Confrontation sample parameter selection method and system based on non-dominated sorting
Through the adversarial sample parameter selection method based on non-dominant sorting, the problem that traditional methods are difficult to balance in the aggressiveness and concealment is solved, and the rapid convergence and multi-solution output of adversarial sample parameters are achieved to meet the actual needs.
Patent Information
- Application Number
- CN202510343545.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-07-08
AI Technical Summary
Traditional adversarial sample parameter selection methods are difficult to balance aggression and concealment, and the generated adversarial samples are often too obvious or have poor attack effectiveness.
Adversarial sample parameter selection method based on non-dominant sorting is adopted, through non-dominant sorting and congestion calculation, combined with CFAR detector, it quickly converges to the Pareto frontier, outputs a set of Pareto optimal solutions, and selects a parameter combination that can balance the aggression and concealment.
It realizes rapid convergence of the selection of sample parameters, avoids local optimality, can effectively explore the parameter space, output multiple Pareto optimal solutions, and select to meet actual needs.
Smart Images

Figure CN120279286A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of intelligent optimization algorithms and image processing, and particularly to a method and system for selecting parameters of adversarial samples based on non-dominated sorting. Background Art
[0002] The generation of adversarial samples is an important research direction in the field of deep learning security. It generates adversarial samples that can deceive the target model by adding tiny perturbations to the original samples. Ideal adversarial samples need to strike a balance between aggressiveness (i.e., successfully deceiving the target model) and invisibility (i.e., the difference from the original samples is not easily noticeable). However, these two goals often conflict with each other. For example, increasing the perturbation size can improve the attack success rate but reduce the invisibility.
[0003] Traditional methods for selecting parameters of adversarial samples usually adopt a single-objective optimization strategy, such as only maximizing the attack success rate or minimizing the perturbation size. This method is difficult to balance between aggressiveness and invisibility, and the generated adversarial samples are often too obvious or have poor attack effects. Summary of the Invention
[0004] The purpose of the present invention is to provide a method and system for selecting parameters of adversarial samples based on non-dominated sorting, to solve the technical problem that traditional methods for selecting parameters of adversarial samples are difficult to balance between aggressiveness and invisibility, and the generated adversarial samples are often too obvious or have poor attack effects, to quickly converge to the Pareto front, improve the parameter selection efficiency; to effectively explore the parameter space and avoid falling into local optima; to output a set of Pareto optimal solutions, which can intuitively compare the performance of different parameter combinations in terms of aggressiveness and invisibility, and make selections according to actual needs.
[0005] To achieve the above purpose,
[0006] The technical solution of the present invention is as follows:
[0007] A method for selecting parameters of adversarial samples based on non-dominated sorting, comprising the following steps:
[0008] S1. Construct a system for selecting parameters of adversarial samples based on non-dominated sorting;
[0009] S2. The initialization module of the system for selecting parameters of adversarial samples based on non-dominated sorting randomly generates an initial population and determines the upper and lower bounds of the input parameters;
[0010] S3. The fitness module of the system for selecting parameters of adversarial samples based on non-dominated sorting determines the objective function and calculates the objective function values corresponding to each individual in the initial population;
[0011] S4. The non - dominated sorting module of the adversarial sample parameter selection system based on non - dominated sorting calculates the dominance relationship between individuals in the population according to the objective function values, and hierarchically sorts the individuals;
[0012] S5. The crowding degree calculation module of the adversarial sample parameter selection system based on non - dominated sorting calculates the density of each individual in its non - dominated layer;
[0013] S6. The evolution module of the adversarial sample parameter selection system based on non - dominated sorting updates the population individuals through selection, crossover and mutation operations to generate an offspring population;
[0014] S7. The elite retention module of the adversarial sample parameter selection system based on non - dominated sorting merges the current population and the offspring population, and selects excellent individuals through non - dominated sorting and crowding degree to form a new generation population;
[0015] S8. The termination judgment module of the adversarial sample parameter selection system based on non - dominated sorting judges whether to output the individuals corresponding to the Pareto front solution set in the current population according to the number of iterations;
[0016] S9. The CFAR detector module of the adversarial sample parameter selection system based on non - dominated sorting screens the perturbation parameters corresponding to the Pareto front solution set, and selects the critical parameters that can be detected by the CFAR detector to significantly generate adversarial attacks.
