Security evaluation method and system for vehicle image classification algorithm
Through standardized interfaces and automated processes, multiple perturbation generation algorithms are integrated to generate perturbations that are difficult to detect by the human eye, which solves the shortcomings of security and robustness evaluation in the existing intelligent algorithm evaluation methods, and realizes efficient and comprehensive security evaluation, which is suitable for intelligent algorithms of different types and structures.
Patent Information
- Application Number
- CN202410033040.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
The existing intelligent algorithm evaluation methods mainly focus on performance indicators, neglecting safety and robustness, making it difficult to comprehensively evaluate the stability and security of the model in the face of various perturbations and abnormal situations. The evaluation process relies on a large amount of manual intervention and lacks a systematic framework.
It provides a safety assessment method and system for automotive image classification algorithms. Through standardized interfaces and automated processes, a variety of disturbance generation algorithms are integrated to generate disturbances that are difficult to detect by the human eye, simulate various environmental conditions, and conduct comprehensive safety assessments, including comprehensive considerations for combating samples and natural disturbances.
Improve evaluation efficiency and systematicity, fully cover various challenges faced by the algorithm, ensure the comprehensiveness and credibility of the evaluation results, and provide retraining opportunities to improve model performance.
Smart Images

Figure CN120279295A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a safety evaluation method and system for a vehicle image classification algorithm, belonging to the technical field of intelligent algorithm evaluation. Background Art
[0002] With the rapid development of artificial intelligence technology, intelligent algorithms have been widely used in various fields, such as autonomous driving, medical diagnosis, financial analysis, etc. The security and reliability of these algorithms have become key issues because their decisions directly affect the effectiveness and safety of practical applications.
[0003] Most intelligent algorithm evaluation methods focus on the performance indicators of the algorithm, such as accuracy, response time, etc., but often ignore the dimensions of security and robustness that are critical to practical applications. For example, when faced with deliberately designed input data (such as adversarial attacks), the algorithm may make wrong decisions, leading to serious security issues.
[0004] In addition, existing evaluation technologies often require a lot of manual participation when dealing with new or improved intelligent algorithms to customize test scripts and evaluation processes. This approach is not only inefficient, but also difficult to maintain consistency and comparability of evaluations, especially when evaluating algorithms of different types or structures.
[0005] Finally, there is no systematic framework for evaluating the security of deep learning models. Most existing evaluation methods focus on performance evaluation in specific aspects, but lack comprehensive consideration of model security. In this case, the evaluation results can only reflect local performance and cannot fully reflect the stability and security of the model in the face of various disturbances and abnormal situations. Therefore, the lack of a comprehensive and specific model security evaluation framework limits the comprehensiveness and credibility of the evaluation results.
[0006] In the development of intelligent algorithms, security evaluation has become a crucial area. This evaluation involves not only the response of intelligent algorithms to adversarial samples, but also their ability to handle natural disturbances. Adversarial samples are specially designed to mislead the input data of intelligent algorithms to produce incorrect outputs, which often look normal to human observers. At the same time, natural disturbances, such as severe weather conditions (e.g., fog, rain, snow), lighting changes (strong light or night), and environmental occlusion, are also key factors in testing the robustness of intelligent algorithms.
[0007] Taking autonomous driving as an example, adversarial examples may include subtle modifications to road signs, which are sufficient to mislead the algorithm and lead to incorrect interpretations of the sign meanings. Natural disturbances, such as fog or strong light, may also affect the performance of the vision system, making it difficult for the algorithm to correctly identify road signs or obstacles. These factors may all lead to misjudgments by the algorithm, thus triggering serious safety problems.
[0008] Chinese Patent CN202310723878.7 discloses an evaluation method for the adversarial robustness of a vision detection model, including: obtaining the vision detection model to be evaluated; using the Bidirectional Feature Distortion Attack (BFDA) method to generate an enhanced adversarial example dataset; evaluating the vision detection model according to the adversarial example dataset to obtain the evaluation result of the adversarial robustness of the vision detection model. It does not conduct a comprehensive security evaluation.
[0009] However, it is crucial to conduct a comprehensive security evaluation of intelligent algorithms, which includes a comprehensive consideration of adversarial examples and natural disturbances. Such an evaluation helps to ensure that the algorithm can maintain its robustness and reliability when facing the complexity and potential threats of the real world. Through such an evaluation, not only can the potential weaknesses of the algorithm be discovered, but also methods to optimize and enhance its ability to cope with these challenges can be found. Summary of the Invention
[0010] Object of the Invention: To overcome the deficiencies in the prior art, the present invention provides a method and system for evaluating the security of a vehicle-mounted image classification algorithm, which is not only applicable to intelligent algorithms of different types and structures, but can also specifically evaluate the security of the algorithm in addition to evaluating its functional indicators, and also aims to improve the efficiency of the evaluation process and the systematicness of the evaluation.
