Black box evaluation method based on intermediate layer random mask in financial science and technology scene
By inserting a random mask layer into the intermediate layer of the ViT model, the migration adversarial samples are generated, and the limitations of the existing migration attack methods in the financial technology scenario are solved, achieving more efficient migration attack effects and better practicality.
Patent Information
- Application Number
- CN202510178898.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-06-27
AI Technical Summary
The existing migration attack methods are difficult to effectively evaluate the robustness of the model to be detected in financial technology scenarios, and the method is single, which ignores the important role of the model middle layer, and there are limitations of white box attacks and query attacks, which are difficult to successfully use in practical applications.
A black box evaluation method based on the intermediate layer random mask of ViT model is adopted. By inserting a random mask layer into the intermediate layer of the ViT model, migration adversarial samples are generated to achieve better migration attack effect.
It improves the practicality and success rate of migration attacks, can generate migratory adversarial samples in a completely black box scenario, has good cross-model effect, is easy to combine with existing methods, and enhances the enlightenment of model adversarial defense methods.
Smart Images

Figure CN120218174A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of model evaluation methods, and particularly relates to a black-box evaluation method based on intermediate-layer random masking in the fintech scenario. Background Art
[0002] With the development of the fintech field, deep learning models have been widely applied in multiple fields such as identity recognition, liveness detection, and image classification, and have promoted the research and development of new deep learning models. Financial institutions need to classify and analyze a large amount of image data, such as identifying the text or images on credit cards and detecting fraud. By training large-scale image datasets, deep learning models can learn high-level features and patterns, thereby achieving accurate image classification and recognition. The application of this technology can help financial institutions improve their risk assessment and fraud detection capabilities and reduce the occurrence of financial fraud.
[0003] However, deep learning models are vulnerable to adversarial samples. Adversarial attacks refer to the situation where an attacker adds subtle perturbations to clean samples to obtain adversarial samples. Adversarial perturbations (adversarial noise) are almost imperceptible to the human eye but can successfully mislead the target model. Adversarial attacks are divided into white-box attacks and black-box attacks, and black-box attacks are divided into query attacks and transfer attacks. In the white-box attack scenario, the attacker knows the structure and parameters of the target model and can directly use the target model to generate adversarial samples in a targeted manner. In the query attack scenario, although the attacker does not know the structure and parameters of the target model, the attacker can construct special inputs to query the target model and generate adversarial samples based on the output results. In the transfer attack scenario, the attacker uses a locally known model as a surrogate model, uses the surrogate model to generate adversarial samples, and directly attacks the target model with these adversarial samples, and this process is called a transfer attack. A transfer attack scenario is shown in the appendix Figure 6 as follows.
[0004] In the fintech scenario, it is difficult for an attacker to directly obtain the structure and parameters of the target model, and the number of its queries will also be correspondingly restricted by the number of accesses. Therefore, the most practical scenario is a transfer attack. Similarly, in the fintech evaluation scenario, the party to be detected will also tend to hide model details due to considerations of trade secrets. In summary, it is realistic and feasible to study the method of evaluating the robustness of the model to be detected through transfer attacks. The existing transfer attack methods are as follows:
[0005] The Momentum Iterative Method (MIM) is a technique widely used in transfer attacks, which enhances the generation of adversarial noise through momentum optimization. The Skip Gradient Method (SGM) attenuates gradient information through residual connection attenuation. The Nesterov Iterative Fast Gradient Sign Method (NI-FGSM) makes full use of second-order derivatives. The Variance Tuning Method (VMI) stabilizes the update direction based on gradient differences. The Patchout method uses a mask layer at the granularity of image patches when the image is input into the transformer, increasing the diversity of input samples. The Dropout Face Attacking Network (DFANet) introduces a large number of dropout layers in the convolutional neural network layer, thus improving the generalization ability of the surrogate model. The Token Gradient Regularization (TGR) method discards the extreme gradient values in the surrogate model.
