Method and device for defending bill against anti-counterfeiting attack of sample, and computer program product
The superimposed perturbation projection gradient descent attack algorithm conducts adversarial training on the bill image authenticity and false recognition classifier. Using the transferability of the adversarial samples between adjacent training cycles, the bill adversarial samples problem after the tiny perturbation noise in the prior art is solved, and the accuracy and robustness of bill recognition are improved.
Patent Information
- Application Number
- CN202510379710.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-07-01
AI Technical Summary
The prior art cannot accurately identify bill confrontation samples after adding tiny perturbation noise, resulting in low accuracy of bill recognition results.
The superimposed perturbation projection gradient descent attack algorithm is used to conduct adversarial training on the ticket image authenticity and false recognition classifier. By retaining and iteratively using adversarial samples between adjacent training cycles, the classifier's robustness is gradually enhanced, and the high transferability of adversarial samples between adjacent training cycles is used to reduce the impact of perturbations in the early training stage.
It improves the identification accuracy and robustness of the bill image authenticity recognition classifier when facing confronting sample attacks, ensuring that it can effectively distinguish authenticity and fake bills in practical applications and protect the security and reliability of financial transactions.
Smart Images

Figure CN120236286A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of bill anti-counterfeiting identification, and more particularly, to a method for defending bill countermeasure samples against anti-counterfeiting attacks, an apparatus for defending bill countermeasure samples against anti-counterfeiting attacks, a computer-readable storage medium, and a computer program product. Background Art
[0002] Commercial bills are one of the commonly used payment tools in commercial transactions, and usually involve relatively large amounts, starting from millions or tens of millions. Therefore, ensuring the authenticity and security of bills through bill anti-counterfeiting identification is a very important link. Deep learning technology has currently achieved performance beyond human capabilities in many application scenarios, and can also achieve quite excellent results in the field of bill anti-counterfeiting identification. However, recent studies have shown that the bill image authenticity identification classifier trained based on deep learning is very vulnerable to attacks by countermeasure samples. For example, in the anti-counterfeiting application of commercial bill images, an attacker can add small but non-random perturbations to the sample data, forcing the bill image authenticity identification classifier to produce incorrect outputs and identifying fake forged bills as genuine. The existence of countermeasure samples poses a great threat to deep learning applications in real-world scenarios. In an anti-countermeasure environment such as bank bill business applications that are highly related to security, if malicious attackers are given the opportunity, serious losses will be caused. Therefore, it is very necessary to study the method for defending against countermeasure samples of the deep learning bill image authenticity identification classifier.
[0003] Existing bill authentication methods usually rely on physical and chemical methods to create anti-counterfeiting features, and then identify the authenticity through methods of extracting and recognizing the anti-counterfeiting features of bills. The main methods include the following: embedding special watermarks during the paper-making process, which are difficult to detect by the naked eye but visible under specific lighting conditions. Or adding tiny text or patterns to the bill, which are difficult to replicate by conventional printing means, and these fine details need to be viewed with a magnifying glass or special tools. For example, in the invention "Bill Automatic Authentication Processing System and Method Based on Bill Graphic Codes" CN 1967601 A, the authenticity is identified by printing an image of a two-dimensional distribution of encrypted information on the bill. In the invention "Bill Authenticity Identification Device and Bill Authenticity Identification System" CN 205862423 U, the fluorescence anti-counterfeiting ink (such as ultraviolet fluorescence ink, infrared fluorescence ink) on the bill is irradiated with white light, ultraviolet light, and infrared light, and the fluorescence characteristic image of the bill is collected for bill authentication. In the invention "A Bill Anti-Counterfeiting Authentication Method Based on the Fluorescence Characteristics of the Main Pattern" CN107221070 A, the fluorescence characteristics are also formed by irradiating the anti-counterfeiting ink with ultraviolet light, and the anti-counterfeiting purpose is achieved by comparing the fluorescence characteristics of the main pattern. However, the materials for preparing the fluorescence anti-counterfeiting ink are relatively easy to obtain in the market. Therefore, this authentication method is difficult to be used for high-end anti-counterfeiting. To sum up, the existing authentication methods usually adopt traditional physical and chemical means. One of the characteristics is that it can be counterfeited by some high-end technologies, and the other is that it cannot resist the current advanced adversarial sample attacks. Whether it is through manual identification or existing technical solutions, it is impossible to accurately identify the bill adversarial samples with tiny perturbation noise added. Summary of the Invention
[0004] The main purpose of this application is to provide a method for defending against bill adversarial sample anti-counterfeiting attacks, a device for defending against bill adversarial sample anti-counterfeiting attacks, a computer-readable storage medium, and a computer program product, so as to at least solve the problem in the prior art that the accuracy of bill recognition results is low because the bill adversarial samples with tiny perturbation noise added cannot be accurately identified.
[0005] To achieve the above object, according to one aspect of the present application, a method for defending against counterfeiting attacks on sample bills is provided. The method includes: obtaining sample bill image data; a first training step of performing adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm according to the sample bill image data, and retaining the current adversarial sample, where the current adversarial sample is the adversarial sample obtained in the current training cycle; a second training step of using the current adversarial sample output in the current training cycle as the input to the bill image authenticity recognition classifier in the next training cycle, and continuing the adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm, and retaining the adversarial sample corresponding to the next training cycle, where the next training cycle is the next training cycle adjacent to the current training cycle; repeating the step of updating the next training cycle to be the current training cycle, and repeating the second training step at least once until the number of the current training cycle is a multiple of the set reset perturbation period number, where the set reset perturbation period number is a set number of the training cycles; a testing step of testing the bill image authenticity recognition classifier based on a test set to obtain the classifier accuracy, where the test set includes the sample bill image data and the sample bill authentication result corresponding to the sample bill image data; in the case where the classifier accuracy does not meet the accuracy requirement, adjusting the parameters of the bill image authenticity recognition classifier, and sequentially repeating the first training step, the second training step, the repeating step, and the testing step at least once until the set maximum iteration period is reached or the classifier accuracy meets the accuracy requirement, and determining the currently trained bill image authenticity recognition classifier as the target bill image authenticity recognition classifier, where the set maximum iteration period is greater than the set reset perturbation period number; obtaining the bill image data to be authenticated, and inputting the bill image data to be authenticated into the target bill image authenticity classifier to obtain a bill authentication result, so as to execute a corresponding disposal strategy on the bill according to the bill authentication result, where the bill authentication result is one of the following: the bill image data to be authenticated is genuine and the bill image data to be authenticated is fake.
[0006] Optionally, before performing adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm according to the sample bill image data and retaining the current adversarial sample, the method further includes: determining the objective function of the bill image authenticity recognition classifier, and the expression of the objective function is arg min θ ·E(x,y)~D[max δ∈sL(f(x + δ, θ), y)], where x represents the sample bill image data, y represents the reference label of the sample bill image data, D represents the data distribution of the sample bill image data x and the reference label y, L represents the internal maximization loss function, f represents the bill image authenticity classifier parameterized by θ, S represents the set allowable perturbation space, δ represents the adversarial perturbation added to the sample bill image data, θ represents the parameters within the bill image authenticity recognition classifier, and E(x, y) represents the external minimization loss function; determining the internal maximization loss function and the external minimization loss function of the bill image authenticity recognition classifier, where the expression of the internal maximization loss function is L(f(x + δ), y), L represents the internal maximization loss function, f represents the bill image authenticity classifier, x represents the sample bill image data, y represents the reference label of the sample bill image data, and the expression of the external minimization loss function is E(x, y) = BCE(f(x + δ), θ), y + λ · KL(f(x, θ) || f(x + δ, θ)) · (1 - p y (x, θ)), BCE represents the enhanced cross-entropy loss, p y (x, θ) represents the probability value that the bill image authenticity classifier predicts the sample bill image data x as the reference label y when the parameter is θ, KL represents the Kullback-Leibler divergence term, and λ represents an adjustable parameter.
[0007] Optionally, using the current adversarial sample output in the current training cycle as the input to the bill image authenticity recognition classifier in the next training cycle, and continuing the adversarial training on the bill image authenticity recognition classifier based on the stacked perturbation projected gradient descent attack algorithm, and retaining the adversarial sample corresponding to the next training cycle, including: in the next training cycle, attacking the bill image authenticity recognition classifier based on the stacked perturbation projected gradient descent attack algorithm on the basis of the current adversarial sample to generate the next adversarial sample, where the next adversarial sample is the adversarial sample generated in the next training cycle.
[0008] Optionally, in the next training cycle, attacking the bill image authenticity recognition classifier based on the stacked perturbation projected gradient descent attack algorithm on the basis of the current adversarial sample to generate the next adversarial sample, including: generating the next adversarial sample according to the first formula, and the first formula is represents the next adversarial sample corresponding to the (i + 1)-th training cycle, A represents the stacked perturbation projected gradient descent attack algorithm, f i+1denote the bill image authenticity recognition classifier for the (i + 1)-th training cycle, x denote the sample bill image data, and y denote the reference label corresponding to the sample bill image data. denote the adversarial sample generated in the i-th training cycle.
