Adversarial sample generation method based on high-frequency remodeling
Through the adversarial sample generation method based on high-frequency remodeling, the problem of insufficient adversarial sample generation efficiency and quality in the prior art is solved, and high-quality adversarial samples are generated under zero query conditions, and the attack success rate and model adaptability are improved.
Patent Information
- Application Number
- CN202510276062.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-27
AI Technical Summary
The existing adversarial sample generation methods have shortcomings in the initial sample quality and optimization efficiency, especially in black box attacks, which require a large number of queries to generate effective adversarial samples, and are not adaptable to the new model architecture.
Using an adversarial sample generation method based on high-frequency remodeling, the clean sample and reference sample are decomposed into high-frequency and low-frequency components through discrete cosine transformation, the high-frequency residual image is processed and superimposed on the low-frequency clean sample to generate adversarial samples.
Generate high-quality initial samples under zero query conditions, significantly improve attack success rate, reduce sample perturbation, and be compatible with various model architectures such as convolutional neural networks and transformers.
Smart Images

Figure CN120219876A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of adversarial example generation. More specifically, it relates to an adversarial example generation method based on high-frequency reshaping. Background Art
[0002] In recent years, the rapid development of deep neural networks (DNNs) has achieved remarkable results in fields such as image classification, speech recognition, and natural language processing. However, research has shown that even well-trained DNN models are still vulnerable to adversarial examples. These adversarial examples can significantly change the prediction results of the model through perturbations that are imperceptible to human vision, thus threatening the security and reliability of deep learning systems.
[0003] Adversarial attack techniques can be classified into white-box attacks and black-box attacks according to the degree of information the attacker has about the model. White-box attacks assume that the attacker can fully know the structure and parameters of the target model, such as gradient calculation methods like FGSM and PGD. This type of attack can generate efficient adversarial examples in a very short time. In contrast, black-box attacks can only access the output of the target model (such as classification labels or probability distributions), which is more in line with the security scenarios in real-world applications. However, a major challenge of black-box attacks is that a large number of queries are required to generate effective adversarial examples, and the frequency and cost of queries become important factors restricting the efficiency of black-box attacks.
[0004] In black-box attacks, decision-based attack methods have received particular attention. These methods only use the prediction labels of the model as feedback information and do not rely on gradient information or confidence distributions, thus having higher practicality. For example, methods such as Boundary Attack and SurFree explore the decision boundary through geometric optimization, significantly reducing the number of queries. However, these methods have limitations in optimizing the quality of the initial samples and reducing perturbations, and also have insufficient adaptability to new architectures such as transformer models.
[0005] The research on frequency-domain signals provides a new perspective for adversarial attacks. The frequency-domain characteristics of images show that high-frequency components have a more significant impact on the decision-making of neural networks, and appropriately adjusting high-frequency components can generate adversarial examples more efficiently. For example, research has shown that in the high-frequency components, the decision boundary of the model is tighter, thus increasing the sensitivity of adversarial example generation. However, existing methods have not fully utilized the frequency-domain characteristics to optimize the adversarial example generation process, and there is still room for further improvement in both efficiency and effect.
[0006] In practical applications, in fields such as autonomous driving, medical diagnosis, and face recognition, adversarial examples may pose serious security risks. For example, attacking the object detection model in an autonomous driving system may lead to traffic accidents; attacking a medical diagnosis model may result in misdiagnosis; in a face recognition system, adversarial examples may bypass security verification. With the wide application of deep learning technology, how to design more efficient adversarial attack methods and at the same time evaluate and improve the robustness of models has become an important research direction in academia and industry.
[0007] Although existing research has made some progress in reducing the number of queries and improving the attack efficiency, there are still challenges in the following aspects:
[0008] 1. Efficiency and quality in the initialization stage: Most methods rely on random initialization or high-noise perturbations, which lead to low-quality initial samples and thus increase the optimization difficulty.
[0009] 2. Efficiency in the optimization stage: Many optimization methods require a large number of queries to converge, which is difficult to apply in scenarios with high query costs.
[0010] 3. Model generality: Existing methods have significant effects on convolutional neural networks (CNNs), but their applicability to new architectures such as transformers is insufficient. Summary of the Invention
[0011] The purpose of the present invention is to overcome the deficiencies of the prior art and provide an adversarial example generation method based on high-frequency remodeling, which makes full use of the frequency-domain characteristics of images and generates adversarial examples through high-frequency remodeling (HFR) to improve the quality and attack success rate of adversarial examples.