[0017] Further, the S2 includes the following steps:
[0018] S21. Taking the perturbation factor ε as the input, and determining that the upper bound of the perturbation factor ε is 0.3 and the lower bound is 0 according to the curve graph of the network recognition accuracy of AlexNet for the MSTAR dataset changing with the perturbation factor;
[0019] S22. Randomly generate an initial population P0 according to the upper and lower bounds of the perturbation factor ε
[0020] P0 = {x1, x2,...x i ,...x N}, i = 1,..., N
[0021] x i =(x max - x min )*rand(·)+x min
[0022] where, x i is an individual in the population, N is the population size, x max and x min are the upper and lower bounds of the perturbation factor ε respectively, and rand(·) is a uniform distribution function on (0, 1).
[0023] Further, S3 includes the following steps:
[0024] S31. Taking the recognition accuracy of the MSTAR dataset by the AlexNet network and the structural similarity between the image after being attacked by the generative adversarial attack and the original image as the objective function, and calculating the objective function value corresponding to each individual in the population;
[0025] S32. For the individual x in the population i , determining the corresponding objective function f1 according to the curve graph of the network recognition accuracy of the AlexNet for the MSTAR dataset changing with the perturbation factor;
[0026] S33. Calculating the structural similarity between the image after being attacked by the generative adversarial attack and the original image according to the structural similarity formula, that is, the objective function f2
[0027]
[0028] C1 = (K1L) 2 , K1 << 1
[0029] C2 = (K2L) 2 , K2 << 1
[0030] where μ x and μ y are the means of the image after being attacked by the generative adversarial attack and the original image respectively, and are the variances of the image after being attacked by the generative adversarial attack and the original image respectively, σ xy is the covariance between the two, and L is the dynamic range of the image grayscale.
[0031] Further, S4 includes the following steps:
[0032] S41. Let the population be P, which contains N individuals. For each individual x in the population i , calculating its domination individual number n i and the set S of individuals dominated by it i ,
[0033] If for two individuals x i and x j , the following is satisfied:
[0034]
[0035] Then it is said that x i dominates x j ,
[0036] The domination individual number n i: x i is dominated by how many individuals,
[0037] the dominated set S i : x i dominates which individuals;
[0038] S42. Stratify and sort the individuals.
[0039] Furthermore, the S42 includes the following steps:
[0040] S421. Initialize n of each individual to 0 and i = 0 and
[0041] S422. For each individual x i , traverse all individuals x in the population j ;
[0042] If x i dominates x j , then S i = S i ∪{x j},
[0043] If x j dominates x i , then n i = n i + 1;
[0044] S423. Take all individuals with n i = 0 as the first non-dominated layer F1;
[0045] S424. For each individual x in the first layer F1 i , update n of each individual in the set S i dominated by it. If n j = 0, then add it to the next non-dominated layer F2; j
[0046] S425. Repeat step S424 until all individuals are sorted into the corresponding layers.
[0047] Furthermore, the S5 includes the following steps:
[0048] S51. Let F i be the i-th non-dominated layer, and initialize the crowding degree d of each individual to 0; i = 0;
[0049] S52. For each objective function f k , sort the individuals in this layer according to the objective function value f k Sorting. For the sorted individuals, set the crowding degree of the boundary individuals to infinity. For non-boundary individuals, calculate their crowding degree d based on the differences in the objective function values of adjacent individuals. i :
[0050]
[0051] Among them, and are respectively the maximum and minimum values of the k-th objective function at this layer.
[0052] Furthermore, S6 includes the following steps:
[0053] S61. According to non-dominated sorting and crowding degree, use the tournament selection strategy to select the population, and give priority to individuals with a lower non-dominated sorting level during selection;
[0054] S62. If two individuals are in the same layer, select the individual with a larger crowding degree;
[0055] S63. After selection, generate new offspring through crossover and mutation operations.
[0056] Furthermore, S7 includes the following steps
[0057] S71. Combine the current population P t and the offspring population Q t to form a combined population R t ;
[0058] S72. Perform non-dominated sorting on R t and select the top N individuals according to the non-dominated level and crowding degree to form a new generation population P t+1 .