[0009] Optionally, after updating the next training cycle to the current training cycle, the method further includes: updating the next adversarial sample to the current adversarial sample.
[0010] Optionally, after updating the next training cycle to the current training cycle and repeating the second training step at least once until before reaching the set reset perturbation period number, the method further includes: setting a periodic reset perturbation strategy, where the periodic reset perturbation strategy is to periodically superimpose the adversarial perturbation starting from the sample bill image data every interval of the set reset perturbation period number.
[0011] Optionally, repeating the first training step, the second training step, and the test step at least once in sequence until reaching the set maximum iteration cycle or the classifier accuracy of the bill image authenticity recognition classifier meets the accuracy requirement, including: optimizing the adversarial training process of the bill image authenticity recognition classifier using stochastic weight averaging and mixed precision.
[0012] According to another aspect of the present application, there is provided a device for defending bill against sample anti-counterfeiting attacks, the device comprising: an acquisition unit for acquiring sample bill image data; a first training unit for performing a first training step of performing adversarial training on a bill image authenticity recognition classifier based on the sample bill image data according to the superimposed perturbation projection gradient descent attack algorithm, and retaining the current adversarial sample, where the current adversarial sample is the adversarial sample obtained in the current training cycle; a second training unit for performing a second training step of using the current adversarial sample output in the current training cycle as the input to the bill image authenticity recognition classifier in the next training cycle, and continuing to perform the adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm, and retaining the adversarial sample corresponding to the next training cycle, where the next training cycle is the next training cycle adjacent to the current training cycle; a first repetition unit for performing a repetition step of updating the next training cycle to the current training cycle, and repeating the second training step at least once until the number of the current training cycle is a multiple of a set reset perturbation period number, where the set reset perturbation period number is a set number of the training cycles; a testing unit for performing a testing step of testing the bill image authenticity recognition classifier based on a test set to obtain a classifier accuracy, where the test set includes the sample bill image data and the sample bill authentication result corresponding to the sample bill image data; a second repetition unit for adjusting the parameters of the bill image authenticity recognition classifier when the classifier accuracy does not meet the accuracy requirement, and sequentially repeating the first training step, the second training step, the repetition step, and the testing step at least once until a set maximum iteration period is reached or the classifier accuracy meets the accuracy requirement, and determining the currently trained bill image authenticity recognition classifier as the target bill image authenticity recognition classifier, where the set maximum iteration period is greater than the set reset perturbation period number; an input unit for acquiring bill image data to be authenticated, and inputting the bill image data to be authenticated into the target bill image authenticity classifier to obtain a bill authentication result, so as to perform a corresponding disposal strategy on the bill according to the bill authentication result, where the bill authentication result is one of the following: the bill image data to be authenticated is genuine and the bill image data to be authenticated is fake.
[0013] According to still another aspect of the present application, there is provided a computer-readable storage medium, the computer-readable storage medium including a stored program, wherein when the program runs, it controls a device where the computer-readable storage medium is located to execute any one of the methods.
[0014] According to yet another aspect of the present application, there is provided a computer program product including computer instructions, where when the computer instructions are executed by a processor, they implement any one of the methods.
[0015] Applying the technical solution of the present application in the method for defending against anti-counterfeiting attacks of bill counterfeiting samples, first, obtain the image data of the sample bill; then, in the first training step, based on the above sample bill image data, perform adversarial training on the bill image authenticity recognition classifier using the superimposed perturbation projection gradient descent attack algorithm, and retain the current adversarial sample, where the current adversarial sample is the adversarial sample obtained in the current training cycle; thereafter, in the second training step, use the above current adversarial sample output in the current training cycle as the input to the bill image authenticity recognition classifier in the next training cycle, and continue to perform the above adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm, and retain the adversarial sample corresponding to the next training cycle, where the next training cycle is the next training cycle adjacent to the current training cycle; thereafter, repeat the steps, update the next training cycle to the current training cycle, and repeat the second training step at least once until the number of the current training cycle is a multiple of the set reset perturbation period number, where the set reset perturbation period number is a set number of the above training cycles; thereafter, in the testing step, test the bill image authenticity recognition classifier based on the test set to obtain the classifier accuracy, where the test set includes the above sample bill image data and the sample bill authentication result corresponding to the above sample bill image data; thereafter, in the case where the classifier accuracy does not meet the accuracy requirement, adjust the parameters of the bill image authenticity recognition classifier, and sequentially repeat the first training step, the second training step, the repeating step, and the testing step at least once until the set maximum iteration period is reached or the classifier accuracy meets the above accuracy requirement, and determine the currently trained bill image authenticity recognition classifier as the target bill image authenticity recognition classifier, where the set maximum iteration period is greater than the set reset perturbation period number; finally, obtain the image data of the bill to be authenticated, and input the above image data of the bill to be authenticated into the above target bill image authenticity classifier to obtain the bill authentication result, so as to execute the corresponding disposal strategy on the bill according to the above bill authentication result, where the bill authentication result is one of the following: the above image data of the bill to be authenticated is genuine and the above image data of the bill to be authenticated is fake. The key point of the technical solution of the present application lies in utilizing the high transferability of adversarial samples between the bill image authenticity recognition classifiers in adjacent training cycles, and proposes an improved adversarial training method: an adversarial training method based on the superimposed perturbation projection gradient descent attack. After the end of the i-th training cycle, the obtained adversarial sample is saved as the starting point for generating the adversarial sample in the (i + 1)-th training cycle, and then in the (i + 1)-th training cycle, the bill image authenticity recognition classifier is attacked based on xi* to obtain the adversarial sample in the (i + 1)-th training cycle, and at the same time, the adversarial sample obtained in the (i + 1)-th training cycle is saved for use in the next cycle, and iterative training is performed in this way.Every few training cycles (set the number of reset perturbation cycles), let the adversarial perturbation accumulate periodically starting from the sample bill image data, so as to reduce the impact caused by the perturbation added in the early stage of training. This application solves the problem in the prior art that it is impossible to accurately identify the bill adversarial samples with tiny perturbation noise added, resulting in low accuracy of the bill recognition result. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 FIG. shows a hardware structure block diagram of a mobile terminal for implementing a method for defending against bill adversarial sample anti-counterfeiting attacks according to an embodiment of the present application;
[0017] Figure 2 FIG. shows a schematic flowchart of a method for defending against bill adversarial sample anti-counterfeiting attacks according to an embodiment of the present application;
[0018] Figure 3 FIG. shows a schematic flowchart of a specific method for defending against bill adversarial sample anti-counterfeiting attacks according to an embodiment of the present application;
[0019] Figure 4 FIG. shows a schematic diagram of the difference between a traditional PGD-based adversarial training and the adversarial training of the present application according to an embodiment of the present application;
[0020] Figure 5 FIG. shows a structure block diagram of a device for defending against bill adversarial sample anti-counterfeiting attacks according to an embodiment of the present application.
[0021] Among them, the above-mentioned drawings include the following reference numerals:
[0022] 102, processor; 104, memory; 106, transmission device; 108, input / output device. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0024] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0025] It should be noted that the terms "first", "second", etc. in the specification, claims and above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so as to implement the embodiments of this application described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.
[0026] For the convenience of description, some nouns or terms related to the embodiments of this application are described below:
[0027] An adversarial sample can be defined as a new sample obtained by adding some specially calculated and imperceptible subtle perturbation noises to a clean original sample through the use of a specific attack algorithm, which can force a deep learning bill image authenticity recognition classifier to produce an incorrect output, thereby achieving the purpose of attack.
[0028] Adversarial training refers to using a specific attack algorithm to attack a target model to generate adversarial samples, and then using the augmented training data set containing the adversarial samples to train a classifier until a new model with a certain immunity to the attack is trained, thereby improving the robustness of the deep learning model against adversarial samples in the bill anti-counterfeiting recognition task.
[0029] As introduced in the background art, in the prior art, neither manual recognition nor existing technical solutions can accurately identify bill adversarial samples with added tiny perturbation noises. To solve the problem of low accuracy of bill recognition results caused by the inability to accurately identify bill adversarial samples with added tiny perturbation noises in the prior art, the embodiments of this application provide a method for defending against bill adversarial sample anti-counterfeiting attacks, an apparatus for defending against bill adversarial sample anti-counterfeiting attacks, a computer-readable storage medium, and a computer program product.
[0030] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention.
[0031] The method embodiments provided in the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 is a hardware structure block diagram of a mobile terminal for a method of defending against bill adversarial sample anti-counterfeiting attacks in an embodiment of the present invention. As Figure 1 shown, the mobile terminal may include one or more ( Figure 1Only one processor 102 is shown (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a field-programmable gate array FPGA), and a memory 104 for storing data. Among them, the above mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 The structure shown is only schematic and does not limit the structure of the above mobile terminal. For example, the mobile terminal may further include more or fewer components than those Figure 1 shown in, or have a different configuration from Figure 1 that shown.