[0006] The above exemplarily shows a variety of existing adversarial attack methods, and these existing adversarial attack methods have the following disadvantages in many aspects:
[0007] First, the disadvantages of white-box attack methods and query attack methods: they are difficult in practical applications. First of all, white-box methods require the attacker to have all the knowledge of the target model, including information such as structure, parameters, and training data. Obtaining this information is difficult and time-consuming for the attacker, especially for complex or commercial models. In addition, model designers usually take defensive measures to protect the security of the model, such as compression and encryption, further increasing the difficulty of the attack. Secondly, query attack methods require the attacker to frequently access the target model and obtain the output results, which may trigger abnormal behavior detection or resource consumption limitations, making it impossible for the attacker to conduct large-scale attacks. In addition, obtaining the model output results may require special permissions or cooperation with the model owner, increasing the difficulty of the attack. Finally, for practical reasons, these attack methods are difficult to be successfully used in practical applications. Model designers adopt various defense mechanisms to protect the security of the model, making it difficult for attackers to conduct meaningful attacks on the target model.
[0008] Second, the studied network structures are single. Most past studies are based on convolutional neural networks (CNNs), such as MIM, SGM, NI-FGSM, VMI, DFANet, etc. Only a few studies focus on the Vision transformer (ViT) model that has emerged in recent years, such as Patchout.
[0009] Thirdly, the important role of the middle layer of the model is ignored. Although Patchout studied the ViT model, it only processed the image before it was input into the ViT model and did not utilize the structure of the middle layer of the model.
[0010] In summary, studying transfer attack methods helps to simulate the adversarial threats faced by models in actual application scenarios and provides support for the robustness evaluation of models to be detected. In addition, such research can also provide inspiration and reference for model adversarial defense methods. And, as mentioned above, there are still many deficiencies in the transfer attack methods in the prior art. Therefore, it is necessary to design a new and more optimized transfer attack method. Summary of the Invention
[0011] The present invention is made to solve the above problems, and aims to provide a black-box model evaluation method that utilizes the middle layer of the ViT model and has a better transfer attack effect. The present invention adopts the following technical solutions:
[0012] The present invention provides a black-box evaluation method based on random masking of the middle layer in the fintech scenario, which has the following technical features. The method includes the following steps: Step S1, insert a random masking layer in the middle layer stacked by the ViT model as the proxy model, so as to obtain an improved proxy model; Step S2, use the improved proxy model to generate transfer adversarial samples. Wherein, each of the middle layers includes an attention layer, a first random masking layer, a projection layer, a second random masking layer, a multi-layer perceptron layer, and a third random masking layer. The output of the attention layer is used as the input of the projection layer after passing through the first random masking layer, the output of the projection layer is used as the input of the multi-layer perceptron layer after passing through the second random masking layer, and the output of the multi-layer perceptron layer is used as the output of this middle layer after passing through the third random masking layer.
[0013] The black-box evaluation method based on random masking of the middle layer in the fintech scenario provided by the present invention may also have the following technical features. Wherein, in Step S2, the random masking layer is enabled during the forward inference process of the improved proxy model.
[0014] The black-box evaluation method based on random masking of the middle layer in the fintech scenario provided by the present invention may also have the following technical features. Wherein, the working process of the i-th middle layer includes the following steps: the input X of the i-th middle layer i is linearly transformed to obtain three vectors Q, K, and V:
[0015]
[0016] The vectors Q and K pass through the attention layer and then pass through the first random masking layer to obtain a first vector I1:
[0017] I1 = Mask(Attn(Q, K), p Attn )
[0018] The first vector I1 and the vector V pass through the projection layer and then pass through the second random masking layer to obtain a second vector I2:
[0019] I2 = Mask(Proj(I1, V), p Proj )
[0020] The second vector I2 passes through the multi-layer perceptron layer and then passes through the third random masking layer to obtain the output Y of the intermediate layer of the i-th layer i :
[0021] Y i = Mask(MLP(I2), p MLP )
[0022] In the formula, Mask is the random masking layer, and p Attn is the masking pattern of the first random masking layer, and p Proj is the masking pattern of the second random masking layer, and p MLP is the masking pattern of the third random masking layer.
[0023] The black-box evaluation method based on random masking of the intermediate layer in the fintech scenario provided by the present invention may further have the following technical feature, wherein p Attn , p Proj , p MLP respectively take the same value in each of the intermediate layers, and the Bayesian optimization method is used to search for the values of p Attn , p Proj , p MLP .