[0012] To achieve the above invention purpose, the adversarial example generation method based on high-frequency remodeling of the present invention includes the following steps:
[0013] S1: Decompose the clean sample X c and the reference sample X ref into high-frequency components and low-frequency components respectively through discrete cosine transform;
[0014] S2: Respectively obtain the low-frequency clean sample L c and the low-frequency reference sample L ref by performing inverse discrete cosine transform on the two low-frequency components of the clean sample X c and the reference sample X ref ;
[0015] S3: Use the following formula to process respectively to obtain the high-frequency residual image η c of the clean sample and the high-frequency residual image η ref of the reference sample:
[0016] η c = X c - L c
[0017] η ref = X ref - L ref
[0018] Orthogonalize the two high - frequency residual images η c and η ref to obtain the high - frequency residual image η;
[0019] S4: Superimpose the low - frequency clean sample L c of the clean sample X c and the high - frequency residual image η to obtain the adversarial sample X adv :
[0020] X adv = L c + η.
[0021] Based on the high - frequency reshaping - based adversarial sample generation method of the present invention, the clean sample and the reference sample are respectively decomposed into high - frequency components and low - frequency components through discrete cosine transform. The two low - frequency components are respectively obtained as the low - frequency clean sample and the low - frequency reference sample through inverse discrete cosine transform. Then, the high - frequency residual images of the clean sample and the reference sample are obtained. After orthogonalizing the two high - frequency residual images, they are superimposed on the low - frequency clean sample to generate the adversarial sample.
[0022] The present invention has the following beneficial effects:
[0023] 1) The present invention can directly use the high - frequency reshaping technology to generate high - quality initial samples and can generate adversarial samples under zero - query conditions.
[0024] 2) The present invention can also quickly optimize the adversarial samples through the axial search algorithm, significantly improve the attack success rate under the condition of low query times, and at the same time reduce the sample perturbation.
[0025] 3) The framework of the present invention can be compatible with various model architectures such as convolutional neural networks and transformers, and has wide applicability. Brief Description of the Drawings
[0026] Figure 1 is a flowchart of the specific implementation of the high - frequency reshaping - based adversarial sample generation method of the present invention;
[0027] Figure 2 is an example diagram of the generation of adversarial samples in this embodiment;
[0028] Figure 3It is the adversarial sample iterative optimization method based on the axial search optimization algorithm in this embodiment;
[0029] Figure 4 It is an example diagram of the principle of axial search;
[0030] Figure 5 It is the flowchart of axial search in this embodiment;
[0031] Figure 6 It is the flowchart of binary search in this embodiment;
[0032] Figure 7 It is the comparison chart of the attack performance curves of the present invention and the comparative method on the ResNet-18 model in this embodiment. Detailed implementation manners
[0033] The following describes the detailed implementation manners of the present invention with reference to the accompanying drawings, so that those skilled in the art can better understand the present invention. It should be particularly noted that in the following description, when the detailed descriptions of known functions and designs may dilute the main content of the present invention, these descriptions will be omitted here.
[0034] Embodiment
[0035] Figure 1 It is the flowchart of the detailed implementation manner of the adversarial sample generation method based on high-frequency reshaping of the present invention.
[0036] As Figure 1 shown, the adversarial sample generation method based on high-frequency reshaping of the present invention includes the following steps:
[0037] S101: Frequency domain decomposition:
[0038] Decompose the clean sample X c and the reference sample X ref into high-frequency components and low-frequency components respectively through the Discrete Cosine Transform (DCT). The Discrete Cosine Transform is a commonly used image transformation method, and its specific process will not be elaborated here. Among the two decomposed components, the high-frequency components are used to capture the detailed features of the image, while the low-frequency components contain the overall contour information of the image. In practical applications, in order to enhance the misleading property, the low-frequency components of the clean sample X c and the reference sample X ref can be respectively filtered to smooth the low-frequency information. In this embodiment, the low-frequency component filtering is performed using a bilateral filter.
[0039] S102: Low-frequency restoration:
[0040] Restore the clean sample X cand reference sample X ref The two low-frequency components of ref are respectively obtained through inverse discrete cosine transform (IDCT) to get the low-frequency clean sample L c and the low-frequency reference sample L ref .