[0032] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the method for defending against counterfeiting attacks of counterfeit bills in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above networks include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the mobile terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0033] In this embodiment, a method for defending against counterfeiting attacks of counterfeit bills running on a mobile terminal, a computer terminal, or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from that here.
[0034] Figure 2 is a flowchart of a method for defending against counterfeiting attacks of counterfeit bills according to an embodiment of the present application. As Figure 2 shown, the method includes the following steps:
[0035] Step S201: Obtain the sample bill image data.
[0036] Specifically, as Figure 3 shown, first, collect the bill image data from a database containing a large number of real bills and forged bills. These data need to be preprocessed, such as scaling, grayscaling, data augmentation, etc., to ensure that the bill image authenticity recognition classifier can learn the authenticity features of the bills from diverse perspectives. A high-quality and diverse bill image dataset is the basis for training an efficient and robust bill image authenticity recognition classifier. By obtaining a large number of samples, the bill image authenticity recognition classifier can learn various features of the bill images, including possible forgery patterns and subtle anti-counterfeiting details, thereby improving its recognition ability.
[0037] Step S202: The first training step. Based on the above sample bill image data, perform adversarial training on the bill image authenticity recognition classifier using the superimposed perturbation projection gradient descent attack algorithm, and retain the current adversarial sample. The above current adversarial sample is the adversarial sample obtained in the current training cycle.
[0038] Specifically, the bill image authenticity recognition classifier is first initialized and trained using the sample bill image data. Then, use the superimposed perturbation projection gradient descent (PGD) attack algorithm to generate adversarial samples. Specifically, starting from the original bill image data, find the perturbation that can maximize the internal loss function within the restricted perturbation space through the PGD algorithm to generate adversarial samples. Specifically, train the bill image authenticity recognition classifier, perform adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm. In the first cycle, use the original clean sample to attack the classifier to obtain the adversarial sample, and retain the obtained adversarial sample for use in the next training cycle.
[0039] Step S203: The second training step. Use the above current adversarial sample output in the current training cycle as the input of the bill image authenticity recognition classifier in the next training cycle, and continue the above adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm, and retain the adversarial sample corresponding to the next training cycle. The above next training cycle is the next training cycle adjacent to the above current training cycle.
[0040] Specifically, the key point of the technical solution of the present invention lies in utilizing the high transferability of adversarial examples between the bill image authenticity recognition classifiers in adjacent training cycles, and an improved adversarial training method is proposed - an adversarial training method based on the superimposed perturbation PGD (Projected Gradient Descent) attack. Specifically, the adversarial examples obtained in the previous training cycle are used as the input for the current training cycle, and adversarial training is continued. The obtained adversarial examples are retained and used as the input for the next training cycle.
[0041] As Figure 4 (a) shows, different from the attack method of generating adversarial examples from the sample bill image data x in each training cycle in traditional adversarial training, in the method of the present invention, after the end of the i-th training cycle, the adversarial example xi* obtained in the i-th training cycle is saved as the starting point for generating adversarial examples in the (i + 1)-th training cycle. Then, in the (i + 1)-th training cycle, the bill image authenticity recognition classifier fi+1 is attacked based on xi* to obtain the adversarial example for training in the (i + 1)-th training cycle Then, the adversarial example is used to update the weights of the bill image authenticity recognition classifier in the (i + 1)-th training cycle. At the same time, the adversarial example obtained in the (i + 1)-th training cycle is saved for use in the next cycle (the (i + 2)-th training cycle). That is to say, the generation of adversarial examples in each training cycle starts from the adversarial examples obtained in the previous training cycle, as shown in Figure 4 (b).
[0042] Step S204, repeat the steps, update the above-mentioned next training cycle to the above-mentioned current training cycle, and repeat the above-mentioned second training step at least once until the number of the above-mentioned current training cycle is a multiple of the set reset perturbation period number, and the set reset perturbation period number is the set number of the above-mentioned training cycles.
[0043] Specifically, the purpose of setting the reset perturbation period is to re-initialize the perturbation regularly, avoiding the negative impact of drastic parameter changes in the early training stage on the generation of adversarial samples in subsequent periods. During training, adversarial samples are repeatedly used between training periods. At the end of each training period, the generated adversarial samples are saved as the starting point for the next training. For example, if the reset perturbation period is set to 10 training periods, the adversarial training starts from the sample bill image data in the first training period, and the adversarial samples of the first training period are generated. In the second training period, perturbations are superimposed on the adversarial samples of the first training period, and so on until the 10th training period. The 11th training period starts the adversarial training from the sample bill image data again, and the same applies to subsequent training periods, such as the 21st training period, the 31st training period... The (n*10 + 1)th training period starts the adversarial training from the sample bill image data again, where n is the set reset perturbation period.
[0044] Step S205, a testing step, testing the authenticity recognition classifier of the above bill images based on a test set to obtain the classifier accuracy. The above test set includes the above sample bill image data and the corresponding sample bill authentication results of the above sample bill image data.
[0045] Specifically, an independent test set is used to evaluate the performance of the authenticity recognition classifier of bill images. The test set contains bill image data and their corresponding authenticity labels that have not been used in the training process. By inputting the test set into the authenticity recognition classifier of bill images, the classification accuracy of the authenticity recognition classifier of bill images is calculated. This is the key to evaluating the generalization ability and robustness of the authenticity recognition classifier of bill images, which can help determine whether the authenticity recognition classifier of bill images can perform well on unseen data and at the same time detect whether the authenticity recognition classifier of bill images effectively resists adversarial sample attacks.
[0046] Step S206, in the case where the above classifier accuracy does not meet the accuracy requirement, adjusting the parameters of the above authenticity recognition classifier of bill images, and repeating the above first training step, the above second training step, the above repeating step, and the above testing step at least once in sequence until the set maximum iteration period is reached or the above classifier accuracy meets the above accuracy requirement. The currently trained above authenticity recognition classifier of bill images is determined as the target authenticity recognition classifier of bill images. The above set maximum iteration period is greater than the above set reset perturbation period.
[0047] Specifically, if the classifier accuracy obtained in the testing step is lower than the set accuracy requirement, repeat the above first training step, the above second training step, the above repeating step, and the above testing step until the set maximum iteration period is reached or the classifier accuracy meets the accuracy requirement. Through continuous iterative training and testing, the bill image authenticity recognition classifier can continuously learn and improve until it can maintain a high classification accuracy on clean data and also maintain sufficient defense against adversarial samples. This process helps to finally determine an accurate and robust bill image authenticity recognition classifier, that is, the target bill image authenticity recognition classifier.
[0048] Step S207: Obtain the bill image data to be authenticated, and input the bill image data to be authenticated into the above target bill image authenticity classifier to obtain a bill authentication result, and execute a corresponding disposal strategy for the bill according to the bill authentication result. The bill authentication result is one of the following: the bill image data to be authenticated is genuine and the bill image data to be authenticated is fake.
[0049] Specifically, once the bill image authenticity recognition classifier is trained and reaches the expected performance indicators, the bill image data to be authenticated can be input into the target bill image authenticity recognition classifier to obtain the authentication result of the bill. The accuracy and robustness of the target classifier can ensure that in practical applications, even in the face of adversarial samples carefully designed by forgers, the system can make correct judgments, effectively distinguish genuine and fake bills, and thus protect the security and reliability of financial transactions.
[0050] Through the entire training process, the bill image authenticity recognition classifier not only learns to recognize normal bills and their features, but also learns how to protect itself against adversarial attacks. Finally, the bill image authenticity recognition classifier can obtain high accuracy and robustness at a low computational cost and time overhead, providing an efficient and secure solution for bill anti-counterfeiting.