[0011] Technical Solution: To achieve the above object, the technical solution adopted by the present invention is as follows:
[0012] A method for evaluating the security of a vehicle-mounted image classification algorithm includes the following steps:
[0013] Step 1, Upload: Upload the vehicle-mounted image classification algorithm to be evaluated and upload the test data.
[0014] Step 2, Perform interface verification on the uploaded vehicle-mounted image classification algorithm and save the vehicle-mounted image classification algorithm that passes the interface verification.
[0015] Step 3, Perform data format verification on the test data and save the test data that passes the data format verification.
[0016] Step 4, Integration of multiple perturbation generation algorithms: Multiple perturbation generation algorithms are integrated to generate perturbations that are difficult for the human eye to detect and simulate various environmental conditions that the vehicle may encounter. The perturbation generation algorithms include black-box and white-box adversarial sample generation algorithms and natural perturbation generation algorithms. The integration of multiple perturbation generation algorithms includes an evaluation plan template library or a self-made template based on the integrated perturbation generation algorithms.
[0017] Step 5, Select specific perturbation generation algorithms and test data to generate perturbation samples.
[0018] Step 6, Conduct functional tests on the vehicle image classification algorithm to be evaluated using the test data and the corresponding generated perturbation samples to obtain the model security level.
[0019] Step 7, Obtain the model security level based on the model security level obtained in Step 6.
[0020] Preferably: Model security level:
[0021]
[0022] Among them, S represents the model security level, w i represents the weight of the i-th perturbation generation algorithm, N represents the number of types of selected perturbation generation algorithms, P original , i represents the performance index of the vehicle image classification algorithm to be evaluated on the test data set corresponding to the i-th perturbation generation algorithm, P perturbed , i represents the performance index of the vehicle image classification algorithm to be evaluated on the perturbation samples generated by the i-th perturbation generation algorithm.
[0023] Preferably: Model security level:
[0024]
[0025] Among them, F represents the model security level, and A, B, C, D, and E represent the specific security levels of the model.
[0026] Preferably: In Step 2, the interface verification includes model return interface verification, data preprocessing interface verification, data prediction interface verification, and loss calculation interface verification.
[0027] Preferably: The method for verifying the model return interface is as follows:
[0028] Step 211, Model instantiation: It is necessary to instantiate the user-defined algorithm class, and then obtain the model instance by calling the get_model() interface.
[0029] Step 212, Type Check: After obtaining the model instance, the next step is to perform a type check.
[0030] Step 213, Input / Output Verification: First, create a random input tensor whose shape is provided by the get_input_shape() interface. Then pass the random input to the model and obtain the output. Use the assert statement to check whether the second dimension of the output tensor matches the value returned by the get_num_classes() interface to verify that the output of the model conforms to the expected number of classes.
[0031] Preferably: The data preprocessing interface verification method is as follows:
[0032] Step 221, Input Data Preparation: Create a batch of data images containing multiple images based on the input shape defined by the get_input_shape() interface.
[0033] Step 222, Data Preprocessing: Call the user-defined preprocess_image() method to process the input image data.
[0034] Step 223, Type Verification: Use the assert statement to ensure that the data returned by the preprocess_image method is of the np.ndarray type.
[0035] Step 224, Data Shape Verification: Verify whether the shape of the processed image data conforms to the expectation. If the data shape does not match the expectation, an exception will be thrown.
[0036] Step 225, Value Range Verification: Ensure that the values of the processed image data are within the range returned by the get_value_range() interface.
[0037] Preferably: The data prediction interface verification method is as follows:
[0038] Step 231, Prediction Result Generation: Use the image data processed by the data preprocessing interface to call the predict() interface to generate the prediction result.
[0039] Step 232, Result Type Verification: Check whether the output is of the np.ndarray type through the assert statement.
[0040] Step 233, Output Shape Verification: Calculate the expected shape of the prediction result based on the batch size of the input data and the number of classes that the model should return. Then use the assert statement to check whether the actual shape of the output matches the expected shape.
