on graphical generation methods: Generate adversarial patch samples using graphical generation techniques and examine their attack effects on adversarial patch defense models. Adversarial patch samples generated based on optimization algorithms: Generate adversarial patch samples using optimization algorithm generation techniques and examine their attack effects on adversarial patch defense models.
[0034] Exemplary, it may also include adversarial patch samples generated by a combination of at least two of generative adversarial networks, autoencoders, graphical generation methods, and optimization algorithms. Combine adversarial patch samples of different generation methods to examine whether the model can effectively cope with multiple attack means.
[0035] Exemplary, the training dataset includes a training set, a validation set, and a test set, and the proportions of each type of adversarial patch sample in the training set, validation set, and test set are the same. Training set: The basic dataset for training the adversarial patch defense model, containing different types of adversarial patch samples. Validation set: The dataset used to verify the performance of the adversarial patch defense model during training to ensure that the adversarial patch defense model can generalize well on unknown samples. Test set: An independent dataset used to evaluate the final training results. The selection of the test set should ensure that it covers a sufficient number of adversarial patch samples and attack types to ensure the fairness and integrity of the evaluation.
[0036] In a possible implementation, the augmented dataset is obtained in the following manner: Process the adversarial patch samples of the preset training dataset through one or a combination of several preset data augmentation processing methods to obtain a preset augmented dataset; where the preset data augmentation processing methods include: changing the perspective of the target object in the adversarial patch samples, modifying the lighting conditions of the adversarial patch samples, and modifying the background environment of the adversarial patch samples.
[0037] Explanatory, simulate various actual scenarios through data augmentation techniques, such as different perspectives, lighting conditions, and background environments, to further improve the defense effect of the adversarial patch defense model in complex physical environments.
[0038] In a possible implementation, according to the training method of the adversarial patch defense model, first, a suitable open-source adversarial patch sample dataset is selected, and the diversity of the dataset is expanded in combination with actual application requirements. Subsequently, these diverse adversarial patch sample datasets are applied to the training process of the adversarial patch defense model, and the training mechanism is used to enhance the robustness and adaptability of the adversarial patch defense model to adversarial patch samples.
[0039] Exemplarily, the training process includes a multi-stage strategy: in the first stage, preliminary training is carried out using a standard dataset to ensure that the adversarial patch defense model has basic recognition capabilities in the absence of adversarial interference; in the second stage, multiple types of adversarial patch samples are combined with the original data to form a mixed training set, and strategies are generated for different adversarial patch samples to optimize the defense performance of the adversarial patch defense model; in the third stage, data augmentation techniques are used to simulate various actual scenarios, such as different perspectives, lighting conditions, and background environments, to further improve the defense effect of the adversarial patch defense model in complex physical environments. Finally, after multiple iterations of optimization and verification, an adversarial patch defense model optimized for different adversarial patch sample generation strategies and application scenarios is obtained.
[0040] In a possible implementation, the accuracy metric values include: classification accuracy, recall rate, F1 score, and defense success rate; the generalization metric values include: accuracy error and adversarial success rate error under adversarial patch samples of different generation types; the robustness metric values include: defense success rate error and defense accuracy error under adversarial patch samples of different physical interference factors; the defense efficiency metric values include: inference time, throughput, memory usage, power consumption, defense success rate per unit time, defense cost ratio, and deployment scenario performance difference.
[0041] Explanatorily, based on a preset test dataset, the finally trained adversarial patch defense model is tested to obtain the accuracy metric values of the finally trained adversarial patch defense model under i.i.d. data, as well as the generalization metric values, robustness metric values, and defense efficiency metric values under non-i.i.d. data.
[0042] Exemplarily, in this embodiment, systematic steps are adopted to comprehensively evaluate the performance of the final trained adversarial patch defense model. First, various current technical means for generating adversarial patches are integrated to construct a large-scale and diverse dataset of adversarial patch samples, providing a diverse sample source for evaluation. During the evaluation process, classification judgment is made according to whether the adversarial patch samples belong to the same type of attack method: for the same type of attack, the accuracy index of the model is mainly tested; for different types of attacks, its generalization performance is evaluated. In addition, various interference factors in the actual scenario (such as changes in shooting angle and environmental light) are simulated for scene generalization testing to further examine the adaptability and robustness of the model. At the same time, by adding noise and Gaussian blur and other interferences, the robustness of the model in a complex environment is measured. Finally, the efficiency index of the model is evaluated, including time cost and hardware resource consumption, to ensure the efficiency and feasibility of the model in practical applications. Through multi-dimensional comprehensive evaluation, the method of the present invention can comprehensively measure the performance of the model in terms of accuracy, generalization, robustness and efficiency, providing a scientific basis for optimizing the adversarial patch defense model.