[0051] In this embodiment, first, sample bill image data is obtained; then, in the first training step, based on the above sample bill image data, the bill image authenticity recognition classifier is adversarially trained using the stacked perturbation projection gradient descent attack algorithm, and the current adversarial sample is retained. The above current adversarial sample is the adversarial sample obtained in the current training cycle; thereafter, in the second training step, the above current adversarial sample output in the above current training cycle is used as the input of the above bill image authenticity recognition classifier in the next training cycle, and the above bill image authenticity recognition classifier is continuously adversarially trained based on the stacked perturbation projection gradient descent attack algorithm, and the adversarial sample corresponding to the above next training cycle is retained. The above next training cycle is the next training cycle adjacent to the above current training cycle; thereafter, the steps are repeated, the above next training cycle is updated to the above current training cycle, and the above second training step is repeated at least once until the number of the above current training cycle is a multiple of the set reset perturbation period number, and the above set reset perturbation period number is a set number of the above training cycles; thereafter, in the test step, the above bill image authenticity recognition classifier is tested based on a test set to obtain the classifier accuracy. The above test set includes the above sample bill image data and the sample bill authentication result corresponding to the above sample bill image data; thereafter, in the case where the above classifier accuracy does not meet the accuracy requirement, the parameters of the above bill image authenticity recognition classifier are adjusted, and the above first training step, the above second training step, the above repetition step, and the above test step are sequentially repeated at least once until the set maximum iteration period is reached or the above classifier accuracy meets the above accuracy requirement, and the above bill image authenticity recognition classifier currently being trained is determined as the target bill image authenticity recognition classifier. The above set maximum iteration period is greater than the above set reset perturbation period number; finally, the bill image data to be authenticated is obtained, and the above bill image data to be authenticated is input into the above target bill image authenticity classifier to obtain a bill authentication result, so as to execute a corresponding disposal strategy on the bill according to the above bill authentication result. The above bill authentication result is one of the following: the above bill image data to be authenticated is genuine and the above bill image data to be authenticated is fake. The key point of the technical solution of this application is to utilize the high transferability of adversarial samples between bill image authenticity recognition classifiers in adjacent training cycles, and propose an improved adversarial training method: an adversarial training method based on stacked perturbation projection gradient descent attack. After the end of the i-th training cycle, the obtained adversarial sample is saved as the starting point for generating the adversarial sample in the (i + 1)-th training cycle. Then, in the (i + 1)-th training cycle, the bill image authenticity recognition classifier is attacked based on xi* to obtain the adversarial sample in the (i + 1)-th training cycle, and at the same time, the adversarial sample obtained in the (i + 1)-th training cycle is saved for use in the next cycle, and training is iterated in this way. Every few training cycles (set reset perturbation period number), the adversarial perturbation is allowed to accumulate periodically starting from the sample bill image data, so as to reduce the influence caused by the perturbation added in the early stage of training.This application solves the problem in the prior art that it is impossible to accurately identify the adversarial samples of bills with added minute perturbation noise, resulting in low accuracy of bill recognition results.
[0052] To enable those skilled in the art to more clearly understand the technical solution of this application, the implementation process of the method for defending against bill adversarial sample forgery attacks of this application will be described in detail below in conjunction with specific embodiments.
[0053] To ensure that the bill image authenticity classifier can still maintain a high classification accuracy when under attack, in an optional implementation manner, before the above step S202, the method further includes:
[0054] Step S301, determining the objective function of the above bill image authenticity recognition classifier, and the expression of the above objective function is arg min θ ·E(x, y)~D[max δ∈s L(f(x + δ, θ), y)], where x represents the above sample bill image data, y represents the reference label of the above sample bill image data, D represents the data distribution of the above sample bill image data x and the reference label y, L represents the internal maximization loss function, f represents the above bill image authenticity classifier parameterized by θ, S represents the set allowable perturbation space, δ represents the adversarial perturbation added to the above sample bill image data, θ represents the parameter in the above bill image authenticity recognition classifier, and E(x, y) represents the external minimization loss function;
[0055] Step S302, determining the above internal maximization loss function and the above external minimization loss function of the above bill image authenticity recognition classifier, where the expression of the above internal maximization loss function is L(f(x + δ), y), L represents the above internal maximization loss function, f represents the above bill image authenticity classifier, x represents the above sample bill image data, y represents the reference label of the above sample bill image data, and the expression of the above external minimization loss function is E(x, y) = BCE(f(x + δ), θ), y + λ·KL(f(x, θ)||f(x + δ, θ))·(1 - p y (x, θ)), BCE represents the enhanced cross-entropy loss, p y (x, θ) represents the probability value that the above bill image authenticity classifier predicts the sample bill image data x as the above reference label y when the parameter is θ, KL represents the Kullback-Leibler divergence term, and λ represents an adjustable parameter.
[0056] In the above embodiment, adversarial training is a min-max optimization problem, and its goal is to find the bill image authenticity recognition classifier parameter θ that minimizes the following adversarial risk, and the objective function is such as arg min θ·E(x, y) ~ D[max δ∈s L(f(x + δ, θ), y)]. To ensure the imperceptibility of the perturbation, the perturbation increment needs to be projected into a pre-set perturbation space (S), which usually means that the L∞ norm does not exceed a certain set threshold. This can ensure that the perturbed sample still looks similar to the original sample and misleads the bill image authenticity recognition classifier without being perceptible to the human eye. The basic strategy of adversarial training is to, given the sample bill image data x, find the adversarial sample x + δ with added perturbation to maximize the internal loss with respect to the correct class. Then train the bill image authenticity recognition classifier on the generated adversarial samples to minimize the external loss. Therefore, the loss function in adversarial training involves maximizing the internal loss and minimizing the external loss. (1) Maximizing the internal loss, which is also the attack loss inside adversarial training. The attack generates adversarial samples that misclassify the bill image authenticity classifier through maximizing the internal loss. The internal maximization loss function represents the degree of deviation between the result predicted by the bill image authenticity recognition classifier for the adversarial sample and the reference label. The internal maximization loss function applies a fixed reference label y, with lower computational complexity, which can reduce the computational overhead during training. The internal maximization loss function can simply select an appropriate loss function, such as the binary cross-entropy loss function. (2) Minimizing the external loss: represents the degree of deviation between the probability distributions of the sample bill image data and the adversarial sample predicted by the bill image authenticity classifier. By optimizing the objective function and combining the internal maximization loss and the external minimization loss, the adversarial training method can introduce adversarial perturbations during the training process of the bill image authenticity classifier, enabling the bill image authenticity classifier to still maintain a high classification accuracy when under attack, significantly improving the robustness of the bill image authenticity recognition classifier. Even when the attacker uses adversarial samples, it can effectively identify the authenticity of the bill, thus enhancing the overall security and reliability of the bill anti-counterfeiting system.
[0057] To improve the robustness of the bill image authenticity recognition classifier against real-world attacks, in an optional implementation manner, the above step S203 includes:
[0058] Step S2031, in the next training cycle, based on the above superimposed perturbation projection gradient descent attack algorithm, attack the bill image authenticity recognition classifier on the basis of the current adversarial sample to generate the next adversarial sample, where the next adversarial sample is the adversarial sample generated in the next training cycle.
[0059] In the above embodiments, the adversarial examples generated in the previous training cycle are used as the input for the current training cycle. For the (i + 1)-th training cycle, the perturbation is initialized as the adversarial example of the previous cycle, which means that the accumulation of perturbations starts from the adversarial example of the previous cycle. Using the stacked perturbation projected gradient descent attack algorithm, a new perturbation increment is calculated to maximize the classification error of the bill image authenticity recognition classifier for the adversarial examples. The calculated perturbation increment is added to the current adversarial example to generate a new adversarial example. This process is called stacked perturbation because it adds a new perturbation on the basis of the adversarial example of the previous cycle. By using stacked perturbation in each round of training, the bill image authenticity recognition classifier can gradually adapt and learn how to handle increasingly complex adversarial perturbations, thereby significantly improving its robustness against real-world attacks. By generating new adversarial examples by stacking perturbations in each round of training, not only does it accelerate the adversarial training process, but it also continuously improves the classification accuracy of the bill image authenticity recognition classifier on adversarial examples, ensuring that in the bill authentication task, even in the face of carefully designed adversarial attacks, the bill image authenticity recognition classifier can maintain high robustness and generalization ability. This strategy is crucial for building a secure and reliable bill anti-counterfeiting recognition system.
[0060] To reduce the computational cost of adversarial training, in an alternative embodiment, the above step S2031 includes:
[0061] S20311, generating the above next adversarial example according to the first formula, and the first formula is represents the above next adversarial example corresponding to the (i + 1)-th above training cycle, A represents the above stacked perturbation projected gradient descent attack algorithm, f i+1 represents the above bill image authenticity recognition classifier of the (i + 1)-th training cycle, x represents the above sample bill image data, y represents the reference label corresponding to the above sample bill image data, represents the above adversarial example generated in the i-th above training cycle.
[0062] In the above embodiments, during the training process, by repeatedly using adversarial examples between training cycles, the attack intensity can accumulate cycle by cycle. According to the above first formula, adversarial examples can be generated, and the adversarial examples can be transmitted across cycles through the above connection process, rather than starting from the sample bill image data. Therefore, a high attack intensity can be obtained faster. Compared with generating adversarial examples starting from the sample bill image data each time, the generation method based on stacked perturbation allows obtaining high-quality adversarial examples with fewer iterations and less time, reducing the computational cost of adversarial training.
[0063] To enhance transferability, in an alternative embodiment, after the above step S204, the method further includes:
[0064] Step S401: Update the above-mentioned next adversarial sample to the current adversarial sample.
[0065] In the above embodiment, the adversarial sample obtained in the (i + 1)-th training cycle is saved for use in the next cycle (the (i + 2)-th training cycle), and then the adversarial sample is updated to the current adversarial sample to participate in the training. The high transferability of the adversarial sample between adjacent training cycles means that the adversarial sample generated in one training cycle is still effective in the next cycle. The step of updating the current adversarial sample helps to maintain and strengthen this transferability, enabling the bill image authenticity recognition classifier to learn more comprehensive and complex attack patterns during the training process.
[0066] To mitigate the impact of the perturbations added in the early stage of training, in an alternative embodiment, before the above-mentioned step S204, the method further includes:
[0067] Step S501: Set a periodic reset perturbation strategy, where the periodic reset perturbation strategy is to periodically superimpose the adversarial perturbation starting from the sample bill image data every the set number of reset perturbation periods.