[0041] Preferably: The loss calculation interface verification method is as follows:
[0042] Step 241, Model and Data Preparation: First, set the model to training mode model.train(). Then, convert the image data processed by the data preprocessing interface into a PyTorch tensor d and set the requires_grad attribute to True.
[0043] Step 242, Generate Labels and Calculate Loss: Randomly generate an integer array that matches the batch size as the true class label true. Use the true class label true and the preprocessed image data to call the get_loss() interface to calculate the loss value.
[0044] Step 243, Result Type Verification and Gradient Calculation: Verify whether the loss value loss is of the torch.Tensor type to ensure that the output format of the loss calculation is correct. Then, execute loss.backward(retain_graph=True) to calculate the gradient. If the gradient backpropagation cannot be correctly executed, indicating a problem with the loss calculation logic, an exception will be thrown for inspection.
[0045] Step 244, Gradient Existence and Shape Verification: First, confirm whether the grad attribute of the input tensor is None to ensure that the loss calculation logic is correctly connected to the computational graph. Then, ensure that the gradient shape matches the input image data.
[0046] Preferably, the file structure of the test data is as follows:
[0047]
[0048] Among them, data.zip represents the test data, class_names.txt represents the test data file name, and images represents the folder name of the test data submission image data. In the order of the classes, the image data should be correctly placed in subfolders named 0, 1, 2...
[0049] A safety evaluation system for a vehicle image classification algorithm, including an input unit, an interface verification unit, a data format verification unit, a storage unit, an integrated unit of multiple perturbation generation algorithms, a perturbation sample generation unit, a model safety degree determination unit, and a model safety level determination unit, where:
[0050] The input unit is used to upload the vehicle image classification algorithm to be evaluated and upload the test data.
[0051] The interface verification unit is used to perform interface verification on the uploaded vehicle image classification algorithm.
[0052] The data format verification unit is used to perform data format verification on the test data.
[0053] The storage unit is used to store the vehicle image classification algorithm verified through the interface and store the test data verified through the data format.
[0054] The multiple perturbation generation algorithm integration unit integrates multiple perturbation generation algorithms, which are used to generate perturbations that are difficult for the human eye to detect and simulate various environmental conditions that the vehicle may encounter.
[0055] The perturbation sample generation unit is used to generate perturbation samples according to the selected specific perturbation generation algorithm and test data.
[0056] The model security level determination unit is used to perform functional tests on the vehicle image classification algorithm to be evaluated through the test data and the corresponding generated perturbation samples, and obtain the model security level.
[0057] The model security grade determination unit is used to obtain the model security grade according to the obtained model security level.
[0058] Compared with the prior art, the present invention has the following beneficial effects:
[0059] 1. Standardized interface and automated process: In the present invention, by requiring the intelligent classification algorithm to provide a standardized interface and test data in a unified format, and verifying these interfaces and data, the need for manually customizing test scripts and evaluation processes is significantly reduced. This automated and standardized method improves the test efficiency and reduces the possibility of errors.
[0060] 2. Comprehensive and in-depth security evaluation: The present invention provides a comprehensive solution in terms of security evaluation. It not only considers the response ability of the algorithm to adversarial attacks, but also covers the impact of natural environment perturbations on the algorithm performance. This comprehensive method makes the evaluation not limited to a single dimension, but covers various challenges that the intelligent algorithm may face, ensuring the depth and breadth of the evaluation.
[0061] 3. Retraining opportunity to improve model performance: By saving the generated perturbation samples to the test database, the user can be provided with the opportunity to use these samples for model retraining. This not only helps to improve the model performance, but also facilitates the continuous optimization of the algorithm.
[0062] 4. Comprehensive and universal evaluation framework: The present invention proposes a systematic evaluation framework for the model security dimension, ensuring the comprehensiveness and universality of the evaluation results.
[0063] In summary, the present invention is applicable not only to different types and structures of intelligent algorithms, but also to specifically evaluate the security of algorithms in addition to their functional indicators, and also aims to improve the efficiency and systematicness of the evaluation process. Description of the Drawings
[0064] Figure 1 It is a flowchart of an embodiment. Detailed Embodiments
[0065] The present invention will be further clarified below in conjunction with the drawings and specific embodiments. It should be understood that these examples are only used to illustrate the present invention and not to limit the scope of the present invention. After reading the present invention, various equivalent modifications of the present invention by those skilled in the art fall within the scope defined by the appended claims of this application.