[0024] The black-box evaluation method based on random masking of the intermediate layer in the fintech scenario provided by the present invention may further have the following technical feature, wherein step S2 includes the following sub-steps: step S2-1, generating adversarial samples using the improved surrogate model; step S2-2, calculating the loss based on the clean samples, the adversarial samples, and the loss function; step S2-3, obtaining the gradient of the loss function through the backpropagation algorithm according to the calculated loss; step S2-4, updating the gradient of the model through the obtained gradient of the loss function and the gradient-based attack method; step S2-5, updating the adversarial noise based on the updated gradient of the model; step S2-6, determining whether the predetermined iteration stop condition is reached. When the determination is yes, adding the updated adversarial noise to the clean samples to obtain the transfer adversarial samples, and when the determination is no, returning to step S2-1 for the next round of iteration.
[0025] The black-box evaluation method based on intermediate layer random masking in the fintech scenario provided by the present invention may further have the following technical feature: in step S2-2, the loss function is:
[0026]
[0027] In step S2-4, the gradient of the updated model is:
[0028]
[0029] In step S2-5, the updated adversarial noise is:
[0030]
[0031] In the formula, x is the input sample, D Input is the input dimension, D Output is the output dimension, is the improved surrogate model, ɑ and β are predetermined parameters, τ is the noise budget for each step, Δx i is the adversarial noise, G i is the gradient of the model, and i is the iteration step.
[0032] The black-box evaluation method based on intermediate layer random masking in the fintech scenario provided by the present invention may further have the following technical feature: in step S2-6, it is judged whether the predetermined number of iteration rounds N is reached. If i + 1 is equal to N, the updated adversarial noise Δx i+1 is added to the clean sample x to obtain the transfer adversarial sample x'; if i is less than N, then i = i + 1, and step S2-1 is returned.
[0033] Functions and effects of the invention
[0034] According to the black-box evaluation method based on intermediate layer random masking in the fintech scenario provided by the present invention, compared with the existing attack methods, it has the following advantages in many aspects:
[0035] First, it has better practicability. White-box attacks require the attacker to have all the knowledge of the target model, and query methods require the attacker to be able to access the target model a large number of times. In fact, the possibility of these two scenarios occurring is relatively small. The method of the present invention aims to provide a completely black-box evaluation framework based on transfer attack methods, which can generate transferable adversarial samples only relying on the local surrogate model, so that the evaluation of the model no longer depends on the attacker's detailed understanding of the target model or the ability to access the target model a large number of times, thereby improving the practicability and practical feasibility of the evaluation.
[0036] Second, it has good cross-model effects. Previous related research mainly generated transfer attack samples based on CNNs, and could not effectively attack ViT models and adversarially trained CNN models. That is, there are difficulties in performing transfer attacks across different types of models, and there is a lack of security assessment methods for new ViT models. The method of the present invention directly uses an improved ViT model to generate transfer attack samples, fully leveraging the structural particularity of the ViT model, and the generated adversarial samples have better transfer attack effects.
[0037] Third, it has good transfer attack effects. Compared with existing methods, the method of the present invention fully utilizes the intermediate layers stacked in the ViT model, modifies the intermediate layers, and inserts random mask layers at multiple positions in the intermediate layers, which is equivalent to randomizing the input samples. This can not only prevent the proxy model from overfitting but also play a role in data augmentation. Therefore, the improved proxy model can generate better transfer attack samples, thereby improving the success rate of transfer attacks.
[0038] Fourth, it is easy to combine with existing methods. Since the method of the present invention mainly modifies the intermediate layers of the ViT model and is completely compatible with some existing transfer attack methods, it can be easily combined with existing methods to improve the success rate of transfer attacks of existing methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is a flowchart of the black-box evaluation method based on random masking of intermediate layers in the fintech scenario in an embodiment of the present invention;
[0040] Figure 2 is a schematic structural diagram of an improved Transformer layer in an embodiment of the present invention;
[0041] Figure 3 is a flowchart of the operation of the improved Transformer layer in an embodiment of the present invention
[0042] Figure 4 is a flowchart of an attack using an improved proxy model in an embodiment of the present invention;
[0043] Figure 5 is a table chart of the attack success rate data of different methods in the comparative example of the present invention;
[0044] Figure 6 is a schematic diagram of a transfer attack method in the prior art;
[0045] Figure 7 is a schematic structural diagram of the intermediate layer of a ViT model in the prior art. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] In order to make the technical means, creative features, achieved objectives and effects realized by the present invention easy to understand, the following specifically describes the black-box evaluation method based on intermediate-layer random masking in the fintech scenario of the present invention in combination with embodiments and accompanying drawings.