[0068] In the above embodiment, when adopting the adversarial training process of the present invention, new problems will also be introduced. An important problem is the drastic change in the parameters of the bill image authenticity recognition classifier in the early stage of training: Similar parameters between bill image authenticity recognition classifiers often lead to similar decision boundaries. Therefore, the adversarial sample has high transferability between the bill image authenticity recognition classifiers in adjacent cycles. However, the parameters of the bill image authenticity recognition classifier often change significantly in the early stage of training. Therefore, the adversarial perturbations added in the early cycles are often useless for subsequent cycles and may even weaken the transferability. To solve this problem, a simple but effective solution is adopted here: Set a periodic reset perturbation strategy. Every few training cycles, let the adversarial perturbation accumulate periodically starting from the clean sample, so as to mitigate the impact of the perturbations added in the early stage of training.
[0069] To improve the robustness of the bill image authenticity recognition classifier and the efficiency during the training process, in an alternative embodiment, the above-mentioned step S206 further includes:
[0070] Step S2061: Optimize the adversarial training process of the bill image authenticity recognition classifier using stochastic weight averaging and mixed precision.
[0071] In the above embodiments, during the training process of the present invention, stochastic weight averaging and mixed-precision acceleration calculation techniques are introduced. Stochastic Weight Averaging (SWA) aims to enforce weight smoothing by simply averaging multiple checkpoints along the training trajectory, which can be used to optimize the weight update during training. SWA can find a flatter solution than Stochastic Gradient Descent (SGD), and enable the single bill image authenticity recognition classifier to achieve an approximate ensemble effect. Moreover, it is simple to implement, improves the standard generalization ability, and hardly introduces extra computational costs. In the present invention, SWA is introduced into the adversarial training process to smooth the weights and find a flatter loss minimum, thereby improving the generalization ability of adversarial sample defense. Mixed-precision calculation selectively uses half-precision floating-point numbers for calculation. Using mixed-precision calculation when training a deep network can provide a significant acceleration effect for the training process. Combining SWA and mixed-precision for training can make the bill image authenticity recognition classifier more effective in adversarial sample defense, improve its ability to identify forged bills, especially in terms of the robustness against adversarial samples. This optimization method not only improves the generalization and robustness of the bill image authenticity recognition classifier, but also reduces the training time and resource consumption, making the training and deployment of the bill image authenticity recognition classifier more efficient.
[0072] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0073] The embodiment of the present application also provides a device for defending against bill adversarial sample anti-counterfeiting attacks. It should be noted that the device for defending against bill adversarial sample anti-counterfeiting attacks in the embodiment of the present application can be used to execute the method for defending against bill adversarial sample anti-counterfeiting attacks provided by the embodiment of the present application. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0074] The following introduces the device for defending against bill adversarial sample anti-counterfeiting attacks provided by the embodiment of the present application.
[0075] Figure 5 It is a structural block diagram of the device for defending against bill adversarial sample anti-counterfeiting attacks according to the embodiment of the present application. As Figure 5 shown, the device includes:
[0076] An acquisition unit 10 for acquiring sample bill image data.
[0077] Specifically, as Figure 3 shown, first, bill image data is collected from a database containing a large number of real bills and forged bills. These data need to be preprocessed, such as scaling, grayscaling, data augmentation, etc., to ensure that the bill image authenticity recognition classifier can learn the authenticity features of bills from diverse perspectives. A high-quality and diverse bill image dataset is the basis for training an efficient and robust bill image authenticity recognition classifier. By obtaining a large number of samples, the bill image authenticity recognition classifier can learn various features of the bill images, including possible forgery patterns and subtle anti-counterfeiting details, thereby improving its recognition ability.
[0078] A first training unit 20 for performing a first training step of adversarially training the bill image authenticity recognition classifier based on the stacked perturbation projected gradient descent attack algorithm according to the above sample bill image data, and retaining the current adversarial sample, where the current adversarial sample is the adversarial sample obtained in the current training cycle.
[0079] Specifically, the bill image authenticity recognition classifier is first initialized and trained using the sample bill image data. Then, the projected gradient descent (PGD) attack algorithm is used to generate adversarial samples. Specifically, starting from the original bill image data, the PGD algorithm is used to find the perturbation that can maximize the internal loss function within the restricted perturbation space to generate adversarial samples.
[0080] A third training unit 30 for performing a second training step of continuing the above adversarial training on the bill image authenticity recognition classifier based on the stacked perturbation projected gradient descent attack algorithm by using the current adversarial sample output in the current training cycle as the input to the bill image authenticity recognition classifier in the next training cycle, and retaining the adversarial sample corresponding to the next training cycle, where the next training cycle is the next training cycle adjacent to the current training cycle.
[0081] Specifically, the key point of the technical solution of the present invention is to utilize the high transferability of adversarial samples between the bill image authenticity recognition classifiers in adjacent training cycles, and propose an improved adversarial training method - an adversarial training method based on the stacked perturbation PGD (projected gradient descent) attack.
[0082] As Figure 4As shown in (a), different from the attack method in traditional adversarial training that generates adversarial samples starting from the sample bill image data x in each training cycle, in the method of the present invention, after the end of the i-th training cycle, the adversarial sample xi* obtained in the i-th training cycle is saved as the starting point for generating adversarial samples in the (i + 1)-th training cycle. Then, in the (i + 1)-th training cycle, the bill image authenticity recognition classifier fi+1 is attacked based on xi* to obtain the adversarial sample for training in the (i + 1)-th training cycle. Then use the adversarial sample to update the weights of the bill image authenticity recognition classifier in the (i + 1)-th training cycle, and at the same time save the adversarial sample obtained in the (i + 1)-th training cycle for use in the next cycle (the (i + 2)-th training cycle). That is to say, the generation of adversarial samples in each training cycle starts from the adversarial sample obtained in the previous training cycle, as shown in Figure 4 (b).
[0083] The first repeating unit 40 is used to execute the repeating step, update the next training cycle above to the current training cycle above, and repeat the second training step at least once until the number of the current training cycle is a multiple of the set reset perturbation period number, and the set reset perturbation period number is the set number of the above training cycles.
[0084] Specifically, the purpose of setting the reset perturbation period number is to re-initialize the perturbation regularly to avoid the negative impact of drastic parameter changes in the early training stage on the generation of adversarial samples in subsequent cycles. During the training process, by repeatedly using the adversarial samples between training cycles, each time the training cycle ends, the generated adversarial samples are saved as the starting point for the next training. For example, if the set reset perturbation period number is 10 training cycles, then in the first training cycle, adversarial training starts from the sample bill image data to generate the adversarial sample in the first training cycle. In the second training cycle, additional perturbations are applied based on the adversarial sample in the first training cycle, and so on until the 10th training cycle. The 11th training cycle starts adversarial training from the sample bill image data again, and the same applies to subsequent training cycles. The 21st training cycle, the 31st training cycle... the (n * 10 + 1)-th training cycle starts adversarial training from the sample bill image data again, where n is the set reset perturbation period number.
[0085] The testing unit 50 is used to execute the testing step, test the bill image authenticity recognition classifier based on the test set, and obtain the classifier accuracy. The test set includes the sample bill image data and the sample bill discrimination results corresponding to the sample bill image data.
[0086] Specifically, an independent test set is used to evaluate the performance of the bill image authenticity recognition classifier. The test set contains bill image data that has not been used in the training process and its corresponding authenticity labels. By inputting the test set into the bill image authenticity recognition classifier, the classification accuracy of the bill image authenticity recognition classifier is calculated. This is the key to evaluating the generalization ability and robustness of the bill image authenticity recognition classifier, which can help determine whether the bill image authenticity recognition classifier can perform well on unseen data and at the same time detect whether the bill image authenticity recognition classifier can effectively resist adversarial sample attacks.
[0087] The second repeating unit 60 is used to adjust the parameters of the bill image authenticity recognition classifier in the case where the classifier accuracy does not meet the accuracy requirement. The above-mentioned first training step, the above-mentioned second training step, the above-mentioned repeating step, and the above-mentioned testing step are repeated at least once in sequence until the set maximum iteration period is reached or the classifier accuracy meets the above-mentioned accuracy requirement. The currently trained bill image authenticity recognition classifier is determined as the target bill image authenticity recognition classifier. The set maximum iteration period is greater than the set reset perturbation period number.
[0088] Specifically, if the classifier accuracy obtained in the testing step is lower than the set accuracy requirement, the above-mentioned first training step, the above-mentioned second training step, the above-mentioned repeating step, and the above-mentioned testing step are repeated until the set maximum iteration period is reached or the classifier accuracy meets the accuracy requirement. Through continuous iterative training and testing, the bill image authenticity recognition classifier can continuously learn and improve until it can maintain a high classification accuracy on clean data and also maintain sufficient defense against adversarial samples. This process helps to finally determine an accurate and robust bill image authenticity recognition classifier, that is, the target bill image authenticity recognition classifier.