[0066] A method for evaluating the security of a vehicle image classification algorithm, which not only focuses on the response ability of the intelligent algorithm to adversarial samples, but also includes the ability to handle natural environment disturbances. The evaluation includes the performance tests of the algorithm under the perturbations generated by black-box and white-box adversarial attacks, as well as natural environment disturbances (such as rain, fog, snow, strong light or night environment, blur and occlusion situations). However, the current evaluation methods face the following limitations: First, most evaluation methods mainly focus on performance indicators (such as accuracy), while ignoring the dimensions of security and robustness that are crucial for practical applications; Second, when dealing with new or improved intelligent algorithms, existing evaluation technologies often require a large amount of manual intervention to customize test scripts and evaluation processes; Finally, the existing security evaluation methods have not formed a systematic framework, and the evaluation results often only reflect local performance and are difficult to comprehensively reflect the stability and security of the model in the face of various perturbations and abnormal situations. As Figure 1 shown, it specifically includes the following steps:
[0067] Step 1, Upload: Upload the vehicle image classification algorithm to be evaluated and upload the test data.
[0068] Step 2, To reduce the need for manual customization of test scripts and evaluation processes, the algorithm under test is required to provide a standardized interface, and the uploaded vehicle image classification algorithm is subjected to interface verification, and the vehicle image classification algorithm that passes the interface verification is saved. The interface verification includes model return interface verification, data preprocessing interface verification, data prediction interface verification, and loss calculation interface verification. The algorithm interface will be verified, and modification suggestions will be provided when the verification fails. If the verification is successful, the algorithm will be saved in the model library for subsequent test calls.
[0069] The method for verifying the model return interface is as follows:
[0070] Step 211, Model Instantiation: The user-defined algorithm class needs to be instantiated, and then the model instance is obtained by calling the get_model() interface. This step is the starting point of the entire verification process, ensuring that subsequent steps are based on the model provided by the user.
[0071] Step 212, Type Checking: After obtaining the model instance, type checking is performed next. Here, the assert statement is used to verify whether the model instance is of the torch.nn.Module type to ensure that the model follows the standard model structure of the PyTorch framework.
[0072] Step 213, Input and Output Verification: First, a random input tensor is created, and its shape is provided by the get_input_shape() interface. Then the random input is passed to the model, and the output is obtained. The assert statement is used to check whether the second dimension of the output tensor matches the value returned by the get_num_classes() interface to verify whether the output of the model meets the expected number of classes.
[0073] The verification method for the data preprocessing interface is as follows:
[0074] Step 221, Input Data Preparation: A batch of data images containing multiple images is created based on the input shape defined by the get_input_shape() interface.
[0075] Step 222, Data Preprocessing: The user-defined preprocess_image() method is called to process the input image data. This step is the core, converting the original image data into a format that the model can effectively process.
[0076] Step 223, Type Verification: The assert statement is used to ensure that the data returned by the preprocess_image method is of the np.ndarray type. This step ensures that the format of the preprocessed data meets the requirements of subsequent processing.
[0077] Step 224, Data Shape Verification: Verify whether the shape of the processed image data meets the expectations. The expected data shape is defined by the get_input_shape(). If the data shape does not match the expectations, an exception will be thrown.
[0078] Step 225, Value Range Verification: Ensure that the values of the processed image data are within the range returned by the get_value_range() interface. This step is to verify whether the preprocessing step correctly normalizes or adjusts the value range of the image data.
[0079] The verification method for the data prediction interface is as follows:
[0080] Step 231, Prediction Result Generation: Use the image data processed by the data preprocessing interface to call the predict() interface to generate the prediction result. This process simulates the process of the model processing the input data and generating the output in the actual running environment.
[0081] Step 232, Result Type Verification: Check whether the output is of the np.ndarray type through the assert statement. This step ensures that the data format of the prediction output is compatible with the subsequent processing flow.
[0082] Step 233, Output Shape Verification: Calculate the expected shape of the prediction result according to the batch size of the input data (i.e., the size of its first dimension) and the number of classes the model should return (get_num_classes). Then use the assert statement to check whether the actual shape of the output matches the expected shape. This verification ensures that the dimensions of the prediction result are correct, where the first dimension represents the batch size and the second dimension represents the class confidence.
[0083] The verification method of the loss calculation interface is as follows:
[0084] Step 241, Model and Data Preparation: First, set the model to the training mode model.train(). Then, convert the image data processed by the data preprocessing interface into a PyTorch tensor d and set the requires_grad attribute to True for subsequent gradient calculation.