[0059] Furthermore, S9 includes the following steps:
[0060] S91. Multiply the perturbation factor corresponding to each individual in the Pareto front solution set by the perturbation matrix to obtain the final perturbation matrix, and add the perturbation matrix to the original image to obtain the generated adversarial image;
[0061] S92. Use the CFAR detector to detect each generated adversarial image to obtain the critical parameters when obvious generated adversarial attacks can be detected.
[0062] An adversarial sample parameter selection system based on non-dominated sorting, comprising:
[0063] An initialization module, used to randomly generate an initial population and determine the upper and lower bounds of input parameters; and
[0064] A fitness module, used to determine the objective function and calculate the objective function values corresponding to each individual in the initial population; and
[0065] A non-dominated sorting module, used to calculate the dominance relationship between individuals in the population according to the objective function values and perform hierarchical sorting on the individuals; and
[0066] A crowding degree calculation module, used to calculate the density of each individual in its non-dominated layer; and
[0067] An evolution module, used to perform selection, crossover, and mutation operations on the population individuals to generate an offspring population; and
[0068] An elite retention module, used to merge the current population and the offspring population, and select excellent individuals through non-dominated sorting and crowding degree calculation to form a new generation population; and
[0069] A termination judgment module, used to judge whether the maximum number of iterations is reached. If so, output the Pareto front solution set in the current population; and
[0070] A CFAR detector module, used to screen the perturbation parameters in the Pareto front solution set and select the critical parameters that can be detected by the CFAR detector when obvious generative adversarial attacks occur.
[0071] Adopting the above technical solutions, the present invention has the following advantages:
[0072] The present invention provides an adversarial sample parameter selection method and system based on non-dominated sorting. Based on the principle of non-dominated sorting, through iterative evolution, a set of parameter combinations that achieve a balance between attackability and stealth can be found. And by using the CFAR detector to select the critical parameters when obvious generative adversarial attacks are detected by the CFAR detector, it can quickly converge to the Pareto front, improve the parameter selection efficiency; can effectively explore the parameter space and avoid falling into local optima; can output a set of Pareto optimal solutions, which can intuitively compare the performance of different parameter combinations in terms of attackability and stealth, and make selections according to actual needs. Description of the Drawings
[0073] Figure 1 It is the logical structure diagram of the adversarial sample parameter selection system based on non-dominated sorting of the present invention;
[0074] Figure 2 It is the flowchart of the adversarial sample parameter selection method based on non-dominated sorting of the present invention;
[0075] Figure 3 It is a curve graph showing the change of the network recognition accuracy of AlexNet for the MSTAR dataset with the perturbation factor;
[0076] Figure 4 The curve graph corresponding to the Pareto front solution set of the present invention;
[0077] Figure 5 The generated sample graph when the CFAR detector of the present invention critically detects an obvious generated sample attack. Detailed implementation manner
[0078] The technical solution of the present invention will be specifically described below in conjunction with the accompanying drawings of the specification. It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device.
[0079] An adversarial sample parameter selection system based on non-dominated sorting, including an initialization module, a fitness module, a non-dominated sorting module, a crowding degree calculation module, an evolution module, an elite retention module, a termination judgment module and a CFAR detector module. The logical structure diagram between the modules is specifically as Figure 1As shown in the figure, the initialization module is responsible for constructing the initial search space of the algorithm, providing a starting point for the optimization process by randomly generating the initial population, and at the same time clarifying the value range of the input parameters and their upper and lower bound constraints, laying a foundation for the subsequent optimization process. The fitness module is responsible for the definition and calculation of the objective function. By evaluating the objective function values corresponding to each individual in the population, it provides a quantitative basis for the subsequent optimization selection. In terms of population evaluation, the non-dominated sorting module calculates the dominance relationship between population individuals, and hierarchically sorts all individuals using the non-dominated sorting principle to establish the non-dominated hierarchical structure of the population. On this basis, the crowding degree calculation module further evaluates the distribution density of each individual in its non-dominated layer, and maintains the diversity of the population by calculating the crowding distance between individuals, providing a basis for the screening of high-quality individuals. The evolutionary operation module is the core link for the algorithm to update the population. It iteratively optimizes individuals through genetic operations such as selection, crossover, and mutation. Among them, the selection operation is screened based on the fitness value and crowding degree of individuals, the crossover operation realizes the recombination of excellent genes, and the mutation operation introduces new gene characteristics, jointly promoting the population to evolve towards a better solution. The elite retention module ensures the retention of excellent individuals by merging the current population with the offspring population and performing non-dominated sorting and crowding degree calculation again, thus forming a new generation of population with higher fitness. The termination judgment module is responsible for monitoring the running state of the algorithm, and decides whether to terminate the algorithm by judging whether the current iteration number reaches the preset maximum iteration number. If the termination condition is reached, the Pareto front solution set in the current population is output; otherwise, the algorithm will continue to perform iterative optimization. The CFAR detector module performs secondary screening on the Pareto front solution set, and uses the constant false alarm rate detection technology to identify the critical parameters that can effectively generate adversarial attacks, providing a reliable basis for subsequent decision-making.