[0043] Specifically, in the accuracy evaluation under the same distribution data, the effectiveness of the model in known attack scenarios is mainly investigated. The specific method is to generate adversarial patch samples using the same attack method as in the model training stage and input them into the model. By recording indicators such as classification accuracy, recall rate, F1 score and defense success rate, it is analyzed whether the model can effectively resist adversarial attacks under the same distribution. This evaluation can verify the reliability of the model under ideal conditions and lay a foundation for evaluating the defense ability of the model in a standard environment. At the same time, by comparing the performance of models with different training strategies in this indicator, methods for improving the accuracy of the model can also be found.
[0044] In the generalization evaluation under different distribution data, the performance of the model when facing unknown attack types is tested, and its universality is mainly investigated. The specific steps are to construct a dataset of adversarial patch samples of multiple types and mix them to form diverse test samples. These test samples are input into the model, and the accuracy, accuracy error and adversarial success rate error of the model under different types of attacks are observed. This evaluation aims to verify the cross-attack adaptation ability of the model and the performance stability when facing completely unknown attack strategies. The test results can provide a direction for improving the generalization performance of the model, such as exploring a wider training dataset and a more robust defense strategy.
[0045] Optionally, the physical interference factors include two or more of the following: change in light intensity, shadow coverage, Gaussian blur, noise addition, and camera view offset.
[0046] Specifically, in the robustness evaluation, the performance of the model in a complex physical environment is analyzed, and its defense effect under various interference conditions is examined. By introducing a variety of common physical interference factors, such as changes in light intensity, shadow coverage, Gaussian blur, noise addition, and camera view offset, the test data is processed and input into the model. Under these complex conditions, the defense success rate, defense accuracy, and error fluctuation range are recorded. This evaluation can reveal the challenges that the model may face in practical applications and identify its potential weak links. For example, some models may perform well under specific light conditions but experience a significant decline in performance when the camera view changes. Through such analysis, guidance can be provided for optimizing the robustness of the model.
[0047] In the defense efficiency evaluation, combined with the actual application requirements, starting from two aspects of time cost and hardware resource requirements, the practicality of the model is comprehensively analyzed. In different computing environments (such as CPU, GPU, and edge devices), the inference time, throughput, memory usage, power consumption, and the defense success rate and defense cost ratio per unit time of the model are measured. At the same time, simulating the application requirements in real scenarios, such as the real-time requirements in autonomous driving or the large-scale deployment scenarios in security monitoring, the performance of the model under these conditions is analyzed. For example, some models may perform excellently on high-performance devices but be inefficient due to memory limitations in edge devices. Through these analyses, the deployment potential of the model in different application scenarios can be evaluated, and important basis can be provided for optimizing the model performance and reducing the defense cost.
[0048] In a possible implementation manner, when obtaining the accuracy index value, generalization index value, robustness index value, and defense efficiency index value of the finally trained adversarial patch defense model and performing weighted superposition, the weights for weighting are determined according to the application scenario of the adversarial patch defense model or by the sensitivity analysis method.
[0049] Explanatorily, in order to comprehensively evaluate the comprehensive performance of the finally trained adversarial patch defense model, a weighted superposition method based on preset weights is proposed for its accuracy index value, generalization index value, robustness index value, and defense efficiency index value. By assigning reasonable weights to different indicators, these index values are combined to generate a comprehensive evaluation result, which comprehensively reflects the performance of the defense model to be evaluated in each dimension.