[0085] Step 242, Generate Labels and Calculate Loss: Randomly generate an integer array that matches the batch size as the true class label true. Use the true class label true and the preprocessed image data to call the get_loss() interface to calculate the loss value. This step is the core because it involves the model's response to the actual data and the effectiveness of the loss calculation.
[0086] Step 243, Result Type Verification and Gradient Calculation: Verify whether the loss value loss is of the torch.Tensor type to ensure the correct output format of the loss calculation. Then, execute loss.backward(retain_graph=True) to calculate the gradient. If the gradient backpropagation cannot be correctly executed, indicating that there is a problem with the loss calculation logic, an exception will be thrown for inspection.
[0087] Step 244, Gradient Existence and Shape Verification: First, confirm whether the grad attribute of the input tensor is None to ensure that the loss calculation logic is correctly connected to the computational graph. Then ensure that the gradient shape matches the input image data. This step is to verify the correctness of the gradient calculation and its consistency with the input data.
[0088] The verification process for all interfaces is encapsulated within a try-except structure to capture and handle any potential exceptions. If any errors occur during the verification process, an error message will be printed and an exception will be thrown to ensure that prediction methods that do not meet the requirements are not accepted.
[0089] Step 3: Conduct data format verification on the test data and save the test data that passes the data format verification.
[0090] The test data uploaded by the user also needs to meet specific structural and format requirements for the system to read. Specifically, the user needs to submit a category label file and test image data according to the following requirements.
[0091] Requirements for the category file:
[0092] · A file named class_names.txt needs to be provided, with each line corresponding to an independent category. If the true category name is unknown, numbers can be used instead.
[0093] · The order of listing the categories must be consistent with the order of the model's prediction output.
[0094] · This file is used to confirm the total number of categories and it is necessary to ensure that the number of listed categories matches the number of output neurons of the model.
[0095] Requirements for the test data:
[0096] · The image data needs to be submitted in a folder named images. According to the order of the categories, the image data should be correctly placed in sub-folders named 0, 1, 2...
[0097] · For categories lacking test data, one can choose not to create the corresponding sub-folder or create an empty folder for it.
[0098] · It is necessary to ensure that all existing folders must be named with numbers from 0 to the total number of categories - 1, and ensure that the images within the folder belong to the category corresponding to the folder name.
[0099] · It is necessary to ensure that the image file format is.jpg,.jpeg, or.png. Both uppercase and lowercase formats are acceptable.
[0100] The file structure of the test data is as follows:
[0101]
[0102] Among them, data.zip represents the test data, class_names.txt represents the test data file name, and images represents the folder name of the test data submission image data. According to the order of the categories, the image data should be correctly placed in sub-folders named 0, 1, 2,....
[0103] The data that has passed the compliance check will be saved in the test database for subsequent use. In this way, the evaluation method can be applied to various intelligent algorithms, and at the same time, the design of the algorithm library and the database is convenient for the maintenance and management of the algorithms.
[0104] Step 4, integration of multiple perturbation generation algorithms: Integrate multiple perturbation generation algorithms to generate perturbations that are difficult for the human eye to detect and simulate various environmental conditions that a vehicle may encounter. The perturbation generation algorithms include black-box and white-box adversarial sample generation algorithms and natural perturbation generation algorithms. The integration of multiple perturbation generation algorithms includes the evaluation plan template library or self-made templates according to the integrated perturbation generation algorithms.
[0105] To solve the problem of single-dimensional evaluation of intelligent algorithms, the evaluation method proposed in this embodiment focuses on the security evaluation of the algorithms. Different from most evaluation methods that only focus on functional indicators, this embodiment considers the performance of intelligent algorithms under perturbed samples. Especially for vehicle-mounted intelligent algorithms, the evaluation will be carried out in multiple dimensions. The system integrates multiple perturbation generation algorithms, including black-box and white-box adversarial sample generation algorithms and natural perturbation generation algorithms. These algorithms can generate perturbations that are difficult for the human eye to detect and simulate various environmental conditions that a vehicle may encounter, such as rainy days, snowy days, foggy days, object occlusion, and changes in lighting conditions. Users can select predefined evaluation plans from the evaluation plan template library provided by the system or make self-made templates according to the integrated perturbation generation algorithms. Such a design enables the evaluation method to comprehensively test the multi-dimensional performance of vehicle-mounted intelligent algorithms. In addition, the generated perturbed samples will be saved in the test database, which is convenient for users to conduct secondary tests or use them for retraining the model to improve the model performance later.
[0106] Step 5, select specific perturbation generation algorithms and test data to generate perturbed samples.