[0080] A method and system for selecting adversarial sample parameters based on non-dominated sorting are specifically as Figure 2 shown, including the following steps:
[0081] S1. Construct a system for selecting adversarial sample parameters based on non-dominated sorting, which includes an initialization module, a fitness module, a non-dominated sorting module, a crowding degree calculation module, an evolutionary module, an elite retention module, a termination judgment module, and a CFAR detector module.
[0082] S2. The initialization module of the system for selecting adversarial sample parameters based on non-dominated sorting randomly generates the initial population and determines the upper and lower bounds of the input parameters;
[0083] S2 specifically includes the following steps:
[0084] S21. Using the perturbation factor ε as the input, and according to the curve graph of the network recognition accuracy of the AlexNet for the MSTAR dataset changing with the perturbation factor, specifically asFigure 3 As shown, the upper bound of the perturbation factor ε is determined to be 0.3, and the lower bound is 0;
[0085] S22. Randomly generate the initial population P0 according to the upper and lower bounds of the perturbation factor ε
[0086] P0 = {x1, x2,... x i ,... x N}, i = 1,..., N
[0087] x i = (x max - x min ) * rand(·) + x min
[0088] where, x i is an individual in the population, N is the population size, x max and x min are the upper and lower bounds of the perturbation factor ε respectively, and rand(·) is a uniform distribution function on (0, 1).
[0089] S3. The fitness module of the adversarial sample parameter selection system based on non - dominated sorting determines the objective function and calculates the objective function value corresponding to each individual in the initial population;
[0090] S3 includes the following steps:
[0091] S31. Take the recognition accuracy of the AlexNet network for the MSTAR dataset and the structural similarity between the image after the generative adversarial attack and the original image as the objective function, and calculate the objective function value corresponding to each individual in the population;
[0092] S32. For the individual x i in the population, determine the corresponding objective function f1 according to the curve graph of the network recognition accuracy of the AlexNet for the MSTAR dataset changing with the perturbation factor;
[0093] S33. Calculate the structural similarity between the image after the generative adversarial attack and the original image according to the structural similarity formula, that is, the objective function f2
[0094]
[0095] C1 = (K1L) 2 , K1 << 1
[0096] C2 = (K2L) 2 , K2 << 1
[0097] where, μ x and μ yare the means of the image after being attacked by the generative adversarial attack and the original image, respectively, and are the variances of the image after being attacked by the generative adversarial attack and the original image, respectively, and σ xy is the covariance between the two, and L is the dynamic range of the image gray scale.
[0098] S4. The non-dominated sorting module of the adversarial sample parameter selection system based on non-dominated sorting calculates the dominance relationship between individuals in the population according to the objective function values and performs hierarchical sorting on the individuals;
[0099] S4 includes the following specific steps:
[0100] S41. Let the population be P, which contains N individuals. For each individual x i in the population, calculate its number of dominating individuals n i and the set S i of individuals dominated by it,
[0101] If for two individuals x i and x j , the following is satisfied:
[0102]
[0103] then it is said that x i dominates x j ,
[0104] The number of dominating individuals n i : How many individuals x i is dominated by,
[0105] The set S of dominated individuals i : Which individuals x i dominates;
[0106] S42. Perform hierarchical sorting on the individuals.