[0041] S103: High-frequency reshaping:
[0042] The following formula is used to process respectively to obtain the high-frequency residual image η of the clean sample c and the high-frequency residual image η of the reference sample ref :
[0043] η c = X c - L c
[0044] η ref = X ref - L ref
[0045] The two high-frequency residual images η c and η ref are orthonormalized to obtain the high-frequency residual image η.
[0046] S104: Generate adversarial samples:
[0047] The low-frequency clean sample L of the clean sample X c and the high-frequency residual image η are superimposed to obtain the adversarial sample X c : adv :
[0048] X adv = L c + η.
[0049] According to the above process, it can be seen that the present invention processes the high-frequency residual image, and can generate adversarial samples through high-frequency reshaping under the condition of zero query times. Figure 2 is the generation example diagram of the adversarial sample in this embodiment. As Figure 2 shown, the high-frequency component and the low-frequency component are obtained through discrete cosine transform decomposition, and then high-frequency reshaping is performed to quickly generate adversarial samples.
[0050] In order to further improve the misleading of the adversarial sample X adv , in this embodiment, the adversarial sample X adv is further iteratively optimized based on the axial search optimization algorithm to enhance the attack effect while reducing the perturbation. Figure 3 is the adversarial sample iterative optimization method based on the axial search optimization algorithm in this embodiment. As Figure 3As shown in the figure, the adversarial sample iterative optimization method based on the axial search optimization algorithm in this embodiment includes the following steps:
[0051] S301: Initialize the search parameters:
[0052] Initialize the adversarial sample Perturbation δ1 = X adv -X c .
[0053] S302: Let the iteration number q = 1.
[0054] S303: Select a hyperplane:
[0055] Select a hyperplane P in the frequency domain q .
[0056] In this embodiment, in order to improve the optimization efficiency, the hyperplane P q is determined by the following method:
[0057] Perform discrete cosine transform on the perturbation δ q to obtain the frequency domain image F q , perform random sampling on the frequency domain image F q to obtain the frequency domain sampling image The sampling formula is:
[0058]
[0059] where S represents a randomly generated binary matrix.
[0060] Then perform inverse discrete cosine transform on the frequency domain sampling image to obtain the sampling perturbation Take the plane formed by the perturbation δ q and the sampling perturbation as the hyperplane P q .
[0061] S304: Generate an orthogonal vector:
[0062] Calculate the orthogonal vector f q orthogonal to the perturbation δ q in the hyperplane P q . The orthogonal vector is the component of the perturbation in the normal direction of the decision boundary, representing the perturbation perpendicular to the decision boundary. The magnitude of the orthogonal vector determines the amplitude of the adversarial perturbation. Therefore, the core objective of optimization is to reduce the magnitude of the orthogonal vector while ensuring that the sample remains adversarial.
[0063] S305: Axial search to obtain the optimized perturbation:
[0064] Based on the orthogonal vector f q in the hyperplane Pq An optimized perturbation δ is obtained from the internal search q+1 .
[0065] Figure 4 It is an example diagram of the principle of axial search. As Figure 4 shown, axial search (Axis Search) starts from the initial perturbation of the adversarial sample for search. To clarify the relationship between the perturbation vector and the decision boundary, the optimization algorithm first divides the perturbation into an equal component and an orthogonal component, and makes refined adjustments in the orthogonal direction through the axis search strategy to gradually reduce the amplitude of the orthogonal component, thereby realizing the optimization of the perturbation. Figure 5 It is the flowchart of axial search in this embodiment. As Figure 5 shown, the specific steps of axial search in this embodiment include:
[0066] S501: Calculate the optimization direction:
[0067] The optimization direction d and the optimization direction v are calculated using the following formula:
[0068]
[0069] v = δ q ·cosθ
[0070] where θ represents the search angle, which is the angle between the perturbation direction and the decision boundary, and || || P represents taking the P-norm, and ||δ q || P ·sinθ is used to control the adjustment scale of the perturbation amplitude.
[0071] S502: Forward search:
[0072] The N - times binary search is performed within the search range [0, d]. Figure 6 It is the flowchart of binary search in this embodiment. As Figure 6 shown, the specific steps of binary search in this embodiment include:
[0073] S601: Initialize the search range:
[0074] Denote the search range as [A, B].
[0075] S602: Let the query times n = 1.