[0107] Step 6, conduct functional tests on the vehicle-mounted image classification algorithm to be evaluated through the test data and the corresponding generated perturbed samples to obtain the degree of model security;
[0108] For the model security, an index called Performance Fluctuation Degree (PFD) is defined to describe the performance difference of the model between the original test data set and the new test data set with added perturbations. The calculation formula of the performance fluctuation degree is as follows:
[0109]
[0110] Among them, PFD represents the degree of performance fluctuation of the model, and P original represents the performance metric of the model on the original test dataset, and P perturbed represents the performance metric of the model on the new test dataset with added perturbations.
[0111] To comprehensively evaluate the security of the model, the present invention comprehensively considers the performance fluctuations under various perturbation conditions, and the formula is as follows:
[0112]
[0113] Furthermore, we get:
[0114]
[0115] Among them, S represents the degree of model security, and w i represents the weight of the i-th perturbation generation algorithm, N represents the number of types of selected perturbation generation algorithms, and P original , i represents the performance metric of the vehicle image classification algorithm to be evaluated on the test dataset corresponding to the i-th perturbation generation algorithm, and P perturbed , i represents the performance metric of the vehicle image classification algorithm to be evaluated on the perturbation samples generated by the i-th perturbation generation algorithm.
[0116] Step 7, obtain the model security level according to the degree of model security obtained in step 6:
[0117]
[0118] Among them, F represents the model security level, and A, B, C, D, and E represent the specific security levels of the model.
[0119] The description of the security level is as follows:
[0120] Level A (superior level): When the external environment is perturbed or faced with unfriendly inputs, the model can autonomously maintain a high level of stability and security. Even under extreme conditions, it can effectively complete the task as expected, ensuring that the accuracy and reliability of the algorithm results are not affected.
[0121] Level B (robust level): When the external environment is perturbed or faced with unfriendly inputs, although the model shows certain performance fluctuations, it can still maintain good performance and high stability.
[0122] Level C (Adaptable Level): When there are disturbances in the external environment or when facing unfriendly inputs, the performance of the model may decline, but it can still adapt well to these changes and complete tasks as expected, without having a significant impact on the algorithm results.
[0123] Level D (Challenging Level): When there are disturbances in the external environment or when facing unfriendly inputs, the performance of the model may decline significantly, which may have a greater impact on the algorithm results.
[0124] Level E (Risky Level): When there are disturbances in the external environment or when facing unfriendly inputs, the performance of the model may decline significantly, which may have a serious impact on the algorithm results and it is difficult to work as expected, showing high risks.
[0125] This embodiment ensures the standardization of the algorithm interface: In order to evaluate any algorithm, the present invention has standardized requirements for the algorithm interface, and users need to provide it according to the specifications of the present invention, and it will be automatically verified later.
[0126] Standardization of data format: Similarly, in order to test any data, the present invention has standardized requirements for the structure and format of the test data, and users need to provide it according to the specifications of the present invention, and it will be automatically verified later.
[0127] Integration of multiple perturbation generation algorithms: In order to achieve comprehensive security evaluation, the system integrates multiple perturbation generation algorithms, including black-box and white-box adversarial sample generation algorithms and natural perturbation generation algorithms, enabling the evaluation method to comprehensively test the multi-dimensional performance of vehicle intelligent algorithms.
[0128] Evaluation plan template library: Provides an evaluation plan template library. Users can choose predefined evaluation plans or create templates according to the integrated perturbation generation algorithms, enhancing the flexibility and applicability of the evaluation method.
[0129] Innovative evaluation framework: A systematic evaluation framework is proposed for the model security dimension, ensuring the comprehensiveness and universality of the evaluation results.
[0130] A security evaluation system for a vehicle image classification algorithm includes an input unit, an interface verification unit, a data format verification unit, a storage unit, a multiple perturbation generation algorithm integration unit, a perturbation sample generation unit, a model security degree determination unit, and a model security level determination unit, where:
[0131] The input unit is used to upload the vehicle image classification algorithm to be evaluated and upload the test data.
[0132] The interface verification unit is used to perform interface verification on the uploaded vehicle image classification algorithm.
[0133] The data format verification unit is used to verify the data format of the test data.
[0134] The storage unit is used to save the vehicle image classification algorithm verified through the interface and save the test data verified through the data format.
[0135] The multiple perturbation generation algorithm integration unit integrates multiple perturbation generation algorithms, which are used to generate perturbations that are difficult for the human eye to detect and simulate various environmental conditions that the vehicle may encounter.