[0107] Among them, S42 includes the following specific steps:
[0108] S421. Initialize n i = 0 for each individual and
[0109] S422. For each individual x i , traverse all individuals x j in the population;
[0110] If x i dominates x j , then S i = S i ∪{x j},
[0111] If x j dominates x i , then n i = n i + 1;
[0112] S423. Take all individuals with n i = 0 as the first non - dominated layer F1;
[0113] S424. For each individual x i in the first layer F1, update the crowding degree n i of each individual in the set S j dominated by it. If n j = 0, then add it to the next non - dominated layer F2;
[0114] S425. Repeat step S424 until all individuals are sorted into the corresponding layers.
[0115] S5. The crowding degree calculation module of the adversarial sample parameter selection system based on non - dominated sorting calculates the density of each individual in its non - dominated layer;
[0116] The crowding distance is used to measure the density of each individual in its non - dominated layer. The larger the crowding distance of an individual, the sparser the surrounding individuals, and the more likely it is to be selected into the next generation.
[0117] S5 includes the following steps:
[0118] S51. Let F i be the i - th non - dominated layer, and initialize the crowding degree d i of each individual to 0;
[0119] S52. For each objective function f k , sort the individuals in this layer according to the objective function value f k . For the sorted individuals, set the crowding degree of the boundary individuals to infinity. For non - boundary individuals, calculate their crowding degree d i according to the difference in objective function values of adjacent individuals:
[0120]
[0121] where, and are the maximum and minimum values of the k - th objective function in this layer respectively.
[0122] S6. The evolution module of the adversarial sample parameter selection system based on non - dominated sorting updates the population individuals through selection, crossover and mutation operations to generate an offspring population;
[0123] Among them, S6 includes the following specific steps:
[0124] S61. According to non - dominated sorting and crowding degree, adopt the tournament selection strategy to select the population, and give priority to individuals with a lower non - dominated sorting level during selection;
[0125] S62. If two individuals are in the same layer, select the individual with a larger crowding degree;
[0126] S63. After the selection is completed, generate new offspring through crossover and mutation operations.
[0127] S7. The elitist retention module of the adversarial sample parameter selection system based on non - dominated sorting merges the current population and the offspring population output by the evolutionary module, and inputs them to the non - dominated sorting module and the crowding degree calculation module to select excellent individuals to form a new generation of population;
[0128] S7 includes the following steps
[0129] S71. Merge the current population P t and the offspring population Q t to form a combined population R t ;
[0130] S72. Perform non - dominated sorting on R t and select the top N individuals according to the non - dominated level and crowding degree to form a new generation of population P t+1 .
[0131] S8. The termination judgment module of the adversarial sample parameter selection system based on non - dominated sorting judges whether to output the individuals corresponding to the Pareto front solution set in the current population according to the number of iterations; specifically:
[0132] If the maximum number of iterations or other termination conditions are reached, output the Pareto front solution set in the current population; otherwise, repeat the above steps.
[0133] S9. The CFAR detector module of the adversarial sample parameter selection system based on non - dominated sorting screens the perturbation parameters corresponding to the Pareto front solution set, and selects the critical parameters that can be detected by the CFAR detector to significantly generate adversarial attacks.
[0134] S9 includes the following specific steps:
[0135] S91. Multiply the perturbation factor corresponding to each individual in the Pareto front solution set by the perturbation matrix to obtain the final perturbation matrix, and add the perturbation matrix to the original image to obtain the generated adversarial image;
[0136] S92. Use the CFAR detector to detect each generated adversarial image, and obtain the critical parameters when obvious generated adversarial attacks can be detected.