[0047] <Embodiment>
[0048] Figure 1 It is a flowchart of the black-box evaluation method based on intermediate-layer random masking in the fintech scenario in this embodiment.
[0049] As Figure 1 shown, the method of this embodiment includes the following steps:
[0050] Step S1, insert a random masking layer in the intermediate layer of the stacked ViT model serving as the surrogate model, thereby obtaining an improved surrogate model.
[0051] Step S2, use the improved surrogate model to generate transfer adversarial samples.
[0052] The above steps will be described in detail below.
[0053] Step S1, insert a random masking layer in the intermediate layer of the stacked ViT model serving as the surrogate model, thereby obtaining an improved surrogate model.
[0054] To facilitate understanding of the new surrogate model constructed in this embodiment, the structure of the intermediate layer of the ViT model stack in the prior art will be briefly described below.
[0055] Figure 7 It is a schematic diagram of the structure of the intermediate layer of the ViT model in the prior art.
[0056] As Figure 7 shown, the intermediate layer 9 (Transformer layer) of a common ViT model in the prior art includes a linear transformation layer (not shown in the figure), an attention layer 91, a projection layer 92, and a multi-layer perceptron layer 93.
[0057] Taking the base model Vit_base_patch16_224 of Vision Transformer as an example, the working process of the Transformer layer of the i-th layer (i ∈ {1, 2, 3,..., 11, 12}) can be represented by the following steps (assuming the input of the i-th layer Transformer layer is X i ):
[0058] Step P1, the input X i of the i-th layer Transformer layer undergoes linear transformation to obtain three vectors Q, K, V:
[0059]
[0060] Step P2, the vectors Q and K pass through the attention layer 91 to obtain the first vector I1:
[0061] I1 = Attn(Q, K)
[0062] where Attn is the attention layer of the Transformer layer.
[0063] Step P3, the first vector I1 and the vector V pass through the projection layer 92 to obtain the second vector I2:
[0064] I2 = Proj(I1, V)
[0065] where Proj is the projection layer of the Transformer layer.
[0066] Step P4, the second vector I2 passes through the multi-layer perceptron layer 93 to obtain the output Y of the i-th layer Transformer layer i :
[0067] Y i = MLP(I2)
[0068] where MLP is a multi-layer perceptron layer of the Transformer layer.
[0069] Figure 2 is the structural schematic diagram of the improved Transformer layer in this embodiment.
[0070] As Figure 2 shown, the middle layer 10 (Transformer layer) of the ViT model in this embodiment includes an attention layer 11, a projection layer 12, a multi-layer perceptron layer 13, a first random masking layer 14, a second random masking layer 15, and a third random masking layer 16. That is, compared with the Transformer layer of the existing ViT model, there are three more random masking layers. Among them, the first random masking layer 14 is arranged between the attention layer 11 and the projection layer 12, and the output of the attention layer 11 is masked by the first random masking layer 14 and then used as the input of the projection layer 12. The second random masking layer 15 is arranged between the projection layer 12 and the multi-layer perceptron layer 13, and the output of the projection layer 12 is masked by the second random masking layer 15 and then used as the input of the multi-layer perceptron layer 13. The third random masking layer 16 is arranged after the multi-layer perceptron layer 13, and the output of the multi-layer perceptron layer 13 is masked by the third random masking layer 16 and then used as the output of this layer Transformer layer.
[0071] The random masking layer is also called the Dropout layer, and its function is to randomly discard / set to zero a part of the values in the vector. For example, for such an input: After being processed by the random masking layer Mask(X, 0.5), half of the terms are randomly selected from the input and these terms are discarded / set to zero (discarding and setting to zero are synonymous). A total of 4 (9 * 0.5 ≈ 4) terms are set to zero. A possible result is:
[0072] Figure 3 It is the workflow diagram of the improved Transformer layer in this embodiment.
[0073] As described above, in this embodiment, random masking layers are inserted at multiple positions in each Transformer layer of the ViT model, as Figure 3 shown. The workflow of the improved i-th Transformer layer is represented by the following steps:
[0074] Step S1-1, the input X of the i-th Transformer layer i is linearly transformed to obtain three vectors Q, K, V:
[0075]
[0076] Step S1-2, the vectors Q, K pass through the attention layer 11 and then through the first random masking layer 14 to obtain the first vector I1:
[0077] I1 = Mask(Attn(Q, K), p Attn )
[0078] where Mask is the random masking layer and p Attn is the masking pattern of the first random masking layer 14.