[0076] S603: Let the optimization direction
[0077] S604: Generate an adversarial sample:
[0078] Let the perturbation Generate an adversarial sample
[0079] S605: Input the adversarial example into the target model to be attacked, and determine whether the attack is successful. If so, go to step S606; otherwise, go to step S607.
[0080] S606: Update the upper limit of the optimization range:
[0081] Let the upper limit of the optimization range Go to step S608.
[0082] S607: Update the lower limit of the optimization range:
[0083] Let the lower limit of the optimization range Go to step S608.
[0084] S608: Determine whether n < N, where N represents the preset maximum number of queries. If so, go to step S603; otherwise, the query ends.
[0085] S608: Let n = n + 1, and return to step S603.
[0086] S503: Determine whether there is an adversarial example that successfully attacks during the forward search process. If not, go to step S504; otherwise, go to step S505.
[0087] S504: Reverse search:
[0088] Use the binary search method N times within the search range [-d, 0], and go to step S505.
[0089] S505: Determine the optimization perturbation:
[0090] Select the last adversarial example that successfully attacks during this search, and use its perturbation as the optimization perturbation δ q+1 .
[0091] S306: Determine whether the iteration end condition is reached. If not, go to step S307; otherwise, go to step S308. The iteration end condition can be set according to actual needs. In this embodiment, the maximum number of iterations Q is used.
[0092] S307: Let the iteration number q = q + 1, and return to step S303;
[0093] S308: Generate the final adversarial example:
[0094] Generate the final adversarial example X adv = X c + δ q+1 .
[0095] In practical applications, to ensure the perceptual naturalness of adversarial examples, a P-norm constraint can also be introduced to limit the perturbation within a preset threshold range. The specific method is as follows: Determine whether the perturbation ||δ q+1 || P is greater than the preset threshold. If so, truncate the perturbation δ q+1 so that ||δ q+1 || P is less than or equal to the preset threshold; otherwise, do nothing.
[0096] To better illustrate the technical solution of the present invention, specific examples are used to conduct experimental verification on the present invention. In this embodiment, four existing decision-based black-box adversarial attack methods are selected for comparative experiments, including:
[0097] GeoDA, referring to the method in the literature "GeoDA: Geometric Decision-based Adversarial Attack[J]. 2020.";
[0098] SurFree, referring to the method in the literature "SurFree: Surrogate-Free Decision-based Adversarial Attacks[J]. 2021.";
[0099] TA, referring to the method in the literature "TA: Triangle Attack[J]. 2022.";
[0100] CGBA, referring to the literature "CGBA: Circular Geometric Boundary Attack[J]. 2023."
[0101] This embodiment comprehensively compares and analyzes the present invention and existing methods from indicators such as the attack success rate (ASR), perturbation size (Distortion), and query budget (QueryBudget).
[0102] First, this embodiment examines the attack success rate (ASR), median (Mid), and average value (Mean) of the present invention under different l ∞ and l2, perturbation limit (∈), and query budget (Q) conditions.
[0103] Table 1 is a statistical table of the attack performance of the present invention under different conditions in this embodiment.
[0104]
[0105] Table 1
[0106] As shown in Table 1, the present invention can generate adversarial samples under zero query conditions, and the ASR reaches 78.60% under high perturbation conditions (∈ = 30). Compared with other methods, the present invention achieves a higher ASR with a low query budget and significantly reduces the number of queries required during the optimization process.
[0107] Figure 7 It is a comparison chart of the attack performance curves of the present invention and the comparative method on the ResNet-18 model in this embodiment. Figure 7 The number of queries in it ranges from 0 to 50. From Figure 7 It can be seen that the method of the present invention shows a lower perturbation amount at the initial stage and converges rapidly within a short time. Compared with other methods, the present invention shows a higher attack efficiency at the initial stage of optimization and finally reaches the minimum perturbation amount.
[0108] Next, five models (ResNet-18, Inception-v3, DenseNet-121, ViT-B / 16, Swin-B) are used as the attack targets to compare and verify the attack success rates of the present invention and the comparative method. Table 2 is a comparison table of the attack success rates of the present invention and the comparative method on the five models in this embodiment.
[0109]
[0110] Table 2
[0111] As shown in Table 2, the present invention shows the best ASR under different l2 perturbation limits and query budgets. Especially when the query budget is low (Q = 10 or Q = 0), the success rate is significantly better than that of the existing methods, demonstrating the high efficiency and applicability of the present invention.