[0089] The input unit 70 is used to obtain the bill image data to be authenticated and input the above-mentioned bill image data to be authenticated into the above-mentioned target bill image authenticity classifier to obtain a bill authentication result, so as to execute a corresponding disposal strategy on the bill according to the above-mentioned bill authentication result. The above-mentioned bill authentication result is one of the following: the above-mentioned bill image data to be authenticated is true and the above-mentioned bill image data to be authenticated is false.
[0090] Specifically, once the bill image authenticity recognition classifier is trained and reaches the expected performance indicators, the bill image data to be authenticated can be input into the target bill image authenticity recognition classifier to obtain the authentication result of the bill. The accuracy and robustness of the target classifier can ensure that in practical applications, even in the face of adversarial samples carefully designed by forgers, the system can make a correct judgment, effectively distinguish genuine and fake bills, thereby protecting the security and reliability of financial transactions.
[0091] Throughout the training process, the bill image authenticity recognition classifier has not only learned to recognize normal bills and their features but also learned how to protect itself against adversarial attacks. Ultimately, the bill image authenticity recognition classifier can achieve high accuracy and robustness at a relatively low computational cost and time overhead, providing an efficient and secure solution for bill anti-counterfeiting.
[0092] In this embodiment, after the training of the i-th training cycle is completed, the obtained adversarial samples are saved as the starting point for generating adversarial samples in the (i + 1)-th training cycle. Then, in the (i + 1)-th training cycle, the bill image authenticity recognition classifier is attacked based on xi* to obtain the adversarial samples of the (i + 1)-th training cycle. At the same time, the adversarial samples obtained in the (i + 1)-th training cycle are saved for use in the next cycle, and the training is iterated in this way. Every few training cycles (set the reset perturbation cycle number), the adversarial perturbation is accumulated periodically starting from the sample bill image data, so as to reduce the impact caused by the perturbation added in the early stage of training. This application solves the problem in the prior art that it is impossible to accurately recognize the bill adversarial samples with tiny added perturbation noise, resulting in low accuracy of the bill recognition result.
[0093] To ensure that the bill image authenticity classifier can still maintain a high classification accuracy rate when under attack, in an optional implementation manner, the device further includes:
[0094] A first determination unit, configured to determine the objective function of the bill image authenticity recognition classifier before retaining the current adversarial sample when performing adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projected gradient descent attack algorithm according to the above sample bill image data. The expression of the objective function is arg min θ ·E(x,y)~D[max δ∈s L(f(x + δ,θ),y)], where x represents the above sample bill image data, y represents the reference label of the above sample bill image data, D represents the data distribution of the above sample bill image data x and the reference label y, L represents the internal maximization loss function, f represents the above bill image authenticity classifier parameterized by θ, S represents the set allowable perturbation space, δ represents the adversarial perturbation added to the above sample bill image data, θ represents the parameters in the above bill image authenticity recognition classifier, and E(x,y) represents the external minimization loss function;
[0095] A second determination unit, configured to determine the internal maximization loss function and the external minimization loss function of the bill image authenticity recognition classifier, where the expression of the internal maximization loss function is L(f(x+δ), y), L represents the internal maximization loss function, f represents the bill image authenticity classification classifier, x represents the sample bill image data, y represents the reference label of the sample bill image data, and the expression of the external minimization loss function is E(x, y) = BCE(f(x+δ), θ), y + λ·KL(f(x, θ)||f(x+δ, θ))·(1 - p y (x, θ)), BCE represents the enhanced cross-entropy loss, p y (x, θ) represents the probability value that the bill image authenticity classification classifier predicts the sample bill image data x as the reference label y when the parameter is θ, KL represents the Kullback-Leibler divergence term, and λ represents an adjustable parameter.
[0096] In the above embodiment, adversarial training is a min-max optimization problem, and its objective is to find the bill image authenticity recognition classifier parameter θ that minimizes the following adversarial risk, and the objective function is such as arg min θ ·E(x, y)~D[max δ∈sL(f(x + δ, θ), y). To ensure the imperceptibility of the perturbation, the perturbation increment needs to be projected into a pre-set perturbation space (S), which usually means that the L∞ norm does not exceed a certain set threshold. This can ensure that the perturbed sample still looks similar to the original sample and misleads the bill image authenticity recognition classifier without being perceptible to the human eye. The basic strategy of adversarial training is to, given the sample bill image data x, find the adversarial sample x + δ with added perturbation to maximize the internal loss with respect to the correct category. Then, train the bill image authenticity recognition classifier on the generated adversarial samples to minimize the external loss. Therefore, the loss function in adversarial training involves maximizing the internal loss and minimizing the external loss. (1) Maximizing the internal loss, which is also the attack loss inside adversarial training. The attack generates adversarial samples that misclassify the bill image authenticity classifier through maximizing the internal loss. The internal maximization loss function represents the degree of deviation between the result predicted by the bill image authenticity recognition classifier for the adversarial sample and the reference label. The internal maximization loss function applies a fixed reference label y, with lower computational complexity, which can reduce the computational overhead during training. The internal maximization loss function can simply select an appropriate loss function, such as the binary cross-entropy loss function. (2) Minimizing the external loss: represents the degree of deviation between the probability distributions of the sample bill image data and the adversarial samples predicted by the bill image authenticity classifier. By optimizing the objective function and combining the internal maximization loss and the external minimization loss, the adversarial training method can introduce adversarial perturbations during the training process of the bill image authenticity classifier, enabling the bill image authenticity classifier to still maintain a high classification accuracy when under attack, significantly improving the robustness of the bill image authenticity recognition classifier. Even when the attacker uses adversarial samples, it can effectively identify the authenticity of the bill, thus enhancing the overall security and reliability of the bill anti-counterfeiting system.
[0097] To improve the robustness of the bill image authenticity recognition classifier against real-world attacks, in an optional implementation manner, the above-mentioned second training unit includes:
[0098] A training module, configured to attack the bill image authenticity recognition classifier based on the above-mentioned stacked perturbation projection gradient descent attack algorithm on the basis of the above-mentioned current adversarial sample in the above-mentioned next training cycle to generate the next adversarial sample, where the next adversarial sample is the adversarial sample generated in the above-mentioned next training cycle.
[0099] In the above embodiments, the adversarial examples generated in the previous training cycle are used as the input for the current training cycle. For the (i + 1)-th training cycle, the perturbation is initialized as the adversarial example of the previous cycle, which means that the accumulation of perturbations starts from the adversarial example of the previous cycle. Using the stacked perturbation projected gradient descent attack algorithm, a new perturbation increment is calculated to maximize the classification error of the bill image authenticity recognition classifier for the adversarial examples. The calculated perturbation increment is added to the current adversarial example to generate a new adversarial example. This process is called stacked perturbation because it adds a new perturbation on the basis of the adversarial example of the previous cycle. By using stacked perturbation in each round of training, the bill image authenticity recognition classifier can gradually adapt to and learn how to handle increasingly complex adversarial perturbations, thereby significantly enhancing its robustness against real-world attacks. By generating new adversarial examples by stacking perturbations in each round of training, not only does it accelerate the adversarial training process, but also continuously improves the classification accuracy of the bill image authenticity recognition classifier on adversarial examples, ensuring that in the bill authentication task, even in the face of carefully designed adversarial attacks, the bill image authenticity recognition classifier can maintain high robustness and generalization ability. This strategy is crucial for building a secure and reliable bill anti-counterfeiting recognition system.
[0100] To reduce the computational cost of adversarial training, in an alternative embodiment, the above training module includes:
[0101] A generation sub-module that generates the next adversarial example according to the first formula, where the first formula is represents the next adversarial example corresponding to the (i + 1)-th training cycle, A represents the stacked perturbation projected gradient descent attack algorithm, f i+1 represents the bill image authenticity recognition classifier of the (i + 1)-th training cycle, x represents the sample bill image data, y represents the reference label corresponding to the sample bill image data, represents the adversarial example generated in the i-th training cycle.
[0102] In the above embodiments, during the training process, by repeatedly using adversarial examples between training cycles, the attack intensity can accumulate cycle by cycle. According to the first formula, adversarial examples can be generated, and the adversarial examples can be transmitted across cycles through the above connection process, rather than starting from the sample bill image data. Therefore, a high attack intensity can be obtained faster. Compared with generating adversarial examples starting from the sample bill image data each time, the generation method based on stacked perturbation allows obtaining high-quality adversarial examples with fewer iterations and less time, reducing the computational cost of adversarial training.
[0103] To enhance transferability, in an alternative embodiment, the device further includes:
[0104] An update unit, configured to update the next adversarial sample to the current adversarial sample after updating the next training cycle to the current training cycle.
[0105] In the above embodiment, the adversarial sample obtained in the (i + 1)-th training cycle is saved for use in the next cycle (the (i + 2)-th training cycle), and then the adversarial sample is updated to the current adversarial sample to participate in training. The high transferability of adversarial samples between adjacent training cycles means that the adversarial samples generated in one training cycle are still effective in the next cycle. The step of updating the current adversarial sample helps to maintain and strengthen this transferability, enabling the bill image authenticity recognition classifier to learn more comprehensive and complex attack patterns during the training process.