[0050] During the weighted superposition process, first, according to the actual application requirements and scenario characteristics, the weights of each evaluation dimension are set. For example, in scenarios with high real-time requirements, such as autonomous driving or intelligent monitoring systems, the defense efficiency may occupy a higher weight; while in fields with stronger security requirements, such as financial or medical systems, the accuracy and robustness indicators may be given a greater proportion. The setting of weights needs to comprehensively consider the important performance requirements of the target scenario, so that the final evaluation result can truly reflect the practical value of the model.
[0051] Specifically, the values of each indicator are normalized according to a unified standardization process to ensure that they have the same dimension when weighted and superimposed. Subsequently, according to the preset weight ratio, the standardized values of the accuracy indicator value, generalization indicator value, robustness indicator value, and defense efficiency indicator value are multiplied by the corresponding weights and summed to finally obtain a single comprehensive score. This score can intuitively show the comprehensive performance of the model in various aspects and provide a quantitative basis for performance comparison between different models.
[0052] Exemplarily, in order to better analyze the contribution of different indicators to the comprehensive evaluation result, the sensitivity analysis can also be used to study the impact of weight changes on the final result. For example, by adjusting the weight ratio, observe the importance of each dimension indicator in different application scenarios, so as to adjust the optimization direction of the model. This comprehensive evaluation method not only improves the scientificity and objectivity of the defense model performance evaluation, but also provides an important reference basis for designing more efficient and robust defense models.
[0053] In a possible implementation manner, the method for evaluating the adversarial patch defense model further includes: based on a preset actual adversarial patch sample, obtaining the accuracy indicator value, generalization indicator value, robustness indicator value, and defense efficiency indicator value of the finally trained adversarial patch defense model under the actual adversarial patch sample and performing weighted superposition to obtain the evaluation value of the actual application performance of the finally trained adversarial patch defense model; wherein, the actual adversarial patch sample is obtained by performing an adversarial attack on the image to be attacked captured by the camera.
[0054] Explanatorily, the actual performance of the model is tested through physical world experiments to evaluate whether the adversarial patch defense model can work effectively in the actual application environment.
[0055] Exemplarily, physical world experiment: By applying the model to the actual environment, such as performing an adversarial attack based on the images captured by the camera, the effect of the model in the real environment is tested. This evaluation method takes into account the interference factors in the real world such as light, angle, and noise to ensure the practical applicability of the model.
[0056] The following is an apparatus embodiment of the present invention, which can be used to execute the method embodiment of the present invention. For details not disclosed in the apparatus embodiment, please refer to the method embodiment of the present invention.
[0057] Referring to Figure 2 , in another embodiment of the present invention, there is provided an adversarial patch defense model evaluation system, which can be used to implement the above-mentioned adversarial patch defense model evaluation method. Specifically, the adversarial patch defense model evaluation system includes a preliminary training module, a final training module, and an evaluation module.
[0058] Among them, the preliminary training module is used to train an adversarial patch defense model according to a preset training data set to obtain a preliminary trained adversarial patch defense model; among them, the training data set includes adversarial patch samples based on different generation types; the final training module is used to train the preliminary trained adversarial patch defense model according to a preset augmented data set to obtain a final trained adversarial patch defense model; among them, the augmented data set is obtained by simulating different scenarios through data augmentation technology based on the training data set; the evaluation module is used to obtain the accuracy index value, generalization index value, robustness index value, and defense efficiency index value of the final trained adversarial patch defense model based on a preset test data set and weighted superposition to obtain the evaluation value of the final trained adversarial patch defense model.
[0059] All relevant contents of each step involved in the embodiment of the above-mentioned adversarial patch defense model evaluation method can be cited in the function description of the corresponding functional module of the adversarial patch defense model evaluation system in the embodiment of the present invention, and will not be elaborated here.
[0060] The division of modules in the embodiments of the present invention is illustrative, only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present invention, each functional module can be integrated in a processor, or can exist independently physically, or two or more modules can be integrated in one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0061] In another embodiment of the present invention, a computer device is provided. The computer device includes a processor and a memory. The memory is used to store a computer program, and the computer program includes program instructions. The processor is used to execute the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function. The processor described in the embodiment of the present invention can be used for the operation of the anti-patch defense model evaluation method.