[0137] Finally, verify the method for selecting adversarial sample parameters based on non-dominated sorting of the present invention through simulation experiments. The present invention obtains the curve graphs of structural similarity and network recognition accuracy through the method for selecting adversarial sample parameters based on non-dominated sorting. This curve is the Pareto front solution set, specifically as Figure 4 shown , Use the CFAR detector to detect the Pareto front solution set, and obtain that the structural similarity of the generated sample when obvious generated sample attacks are critically detected is 0.388. At this time, the detection result is as Figure 5 shown, where Figure 5 (a) is the input image, Figure 5 (b) is the global CFAR result, Figure 5 (c) is the CFAR detection result. It can be Figure 4 seen that the recognition accuracy corresponding to the critical structural similarity is 74.0%. Then, based on this, it can be Figure 3 determined that the perturbation factor at the critical accuracy is 0.125. Therefore, the balance point between aggressiveness and stealth in the present invention is 0.125, that is, the optimal parameter selected by the present invention is the perturbation factor ε = 0.125.
[0138] Finally, it should be pointed out that although the present invention has been described with reference to the current specific embodiments, those of ordinary skill in the art in this technical field should recognize that the above embodiments are only used to illustrate the present invention, rather than to limit the present invention. Various equivalent changes or substitutions can be made without departing from the concept of the present invention. Therefore, as long as the changes and modifications of the above embodiments are within the scope of the spirit of the present invention, they will fall within the scope of the claims of the present invention.
Claims
1. An adversarial sample parameter selection method based on non-dominated sorting, characterized in that, It includes the following steps: S1. Construct an adversarial sample parameter selection system based on non-dominated sorting; S2. The initialization module of the adversarial sample parameter selection system based on non-dominated sorting randomly generates an initial population and determines the upper and lower bounds of the input parameters; S3. The fitness module of the adversarial sample parameter selection system based on non-dominated sorting determines the objective function and calculates the objective function values corresponding to each individual in the initial population; S4. The non-dominated sorting module of the adversarial sample parameter selection system based on non-dominated sorting calculates the dominance relationship between individuals in the population according to the objective function values and performs hierarchical sorting on the individuals; S5. The crowding degree calculation module of the adversarial sample parameter selection system based on non-dominated sorting calculates the density of each individual in its non-dominated layer; S6. The evolution module of the adversarial sample parameter selection system based on non-dominated sorting updates the population individuals through selection, crossover, and mutation operations to generate an offspring population; S7. The elite retention module of the adversarial sample parameter selection system based on non-dominated sorting merges the current population and the offspring population and selects excellent individuals through non-dominated sorting and crowding degree to form a new generation population; S8. The termination judgment module of the adversarial sample parameter selection system based on non-dominated sorting judges whether to output the individuals corresponding to the Pareto front solution set in the current population according to the number of iterations; S9. The CFAR detector module of the adversarial sample parameter selection system based on non-dominated sorting screens the perturbation parameters corresponding to the Pareto front solution set and selects the critical parameters that can be detected by the CFAR detector when obvious adversarial attacks are generated; 2. The method for selecting parameters of adversarial samples based on non-dominated sorting according to claim 1, wherein The said S2 includes the following steps: S21. Taking the perturbation factor ε as the input and determining that the upper bound of the perturbation factor ε is 0.3 and the lower bound is 0 according to the curve graph of the network recognition accuracy of the AlexNet for the MSTAR dataset changing with the perturbation factor; S22. Randomly generate the initial population P0 according to the upper and lower bounds of the perturbation factor ε P0 = {x1, x2,... x i ,... x N}, i = 1,..., N x i = (x max - x min ) * rand(·) + x min Among them, x i is an individual in the population, N is the population size, x max and x min are the upper and lower bounds of the perturbation factor ε respectively, and rand(·) is a uniform distribution function on (0, 1).
3. The method for selecting parameters of adversarial samples based on non-dominated sorting according to claim 2, wherein The said S3 includes the following steps: S31. Taking the recognition accuracy of the AlexNet network for the MSTAR dataset and the structural similarity between the image after being subjected to an adversarial attack and the original image as the objective function and calculating the objective function values corresponding to each individual in the population; S32. For an individual x in the population i , determine the corresponding objective function f1 according to the curve graph of the network recognition accuracy of the MSTAR dataset by AlexNet varying with the perturbation factor; S33. Calculate the structural similarity between the image after being subjected to an adversarial attack and the original image according to the structural similarity formula, that is, the objective function f2 C1 = (K1L) 2 , K1 << 1 C2 = (K2L) 2 , K2 << 1 Among them, μ x and μ y are the means of the image after being attacked by the generative adversarial attack and the original image respectively, and are the variances of the image after being attacked by the generative adversarial attack and the original image respectively, σ xy is the covariance between the two, and L is the dynamic range of the image grayscale.