[0079] Step S1-3, the first vector I1 and the vector V pass through the projection layer 12 and then through the second random masking layer 15 to obtain the second vector I2:
[0080] I2 = Mask(Proj(I1, V), p Proj )
[0081] where p Proj is the masking pattern of the second random masking layer 15.
[0082] Step S1-4, the second vector I2 passes through the multi-layer perceptron layer 13 and then through the third random masking layer 15 to obtain the output Y of the i-th Transformer layer i :
[0083] Y i = Mask(MLP(I2), p MLP )
[0084] where pMLP is the masking pattern of the third random masking layer 15.
[0085] where p Attn ,p Proj ,p MLP takes a unified value in each Transformer layer respectively, and the numerical values of the three can be adjusted flexibly. They can be set according to experience or searched using hyperparameter search methods (such as Bayesian optimization method).
[0086] Although multiple random masking layers are introduced in the forward propagation process, simply enabling random masking directly cannot improve the transfer attack effect. Instead, an appropriate dropout rate needs to be set to adapt to the surrogate model. In this embodiment, the Bayesian optimization method is used to search for appropriate random masking settings (Dropout settings), and two techniques for searching the dropout rate are adopted: (1) modifying the number of iterations and the budget for each iteration; (2) using a small-scale dataset sampled randomly. Specifically, by reducing the number of iterations of the black-box transfer attack and increasing the noise perturbation budget for each iteration step while keeping the overall budget unchanged, the efficiency of the search process is ensured. In addition, using a small-scale dataset sampled from the entire dataset helps prevent overfitting of the hyperparameters to the target dataset and reduces the running time required for each search experiment.
[0087] It should be noted that currently in the training of neural networks, during the forward inference process, random masking (Dropout layer) is usually disabled. However, in this embodiment, random masking is enabled during the forward inference process. In principle, Dropout layers are introduced between different modules of the Transformer block. The added Dropout layers are equivalent to randomizing the input samples, which can not only prevent the surrogate model from overfitting but also play a role in data augmentation. Taking the ViT base model (ViT-B / 16) as an example, its Transformer block contains 12 Transformer layers and 36 Dropout modules. Through this stacked network, sufficient randomness is introduced into the Transformer block and the subsequent MLP modules, thus endowing the surrogate model with the effect of ensemble learning.
[0088] Step S2, generating transfer adversarial samples using the improved surrogate model.
[0089] Figure 4 is the flow chart of the attack using the improved surrogate model in this embodiment.
[0090] Let the input sample be x, and the input dimension be D Input ,and the surrogate model be S, and the output dimension D Output, if the total number of algorithm loops is N and the noise budget is ε, then the noise budget for each step is τ = ε / N, and the parameters ɑ, β, and the initial noise Gradient The current iteration step i = 0. After the above transformation of the surrogate model, the surrogate model changes from S to As Figure 4 shown, the process of using the improved surrogate model for attack is as follows:
[0091] Step S2-1, generate adversarial examples using the improved surrogate model.
[0092] Step S2-2, calculate the loss based on the clean example, adversarial example, and loss function:
[0093]
[0094] In the formula, the former term is the cross-entropy of the outputs obtained by inputting the clean example and the adversarial example into the surrogate model, and the latter term is the magnitude of the adversarial noise.
[0095] Step S2-3, according to the calculated loss, use the backpropagation algorithm to find the gradient of the loss function
[0096] Step S2-4, update the gradient of the model through the obtained gradient of the loss function and the gradient-based attack method (Momentum Iterative Method, MIM):
[0097]
[0098] Step S2-5, update the adversarial noise based on the updated gradient:
[0099]
[0100] In the formula, is a normalization operation that preserves the direction of the vector and sets the norm to 1.
[0101] Step S2-6, determine whether the predetermined number of iteration rounds is reached. If i + 1 is equal to N, then add the updated adversarial noise Δx i+1 to the clean example x to obtain the final adversarial example x'; if i is less than N, then i = i + 1, and return to Step S2-1, that is, perform the next round of iteration.