[0136] The perturbation sample generation unit is used to generate perturbation samples according to the selected specific perturbation generation algorithm and test data.
[0137] The model security level determination unit is used to perform functional tests on the vehicle image classification algorithm to be evaluated through the test data and the corresponding generated perturbation samples, and obtain the model security level.
[0138] The model security grade determination unit is used to obtain the model security grade according to the obtained model security level.
[0139] This embodiment provides a new and effective perspective for evaluating the stability and security of deep learning algorithms. By introducing a set of standardized and comprehensive test processes and evaluation criteria, it effectively solves the deficiencies of existing evaluation methods in terms of security and robustness. First, standardize the interfaces of algorithms and data to reduce manual intervention and improve test efficiency; second, by integrating multiple perturbation generation algorithms, the present invention not only considers conventional performance indicators, but also attaches more importance to the performance of algorithms under various environmental perturbations, thus ensuring the comprehensiveness and in-depthness of the evaluation; finally, a systematic security evaluation framework is proposed, and the present invention ensures the comprehensiveness and universality of the evaluation results. The flowchart of the overall solution is as Figure 1 shown. This flowchart clearly shows each key step of the evaluation method, thus providing users with an intuitive and easy-to-understand overview of the evaluation process.
[0140] This embodiment aims to solve several core problems in the field of safety evaluation of vehicle intelligent algorithms: Firstly, it is to improve the adaptability and flexibility of the evaluation method for different types and structures of intelligent algorithms; Secondly, it is to achieve a high degree of automation in the evaluation process and reduce the need for manual intervention; Then, it is to solve the problem of single-dimensional evaluation by expanding the evaluation focus to not only include the functional indicators of the algorithm, such as accuracy, but more importantly, to evaluate the robustness and generalization ability of the algorithm in the face of potential attacks; Finally, this embodiment proposes a brand-new and comprehensive safety evaluation framework, aiming to provide a unified and efficient safety evaluation framework for various vehicle intelligent algorithms through a fully automated evaluation method. It not only improves the efficiency and accuracy of the evaluation, but also ensures the universality and scalability of the method, thus solving the deficiencies of the existing evaluation methods in terms of adaptability, automation, and multi-dimensional evaluation.
[0141] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A safety evaluation method for a vehicle image classification algorithm, characterized in that It includes the following steps: Step 1, Upload: Upload the vehicle image classification algorithm to be evaluated and upload the test data; Step 2, Interface verification of the uploaded vehicle image classification algorithm, and save the vehicle image classification algorithm that passes the interface verification; Step 3, Data format verification of the test data, and save the test data that passes the data format verification; Step 4, Integration of multiple perturbation generation algorithms: Integrate multiple perturbation generation algorithms, which are used to generate perturbations that are difficult for the human eye to detect and simulate various environmental conditions that the vehicle may encounter. The perturbation generation algorithms include black-box and white-box adversarial sample generation algorithms and natural perturbation generation algorithms; The integration of multiple perturbation generation algorithms includes an evaluation plan template library or a self-made template according to the integrated perturbation generation algorithms; Step 5, Select a specific perturbation generation algorithm and test data to generate perturbation samples; Step 6, Conduct functional testing on the vehicle image classification algorithm to be evaluated through the test data and the corresponding generated perturbation samples to obtain the model security level; Step 7, Obtain the model security level according to the model security level obtained in Step 6.
2. The safety evaluation method for the vehicle image classification algorithm according to claim 1, wherein: Model security level: Among them, S represents the degree of model security, w i represents the weight of the i-th perturbation generation algorithm, represents the number of types of perturbation generation algorithms selected, P original , i represents the performance index of the vehicle image classification algorithm to be evaluated on the test data set corresponding to the i-th perturbation generation algorithm, P perturbed , i represents the performance index of the vehicle image classification algorithm to be evaluated on the perturbation samples generated by the i-th perturbation generation algorithm.
3. The safety evaluation method for the vehicle-mounted image classification algorithm according to claim 2, characterized in that: Model security level: Among them, F represents the model security level, and A, B, C, D, and E represent the specific security levels of the model.
4. The safety evaluation method of the vehicle-mounted image classification algorithm according to claim 3, characterized in that: The interface verification in Step 2 includes model return interface verification, data preprocessing interface verification, data prediction interface verification, and loss calculation interface verification.