[0062] In another embodiment of the present invention, a storage medium is also provided, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in the computer device and is used to store programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and, of course, the extended storage medium supported by the computer device. The computer-readable storage medium provides a storage space, and the operating system of the terminal is stored in this storage space. And, one or more instructions suitable for being loaded and executed by the processor are also stored in this storage space. These instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. One or more instructions stored in the computer-readable storage medium can be loaded and executed by the processor to implement the corresponding steps of the anti-patch defense model evaluation method in the above embodiment.
[0063] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0064] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0065] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0066] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable devices provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0067] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: still can modify the specific implementation manners of the present invention or make equivalent replacements. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A method for evaluating an anti-patch defense model, characterized in that: include: Training the adversarial patch defense model according to a preset training data set to obtain an initially trained adversarial patch defense model; wherein the training data set includes adversarial patch samples based on different generation types; The initial training adversarial patch defense model is trained according to a preset augmented data set to obtain a final training adversarial patch defense model; wherein the augmented data set is obtained by simulating different scenarios based on the training data set through data augmentation technology; Based on the preset test data set, the accuracy index value, generalization index value, robustness index value and defense efficiency index value of the final trained adversarial patch defense model are obtained and weightedly superimposed to obtain the evaluation value of the final trained adversarial patch defense model.
2. The anti-patch defense model evaluation method according to claim 1 is characterized in that: The adversarial patch samples based on different generation types include: Adversarial patch samples generated based on generative adversarial networks, adversarial patch samples generated based on autoencoders, adversarial patch samples generated based on graphical generation methods, and adversarial patch samples generated based on optimization algorithms.
3. The anti-patch defense model evaluation method according to claim 1 is characterized in that: The amplified data set is obtained by: The adversarial patch samples of the preset training data set are processed by one or a combination of several preset data augmentation processing methods to obtain a preset augmented data set; wherein the preset data augmentation processing methods include: changing the perspective of the target object in the adversarial patch sample, modifying the lighting condition of the adversarial patch sample, and modifying the background environment of the adversarial patch sample.
4. The anti-patch defense model evaluation method according to claim 1 is characterized in that: The accuracy index values include: classification accuracy, recall rate, F1 score and defense success rate; the generalization index values include: accuracy error and adversarial success rate error under adversarial patch samples of different generation types; the robustness index values include: defense success rate error and defense accuracy error under adversarial patch samples of different physical interference factors; the defense efficiency index values include: inference time, throughput, memory usage, power consumption, defense success rate and defense cost ratio per unit time, and deployment scenario performance differences.
5. The anti-patch defense model evaluation method according to claim 4 is characterized in that: The physical interference factors include two or more of the following: Light intensity variation, shadow overlay, Gaussian blur, noise addition, and camera perspective offset.
6. The anti-patch defense model evaluation method according to claim 1 is characterized in that: When the accuracy index value, generalization index value, robustness index value and defense efficiency index value of the final trained anti-patch defense model are obtained and weighted and superimposed, the weighted weights are determined according to the application scenario of the anti-patch defense model or by a sensitivity analysis method.
7. The anti-patch defense model evaluation method according to claim 1 is characterized in that: Also includes: Based on the preset actual adversarial patch samples, the accuracy index value, generalization index value, robustness index value and defense efficiency index value of the final trained adversarial patch defense model under the actual adversarial patch samples are obtained and weighted superimposed to obtain the actual application performance evaluation value of the final trained adversarial patch defense model; Among them, the actual adversarial patch sample is obtained by performing an adversarial attack on the image to be attacked captured by the camera.
8. A system for evaluating an anti-patch defense model, characterized in that: include: An initial training module, used to train the adversarial patch defense model according to a preset training data set to obtain an initial trained adversarial patch defense model; wherein the training data set includes adversarial patch samples based on different generation types; A final training module, used for training the initial training adversarial patch defense model according to a preset augmented data set to obtain a final training adversarial patch defense model; wherein the augmented data set is obtained by simulating different scenarios based on the training data set through data augmentation technology; The evaluation module is used to obtain the accuracy index value, generalization index value, robustness index value and defense efficiency index value of the final trained anti-patch defense model based on a preset test data set, and perform weighted superposition to obtain the evaluation value of the final trained anti-patch defense model.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the anti-patch defense model evaluation method as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the anti-patch defense model evaluation method as described in any one of claims 1 to 7 are implemented.