[0112] Although the above describes the illustrative specific embodiments of the present invention for the convenience of those skilled in the art to understand the present invention, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions and creations using the concept of the present invention are within the scope of protection.
Claims
1. A method for generating adversarial samples based on high-frequency reconstruction, characterized in that: The following steps are involved: S1: clean sample X c and reference sample X ref Decompose into high-frequency components and low-frequency components respectively through discrete cosine transform; S2: clean sample X c and reference sample X ref The two low-frequency components of are respectively transformed by inverse discrete cosine to obtain low-frequency clean samples L c and the low frequency reference sample L ref ; S3: The high-frequency residual image η of the clean sample is obtained by processing using the following formulas: c and the high-frequency residual image η of the reference sample ref : or c =X c -L c or ref =X ref -L ref The two high-frequency residual images η c and η ref Orthogonalize to obtain the high-frequency residual image η; S4: clean sample X c Low frequency clean sample L c Superimpose it with the high-frequency residual image η to obtain the adversarial sample X adv : X adv =L c +n.
2. The adversarial sample generation method according to claim 1, characterized in that: In step S1, the clean sample X c and reference sample X ref The low-frequency components are filtered.
3. The adversarial sample generation method according to claim 2, characterized in that: The filtering process is performed using a bilateral filter.
4. The adversarial sample generation method according to claim 1, characterized in that: The step S4 also includes: adv Further iterative optimization is performed, including the following steps: S4.1: Initialize adversarial examples Perturbation δ1 = X adv -X c γ1; S4.2: Let the number of iterations q = 1; S4.3: Select a hyperplane P in the frequency domain q ; S4.4: Calculate the hyperplane P q is orthogonal to the perturbation δ q The orthogonal vector f q ; S4.5: Based on the orthogonal vector f q In the hyperplane P q The inner search obtains the optimal perturbation δ q+1 , the specific method is: S4.5.1: Calculate the optimization direction d and the optimization direction v using the following formula: v=δ q ·cosθ Among them, θ represents the search angle, which is the angle between the perturbation direction and the decision boundary, || || P Indicates the P norm is obtained; S4.5.2: Perform N binary searches within the optimization range [0, d]. The specific method of the binary search is: S4.5.2.1: Let the search range be [A,B]; S4.5.2.2: Let the number of queries n = 1; S4.5.2.3: Optimization direction S4.5.2.4: Make disturbance Generating Adversarial Examples S4.5.2.5: Adversarial Examples Input the target model to be attacked and determine whether the attack is successful. If yes, proceed to step S4.5.2.6; otherwise, proceed to step S4.5.2.
7. S4.5.2.6: Set the upper limit of the optimization range S4.5.2.7: Set the lower limit of the optimization range S4.5.2.8: Determine whether n < N, where N represents the preset maximum number of queries. If so, proceed to step S4.5.2.3, otherwise the query ends; S4.5.2.9: Set n=n+1 and return to step S4.5.2.3; S4.5.3: Determine whether there is an adversarial sample that has successfully attacked during the forward search process. If not, proceed to step S4.5.4; otherwise, proceed to step S4.5.5; S4.5.4: Perform N binary searches in the search range [-d,0]; S4.5.5: Select the last successful adversarial example in this search and use its perturbation as the optimized perturbation δ q+1 ; S4.6: Determine whether the iteration end condition is met, if not, proceed to step S4.7, otherwise proceed to step S4.8; S4.7: Set the number of iterations q = q + 1, and return to step S4.3; S4.8: Generate the final adversarial example X adv =X c +δ q+1 .
5. The adversarial sample generation method according to claim 3, characterized in that: In step S4.3, the hyperplane P q The method of determining is as follows: For the disturbance δ q Perform discrete cosine transform to obtain the frequency domain image F q , for the frequency domain image F q Perform random sampling to obtain a frequency domain sampling image The sampling formula is: Where S represents a randomly generated binary matrix; Then sample the image in the frequency domain Perform inverse discrete cosine transform to obtain the sampled disturbance The disturbance δ q and sampling disturbance The plane formed is the hyperplane P q .
6. The adversarial sample generation method according to claim 3, characterized in that: In step S4.8, the adversarial sample will also be perturbed and controlled. The specific method is as follows: Determine the disturbance ||δ q+1 || P Is it greater than the preset threshold? If so, the disturbance δ q+1 Truncate so that ||δ q+1 || P Less than or equal to the preset threshold, otherwise no action is taken.