4. A method for selecting adversarial sample parameters based on non-dominated sorting according to claim 3, characterized in that, The said S4 includes the following steps: S41. Let the population be P, which contains N individuals. For each individual x in the population i , calculate its number of dominating individuals n i and the set S of individuals dominated by it i , If for two individuals x i and x j , it holds that: Then x is said to be i dominant over x j , Number of dominating individuals n i : x i How many individuals it is dominated by The dominated set S i : x i dominates which individuals; S42. Perform hierarchical sorting on the individuals.
5. A method for selecting adversarial sample parameters based on non-dominated sorting according to claim 4, characterized in that The said S42 includes the following steps: S421. Initialize n of each individual i = 0 and S422. For each individual x i , traverse all individuals x in the population j ; If x i dominates x j , then S i = S i ∪ {x j}, If x j dominates x i , then n i = n i + 1; S423. Take all individuals with n i = 0 as the first non-dominated layer F1; S424. For each individual x in the first layer F1 i , update the set S of individuals dominated by it i for each individual's n in j , if n j = 0, then add it to the next non-dominated layer F2; S425. Repeat step S424 until all individuals are sorted into the corresponding levels.
6. The method for selecting adversarial sample parameters based on non-dominated sorting according to claim 5, characterized in that, The said S5 includes the following steps: S51. Let F i be the non-dominated layer of the i-th layer, and initialize the crowding degree d i of each individual to 0; S52. For each objective function f k , sort the individuals of this layer according to the objective function value f k . For the sorted individuals, set the crowding degree of the boundary individuals to infinity. For non-boundary individuals, calculate their crowding degree d i : Among them, and are respectively the maximum value and the minimum value of the k-th objective function at this layer.
7. A method for selecting parameters of adversarial samples based on non-dominated sorting according to claim 6, characterized in that, The said S6 includes the following steps: S61. According to non-dominated sorting and crowding degree, adopt the tournament selection strategy to select the population, and give priority to individuals with a lower non-dominated sorting level when selecting; S62. If two individuals are in the same layer, select the individual with a larger crowding degree; S63. After the selection is completed, generate new offspring through crossover and mutation operations.
8. A method for selecting adversarial sample parameters based on non-dominated sorting according to claim 7, characterized in that, The said S7 includes the following steps S71. Combine the current population P t and the offspring population Q t to form a combined population R t ; S72. For R t Perform non-dominated sorting on it, and select the top N individuals according to the non-dominated level and crowding degree to form a new generation of population P t+1 .
9. A method for selecting parameters of adversarial samples based on non-dominated sorting according to claim 8, characterized in that, The said S9 includes the following steps: For each individual in the Pareto front solution set, multiply the corresponding perturbation factor by the perturbation matrix to obtain the final perturbation matrix, and add the perturbation matrix to the original image to obtain the generated adversarial image; S92. Use a CFAR detector to detect each generated adversarial image to obtain the critical parameters when obvious generated adversarial attacks can be detected.
10. An adversarial sample parameter selection system based on non-dominated sorting, characterized in that, It includes: An initialization module for randomly generating an initial population and determining the upper and lower bounds of input parameters; And A fitness module for determining the objective function and calculating the objective function values corresponding to each individual in the initial population; And A non-dominated sorting module for calculating the dominance relationship between individuals in the population based on the objective function values and performing hierarchical sorting on the individuals; And A crowding degree calculation module for calculating the density of each individual in its non-dominated layer; And An evolution module for performing selection, crossover, and mutation operations on the population individuals to generate an offspring population; And An elite retention module for merging the current population with the offspring population and selecting excellent individuals through non-dominated sorting and crowding degree calculation to form a new generation population; And A termination judgment module for judging whether the maximum number of iterations is reached. If so, output the Pareto front solution set in the current population; And A CFAR detector module for screening the perturbation parameters in the Pareto front solution set and selecting the critical parameters when obvious generated adversarial attacks can be detected by the CFAR detector.