[0102] In the above step S2-2, cross entropy loss and L2 norm are used to evaluate the interference degree of adversarial samples on the model output and the size of adversarial noise. Cross entropy loss is used to measure the impact of adversarial samples on the model, while L2 norm is used to measure the size of adversarial noise. In the above steps S2-3 to S2-5, the concept of MIM is applied to accelerate the generation process of adversarial samples through the momentum method, which helps to make adversarial samples jump out of the local optimal solution and find better adversarial samples.
[0103] Functions and Effects of the Embodiments
[0104] The black box evaluation method based on intermediate layer random mask in the financial technology scenario provided by this embodiment has the following advantages compared with the attack methods in the prior art:
[0105] First, it is more practical. White-box attacks require the attacker to have full knowledge of the target model, and query methods require the attacker to have a large amount of access to the target model, but in fact these two scenarios are less likely to occur. The method of this embodiment aims to provide a completely black-box evaluation framework based on the migration attack method, which can generate transferable adversarial samples relying only on the local proxy model, so that the evaluation of the model no longer depends on the attacker's detailed understanding of the target model or the ability to access the target model in large quantities, thereby improving the practicality and feasibility of the evaluation.
[0106] Second, the cross-model effect is good. Previous related studies mainly generated migration attack samples based on CNN, which could not attack the ViT model and the CNN model trained through adversarial training well. The method of this embodiment directly uses the improved ViT model to generate migration attack samples, making full use of the structural particularity of the ViT model, and the generated adversarial sample migration attack effect is better.
[0107] Third, the migration attack has a good effect. Compared with the existing method, the method of this embodiment makes full use of the middle layer of the ViT model stack, transforms the middle layer, and inserts a random mask layer at multiple positions in the middle layer, which is equivalent to randomizing the input samples, which can prevent the proxy model from overfitting and also play a role in data amplification. Therefore, the improved proxy model can generate better migration attack samples, thereby improving the success rate of migration attacks.
[0108] Fourth, it is easy to combine with existing methods. Since the method of this embodiment mainly transforms the middle layer of the ViT model, and is completely consistent with some existing migration attack methods, it can be easily combined with existing methods to improve the success rate of migration attacks of existing methods.
[0109] In addition, the method of this embodiment can also provide inspiration and reference for model adversarial defense methods.
[0110] <Proportional Example>
[0111] This proportional example provides three model attack methods in the prior art, and combines the method of the embodiment on the basis of these existing model attack methods for comparison, so as to verify the effect of the method of the embodiment.
[0112] In this proportional example, the three existing model attack methods are MIM, PNA, and TGR respectively. For the convenience of narration, the corresponding improved methods obtained by combining these three model attack methods with the method of the embodiment are denoted as MIM-M, PNA-M, and TGR-M respectively. That is, the model intermediate layer random masking method described in the embodiment is combined in the corresponding improved methods.
[0113] For each existing method and each improved method, four different surrogate models are used to attack three different target models. Table 1 below shows the average value of the attack success rate (%) when using different surrogate models to attack different target models with three existing methods and three improved methods respectively.
[0114] Table 1 Success rate data table of different methods attacking different target models
[0115]
[0116] Among them, the surrogate models (4 kinds) include: vit_base_patch16_224 (ViT-B / 16), pit_b_224 (PiT-B), cait_s24_224 (CaiT-S / 24), visformer_small.
[0117] ViTs (8 kinds) include: vit_base_patch16_224 (ViT-B / 16), pit_b_224 (PiT-B), cait_s24_224 (CaiT-S / 24), visformer_small (Visformer-S), deit_base_distilled_patch16_224 (DeiT-B), tnt_s_patch16_224 (TNT-S), levit_256 (LeViT-256), convit_base (ConViT-B).
[0118] The four CNNs include: tf2torch_inception_v3 (Inc-v3), tf2torch_inception_v4 (Inc-v4), tf2torch_inc_res_v2 (IncRes-v2), and tf2torch_resnet_v2_101 (Res-v2).
[0119] The three CNN-adv include: tf2torch_ens3_adv_inc_v3 (Inc-v3 ens3 ), tf2torch_ens4_adv_inc_v3 (Inc-v3 ens4 ), and tf2torch_ens_adv_inc_res_v2 (IncRes-v2 adv ).
[0120] For example, the first value 58.37 in Table 1 represents the average success rate of 32 attacks when the MIM method is applied to four surrogate models to generate 4 different adversarial samples and these adversarial samples are used to attack 8 different ViT models respectively.