[0106] To mitigate the impact of perturbations added in the early stage of training, in an alternative embodiment, the apparatus further includes:
[0107] A setting unit, configured to set a periodic reset perturbation strategy when updating the next training cycle to the current training cycle and repeating the above second training step at least once until before reaching a set number of reset perturbation cycles. The periodic reset perturbation strategy is to periodically superimpose adversarial perturbations starting from the sample bill image data every interval of the set number of reset perturbation cycles.
[0108] In the above embodiment, when adopting the adversarial training process of the present invention, new problems will also be introduced. An important problem is the drastic change in the parameters of the bill image authenticity recognition classifier in the early stage of training: Similar parameters between bill image authenticity recognition classifiers often lead to similar decision boundaries. Therefore, adversarial samples have high transferability between bill image authenticity recognition classifiers in adjacent cycles. However, the parameters of the bill image authenticity recognition classifier often change significantly in the early stage of training. Therefore, the adversarial perturbations added in the early cycles are often useless for subsequent cycles and may even weaken the transferability. To solve this problem, a simple but effective solution is adopted here: Set a periodic reset perturbation strategy. Every few training cycles, let the adversarial perturbations accumulate periodically starting from clean samples, so as to mitigate the impact of perturbations added in the early stage of training.
[0109] To improve the robustness of the bill image authenticity recognition classifier and the efficiency during the training process, in an alternative embodiment, the above second repeating unit further includes:
[0110] An optimization module, configured to optimize the adversarial training process of the bill image authenticity recognition classifier by using stochastic weight averaging and mixed precision.
[0111] In the above embodiments, during the training process of the present invention, stochastic weight averaging and mixed-precision acceleration calculation techniques are introduced. Stochastic Weight Averaging (SWA) aims to enforce weight smoothing by simply averaging multiple checkpoints along the training trajectory, and can be used to optimize weight updates during training. SWA can find a flatter solution than Stochastic Gradient Descent (SGD), and enable a single bill image authenticity recognition classifier to achieve an approximate ensemble effect. Moreover, it is simple to implement, improves the standard generalization ability, and introduces almost no extra computational cost. In the present invention, SWA is introduced into the adversarial training process to smooth the weights and find a flatter loss minimum, thereby improving the generalization ability of adversarial sample defense. Mixed-precision calculation selectively uses half-precision floating-point numbers for calculation, and using mixed-precision calculation when training a deep network can provide a significant acceleration effect for the training process.
[0112] The above-mentioned defense bill adversarial sample anti-counterfeiting attack device includes a processor and a memory. The above-mentioned acquisition unit, first training unit, second training unit, etc. are all stored in the memory as program units, and the corresponding functions are implemented by the processor executing the above-mentioned program units stored in the memory. The above-mentioned modules are all located in the same processor; or, the above-mentioned each module is located in different processors in any combination form.
[0113] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set, and by adjusting the kernel parameters, the problem that the accuracy of the bill recognition result is low due to the inability to accurately recognize the bill adversarial sample with added tiny perturbation noise points in the prior art can be solved.
[0114] The memory may include non-permanent memory in a computer-readable medium, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0115] The embodiment of the present invention provides a computer-readable storage medium. The above-mentioned computer-readable storage medium includes a stored program, wherein when the above-mentioned program runs, it controls the device where the above-mentioned computer-readable storage medium is located to execute the above-mentioned defense bill adversarial sample anti-counterfeiting attack method.
[0116] The embodiment of the present invention provides a processor. The above-mentioned processor is used to run a program, wherein when the above-mentioned program runs, it executes the above-mentioned defense bill adversarial sample anti-counterfeiting attack method.
[0117] An embodiment of the present invention provides a bill authenticity identification system. The bill authenticity identification system includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of at least a method for defending against counterfeiting attacks of bill adversarial samples.
[0118] Step S201, obtain sample bill image data;
[0119] Step S202, the first training step, based on the above sample bill image data, perform adversarial training on the bill image authenticity identification classifier using the superimposed perturbation projection gradient descent attack algorithm, and retain the current adversarial sample. The above current adversarial sample is the adversarial sample obtained in the current training cycle;
[0120] Step S203, the second training step, use the above current adversarial sample output in the current training cycle as the input of the bill image authenticity identification classifier in the next training cycle, and continue the above adversarial training on the bill image authenticity identification classifier based on the superimposed perturbation projection gradient descent attack algorithm, and retain the adversarial sample corresponding to the above next training cycle. The above next training cycle is the next training cycle adjacent to the above current training cycle;
[0121] Step S204, repeat the step, update the above next training cycle to the above current training cycle, and repeat the above second training step at least once until the number of the above current training cycle is a multiple of the set reset perturbation period number. The above set reset perturbation period number is the set number of the above training cycles;
[0122] Step S205, the testing step, test the bill image authenticity identification classifier based on a test set to obtain the classifier accuracy. The above test set includes the above sample bill image data and the sample bill authentication result corresponding to the above sample bill image data;
[0123] Step S206, in the case where the above classifier accuracy does not meet the accuracy requirement, adjust the parameters of the bill image authenticity identification classifier, and sequentially repeat the above first training step, the above second training step, the above repeating step, and the above testing step at least once until the set maximum iteration period is reached or the above classifier accuracy meets the above accuracy requirement. Determine the currently trained bill image authenticity identification classifier as the target bill image authenticity identification classifier. The above set maximum iteration period is greater than the above set reset perturbation period number;
[0124] Step S207, obtain the bill image data to be authenticated, and input the bill image data to be authenticated into the target bill image authenticity classifier to obtain a bill authentication result, and execute a corresponding disposal strategy on the bill according to the bill authentication result. The bill authentication result is one of the following: the bill image data to be authenticated is true and the bill image data to be authenticated is false.
[0125] The present application also provides a computer program product, which, when executed on a data processing device, is adapted to execute a program initialized with at least the following method steps:
[0126] Step S201, obtain sample bill image data;
[0127] Step S202, the first training step, perform adversarial training on the bill image authenticity recognition classifier based on the sample bill image data using the superimposed perturbation projection gradient descent attack algorithm, and retain the current adversarial sample, where the current adversarial sample is the adversarial sample obtained in the current training cycle;
[0128] Step S203, the second training step, use the current adversarial sample output in the current training cycle as the input of the bill image authenticity recognition classifier in the next training cycle, and continue to perform the above adversarial training on the bill image authenticity recognition classifier based on the superimposed perturbation projection gradient descent attack algorithm, and retain the adversarial sample corresponding to the next training cycle, where the next training cycle is the next training cycle adjacent to the current training cycle;
[0129] Step S204, repeat the steps, update the next training cycle to the current training cycle, and repeat the second training step at least once until the number of the current training cycle is a multiple of the set reset perturbation period number, where the set reset perturbation period number is a set number of the training cycles;
[0130] Step S205, the testing step, test the bill image authenticity recognition classifier based on a test set to obtain a classifier accuracy. The test set includes the sample bill image data and the corresponding sample bill authentication result of the sample bill image data;
[0131] Step S206, in the case where the classifier accuracy does not meet the accuracy requirement, adjust the parameters of the bill image authenticity recognition classifier, and sequentially repeat the first training step, the second training step, the repeating step, and the testing step at least once until the set maximum iteration period is reached or the classifier accuracy meets the accuracy requirement, and determine the currently trained bill image authenticity recognition classifier as the target bill image authenticity recognition classifier, where the set maximum iteration period is greater than the set reset perturbation period number;
[0132] Step S207: Obtain the image data of the bill to be authenticated, and input the above image data of the bill to be authenticated into the above target bill image authenticity classifier to obtain a bill authentication result, and execute a corresponding disposal strategy for the bill according to the above bill authentication result. The above bill authentication result is one of the following: the above image data of the bill to be authenticated is genuine and the above image data of the bill to be authenticated is fake.
[0133] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program code executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described herein can be executed in a different order, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.
[0134] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0135] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0136] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one flow or multiple flows and / or blocksFigure 1 The functions specified in one or more boxes.
[0137] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in one Figure 1 process or multiple processes and / or boxes Figure 1 or more boxes.
[0138] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0139] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0140] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0141] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, commodity or device comprising the element.
[0142] As can be seen from the above description, the above embodiments of the present application achieve the following technical effects:
[0143] 1), For the method for defending against counterfeiting attacks of bill adversarial samples in the present application, the key point of the technical solution of the present application is to utilize the high transferability of adversarial samples between the bill image authenticity recognition classifiers in adjacent training cycles, and an improved adversarial training method is proposed: an adversarial training method based on superimposed perturbation projection gradient descent attack. After the training of the i-th training cycle is completed, the obtained adversarial samples are saved as the starting point for generating adversarial samples in the (i + 1)-th training cycle. Then, in the (i + 1)-th training cycle, the bill image authenticity recognition classifier is attacked based on xi* to obtain the adversarial samples in the (i + 1)-th training cycle. At the same time, the adversarial samples obtained in the (i + 1)-th training cycle are saved for use in the next cycle, and training is iterated in this way. Every few training cycles (set the reset perturbation cycle number), let the adversarial perturbation accumulate periodically starting from the sample bill image data, so as to reduce the influence caused by the perturbation added in the early stage of training. The present application solves the problem in the prior art that it is impossible to accurately identify bill adversarial samples with tiny perturbation noise added, resulting in low accuracy of bill recognition results.