5. The safety evaluation method for the vehicle-mounted image classification algorithm according to claim 4, characterized in that: The method for verifying the model return interface is as follows: Step 211, Model instantiation: It is necessary to instantiate the algorithm class defined by the user, and then obtain the model instance by calling the get_model() interface; Step 212, Type check: After obtaining the model instance, the next step is to perform a type check; Step 213, Input and output verification: First, create a random input tensor, the shape of which is provided by the get_input_shape() interface; Then pass the random input to the model and obtain the output; Use the assert statement to check whether the second dimension of the output tensor matches the value returned by the get_num_classes() interface to verify whether the output of the model meets the expected number of classes.
6. The safety evaluation method for the vehicle-mounted image classification algorithm according to claim 5, characterized in that: The method for verifying the data preprocessing interface is as follows: Step 221, Input data preparation: Create a batch of data images containing multiple images based on the input shape defined by the get_input_shape() interface; Step 222, Data preprocessing: Call the user-defined preprocess_image() method to process the input image data; Step 223, Type verification: Use the assert statement to ensure that the data returned by the preprocess_image method is of the np.ndarray type; Step 224, Data shape verification: Verify whether the shape of the processed image data meets the expectation; If the data shape does not match the expectation, an exception will be thrown; Step 225, Value range verification: Ensure that the values of the processed image data are within the range returned by the get_value_range() interface.
7. The safety evaluation method for the vehicle-mounted image classification algorithm according to claim 6, characterized in that: The method for verifying the data prediction interface is as follows: Step 231, Prediction Result Generation: Use the image data processed by the data preprocessing interface to call the predict() interface to generate a prediction result; Step 232, Result Type Verification: Check whether the output is of the np.ndarray type through the assert statement; Step 233, Output Shape Verification: Calculate the expected shape of the prediction result based on the batch size of the input data and the number of categories that the model should return; then use the assert statement to check whether the actual shape of the output matches the expected shape.
8. The safety evaluation method for the vehicle image classification algorithm according to claim 7, characterized in that: The method for verifying the loss calculation interface is as follows: Step 241, Model and Data Preparation: First, set the model to the training mode model.train(); then, convert the image data processed by the data preprocessing interface into a PyTorch tensor d and set the requires_grad attribute to True; Step 242, Generate Labels and Calculate Loss: Randomly generate an integer array that matches the batch size as the true class label true; use the true class label true and the preprocessed image data to call the get_loss() interface to calculate the loss value; Step 243, Result Type Verification and Gradient Calculation: Verify whether the loss value loss is of the torch.Tensor type to ensure that the output format of the loss calculation is correct; Then, execute loss.backward(retain_graph=True) to calculate the gradient; If the gradient backpropagation cannot be correctly executed, indicating that there is a problem with the loss calculation logic, an exception prompt will be thrown for inspection; Step 244, Gradient Existence and Shape Verification: First, confirm whether the grad attribute of the input tensor is None to ensure that the loss calculation logic is correctly connected to the computational graph; then ensure that the gradient shape matches the input image data.
9. The safety evaluation method for the vehicle image classification algorithm according to claim 8, characterized in that: The file structure of the test data is as follows: Among them, data.zip represents the test data, class_names.txt represents the test data file name, images represents the folder name of the test data submission image data. In the order of the categories, the image data should be correctly placed in subfolders named 0, 1, 2...
10. A safety evaluation system for a vehicle image classification algorithm, characterized in that: Including an input unit, an interface verification unit, a data format verification unit, a storage unit, a multi-disturbance generation algorithm integration unit, a disturbance sample generation unit, a model security degree determination unit, and a model security level determination unit, where: The input unit is used to upload the vehicle image classification algorithm to be evaluated and upload the test data; The interface verification unit is used to perform interface verification on the uploaded vehicle image classification algorithm; The data format verification unit is used to perform data format verification on the test data; The storage unit is used to save the vehicle image classification algorithm that passes the interface verification and save the test data that passes the data format verification; The multi-disturbance generation algorithm integration unit integrates multiple disturbance generation algorithms, which are used to generate disturbances that are difficult for the human eye to detect and simulate various environmental conditions that the vehicle may encounter; The perturbation sample generation unit is used to generate perturbation samples according to the selected specific perturbation generation algorithm and test data; The model security level determination unit is used to perform a functional test on the vehicle image classification algorithm to be evaluated through the test data and the corresponding generated perturbation samples, and obtain the model security level; The model security level determination unit is used to obtain the model security level according to the obtained model security level.
Citation Information
Patent Citations
A method and apparatus for evaluating the adversarial robustness of a visual detection model
CN116468977B