[0121] Figure 5 It is the table graph of the attack success rate data of different methods in this comparative example, that is, the visualization result of the data in Table 1.
[0122] As shown in Table 1 and Figure 5 it can be clearly seen that the attack success rates of the improved methods combining the random masking method of the embodiments are all higher than the corresponding existing methods.
[0123] The above embodiments are only used to illustrate the specific implementation manners of the present invention, and the present invention is not limited to the description scope of the above embodiments. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification only illustrates the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A black box evaluation method based on intermediate layer random mask in financial technology scenario, characterized in that: The following steps are involved: Step S1, inserting a random mask layer into the middle layer of the ViT model stack as the proxy model, thereby obtaining an improved proxy model; Step S2, generating a migration adversarial sample using the improved proxy model, Each of the intermediate layers includes an attention layer, a first random mask layer, a projection layer, a second random mask layer, a multi-layer perceptron layer, and a third random mask layer. The output of the attention layer passes through the first random mask layer as the input of the projection layer. The output of the projection layer passes through the second random mask layer as the input of the multi-layer perceptron layer. The output of the multi-layer perceptron layer is used as the output of the intermediate layer after passing through the third random mask layer.
2. The black box evaluation method based on intermediate layer random mask in the financial technology scenario according to claim 1 is characterized by: in, In step S2, the random mask layer is enabled during the forward reasoning process of the improved proxy model.
3. The black box evaluation method based on intermediate layer random mask in the financial technology scenario according to claim 1 is characterized by: in, The workflow of the middle layer described in layer i includes the following steps: The input X of the intermediate layer of the i-th layer i After linear transformation, we get three vectors Q, K, V: The vectors Q, K pass through the attention layer and then pass through the first random mask layer to obtain the first vector I1: I1=Mask(Attn(Q,K),p Attn ) The first vector I1 and the vector V pass through the projection layer and then pass through the second random mask layer to obtain the second vector I2: I2=Mask(Proj(I1,V),p Proj ) The second vector I2 passes through the multi-layer perceptron layer, and then passes through the third random mask layer to obtain the output Y of the intermediate layer of the i-th layer. i : Y i =Mask(MLP(I2),p MLP ) Where Mask is a random mask layer, p Attn is the mask pattern of the first random masking layer, p Proj is the mask pattern of the second random mask layer, p MLP is the mask pattern of the third random mask layer.
4. The black box evaluation method based on intermediate layer random mask in the financial technology scenario according to claim 3 is characterized by: in, p Attn , p Proj , p MLP A uniform value is taken in each intermediate layer, and the Bayesian optimization method is used to search for p Attn , p Proj , p MLP The value of .
5. According to claim 1, the black box evaluation method based on intermediate layer random mask in the financial technology scenario, Features: Wherein, step S2 includes the following sub-steps: Step S2-1, generating adversarial samples using the improved proxy model; Step S2-2, calculating the loss based on the clean sample, the adversarial sample and the loss function; Step S2-3, according to the calculated loss, the gradient of the loss function is obtained by back propagation algorithm; Step S2-4, updating the gradient of the model by using the gradient of the loss function and the gradient-based attack method; Step S2-5, updating the anti-noise based on the updated gradient of the model; Step S2-6, determine whether the predetermined iteration stop condition is reached. If it is determined to be yes, add the updated adversarial noise to the clean sample to obtain the migration adversarial sample. If it is determined to be no, return to step S2-1 for the next round of iteration.
6. The black box evaluation method based on intermediate layer random mask in the financial technology scenario according to claim 5 is characterized by: in, In step S2-2, the loss function is: In step S2-4, the gradient of the updated model is: In step S2-5, the updated countermeasure noise is: In the formula, x is the input sample, D Input is the input dimension, D Output is the output dimension, is the improved proxy model, ɑ and β are the predetermined parameters, τ is the noise budget for each step, and Δx i To combat noise, G i is the gradient of the model and i is the iteration step.
7. The black box evaluation method based on intermediate layer random mask in the financial technology scenario according to claim 6, Features: in, In step S2-6, it is determined whether the predetermined iteration round N is reached. If i+1 is equal to N, the updated countermeasure noise Δx is i+1 Add the clean sample x to obtain the migration adversarial sample x'; If i is less than N, then i=i+1, and the process returns to step S2-1.