[0144] 2), For the device for defending against counterfeiting attacks of bill adversarial samples in the present application, after the training of the i-th training cycle is completed, the obtained adversarial samples are saved as the starting point for generating adversarial samples in the (i + 1)-th training cycle. Then, in the (i + 1)-th training cycle, the bill image authenticity recognition classifier is attacked based on xi* to obtain the adversarial samples in the (i + 1)-th training cycle. At the same time, the adversarial samples obtained in the (i + 1)-th training cycle are saved for use in the next cycle, and training is iterated in this way. Every few training cycles (set the reset perturbation cycle number), let the adversarial perturbation accumulate periodically starting from the sample bill image data, so as to reduce the influence caused by the perturbation added in the early stage of training. The present application solves the problem in the prior art that it is impossible to accurately identify bill adversarial samples with tiny perturbation noise added, resulting in low accuracy of bill recognition results.
[0145] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for defending against counterfeit attacks of bill adversarial samples, characterized in that: The method comprises: Obtain sample bill image data; In the first training step, adversarial training is performed on the bill image authenticity recognition classifier based on the superposition perturbation projection gradient descent attack algorithm according to the sample bill image data, and the current adversarial sample is retained, and the current adversarial sample is the adversarial sample obtained in the current training cycle; The second training step is to use the current adversarial sample outputted from the current training cycle as the input of the bill image authenticity recognition classifier in the next training cycle, continue to perform the adversarial training on the bill image authenticity recognition classifier based on the superposition perturbation projection gradient descent attack algorithm, and retain the adversarial sample corresponding to the next training cycle, where the next training cycle is the next training cycle adjacent to the current training cycle; Repeating step, updating the next training cycle to the current training cycle, repeating the second training step at least once, until the number of the current training cycle is a multiple of the set reset disturbance cycle number, and the set reset disturbance cycle number is the set number of training cycles; A testing step of testing the bill image authenticity recognition classifier based on a test set to obtain the classifier accuracy, wherein the test set includes the sample bill image data and the sample bill identification result corresponding to the sample bill image data; In the case where the accuracy of the classifier does not meet the accuracy requirement, the parameters of the bill image authenticity recognition classifier are adjusted, and the first training step, the second training step, the repeating step and the testing step are sequentially repeated at least once, until the set maximum iteration cycle is reached or the classifier accuracy meets the accuracy requirement, and the currently trained bill image authenticity recognition classifier is determined as the target bill image authenticity recognition classifier, and the set maximum iteration cycle is greater than the set reset disturbance cycle number; Obtain the image data of the bill to be identified, and input the image data of the bill to be identified into the target bill image authenticity classifier to obtain a bill identification result, so as to execute a corresponding disposal strategy for the bill according to the bill identification result, and the bill identification result is one of the following: the image data of the bill to be identified is true and the image data of the bill to be identified is false.
2. The method according to claim 1, characterized in that Before performing adversarial training on the bill image authenticity recognition classifier based on the superposition perturbation projection gradient descent attack algorithm according to the sample bill image data and retaining the current adversarial sample, the method further includes: Determine the objective function of the bill image authenticity recognition classifier, the expression of the objective function is arg min θ ·E(x, y)~D[max δ∈s L(f(x+δ, θ), y)], x represents the sample bill image data, y represents the reference label of the sample bill image data, D represents the data distribution of the sample bill image data x and the reference label y, L represents the internal maximization loss function, f represents the bill image authenticity classifier parameterized by θ, S represents the setting of the allowed perturbation space, δ represents the adversarial perturbation added to the sample bill image data, θ represents the parameters in the bill image authenticity recognition classifier, and E(x, y) represents the external minimization loss function; Determine the internal maximization loss function and the external minimization loss function of the bill image authenticity recognition classifier, wherein the expression of the internal maximization loss function is L(f(x+δ), y), L represents the internal maximization loss function, f represents the bill image authenticity classifier, x represents the sample bill image data, y represents the reference label of the sample bill image data, and the expression of the external minimization loss function is E(x, y)=BCE(f(x+δ), θ), y+λ·KL(f(x, θ)||f(x+δ, θ))·(1-p y (x, θ)), BCE represents enhanced cross entropy loss, p y (x, θ) represents the probability value that the bill image authenticity classifier predicts the sample bill image data x as the reference label y when the parameter is θ, KL represents the Kullback-Leibler divergence term, and λ represents an adjustable parameter.
3. The method according to claim 1, characterized in that The current adversarial sample outputted from the current training cycle is used as the input of the bill image authenticity recognition classifier in the next training cycle, and the adversarial training is continued on the bill image authenticity recognition classifier based on the superposition perturbation projection gradient descent attack algorithm, and the adversarial sample corresponding to the next training cycle is retained, including: In the next training cycle, based on the current adversarial sample, the bill image authenticity recognition classifier is attacked based on the superimposed perturbation projection gradient descent attack algorithm to generate the next adversarial sample, and the next adversarial sample is the adversarial sample generated in the next training cycle.
4. The method according to claim 3, characterized in that In the next training cycle, based on the current adversarial sample, the bill image authenticity recognition classifier is attacked based on the superposition perturbation projection gradient descent attack algorithm to generate the next adversarial sample, including: The next adversarial sample is generated according to a first formula, where the first formula is: represents the next adversarial sample corresponding to the i+1th training cycle, A represents the superposition perturbation projection gradient descent attack algorithm, and f i+1 represents the bill image authenticity recognition classifier of the i+1th training cycle, x represents the sample bill image data, y represents the reference label corresponding to the sample bill image data, Represents the adversarial sample generated in the i-th training cycle.
5. The method according to claim 3, characterized in that: After updating the next training cycle to the current training cycle, the method further includes: Update the next adversarial sample to the current adversarial sample.
6. The method according to claim 1, characterized in that Before updating the next training cycle to the current training cycle, repeating the second training step at least once until the set reset disturbance cycle number is reached, the method further includes: A periodic reset disturbance strategy is set, wherein the periodic reset disturbance strategy periodically superimposes the counteracting disturbance on the sample bill image data at intervals of the set reset disturbance cycle number.
7. The method according to claim 1, characterized in that Repeating the first training step, the second training step and the testing step at least once in sequence until a set maximum iteration cycle is reached or the classifier accuracy of the bill image authenticity recognition classifier meets the accuracy requirement, including: Random weight averaging and mixed precision are used to optimize the adversarial training process of the bill image authenticity recognition classifier.
8. A device for defending bills against sample anti-counterfeiting attacks, characterized in that: The device comprises: An acquisition unit, used for acquiring sample bill image data; A first training unit is used to execute a first training step, perform adversarial training on the bill image authenticity recognition classifier based on the superposition perturbation projection gradient descent attack algorithm according to the sample bill image data, and retain the current adversarial sample, where the current adversarial sample is the adversarial sample obtained in the current training cycle; A second training unit is used to perform a second training step, using the current adversarial sample outputted in the current training cycle as the input of the bill image authenticity recognition classifier in the next training cycle, continuing the adversarial training on the bill image authenticity recognition classifier based on the superposition perturbation projection gradient descent attack algorithm, and retaining the adversarial sample corresponding to the next training cycle, wherein the next training cycle is the next training cycle adjacent to the current training cycle; A first repeating unit is used to execute the repeating step, update the next training cycle to the current training cycle, and repeat the second training step at least once until the number of the current training cycle is a multiple of the set reset disturbance cycle number, and the set reset disturbance cycle number is the set number of training cycles; A testing unit, configured to execute a testing step, test the bill image authenticity recognition classifier based on a test set to obtain a classifier accuracy, wherein the test set includes the sample bill image data and a sample bill identification result corresponding to the sample bill image data; A second repeating unit is used for adjusting the parameters of the bill image authenticity recognition classifier when the accuracy of the classifier does not meet the accuracy requirement, and sequentially repeating the first training step, the second training step, the repeating step and the testing step at least once, until a set maximum iteration cycle is reached or the accuracy of the classifier meets the accuracy requirement, and determining the currently trained bill image authenticity recognition classifier as a target bill image authenticity recognition classifier, and the set maximum iteration cycle is greater than the set reset disturbance cycle number; An input unit is used to obtain the bill image data to be identified, and input the bill image data to be identified into the target bill image authenticity classifier to obtain a bill identification result, so as to execute a corresponding disposal strategy on the bill according to the bill identification result, and the bill identification result is one of the following: the bill image data to be identified is true and the bill image data to be identified is false.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 7.
10. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Bill anti-fake identification method based on main pattern fluorescent feature identification
CN107221070A
Automatic bill identifying and processing system based on bill map and system thereof
CN1967601A
Bill identification equipment and bill identification system
CN205862423U