General targeted attack resisting method for gesture recognition system aiming at sound wave perception

By generating and optimizing disturbance signals, targeted attacks are carried out against the sound wave-aware gesture recognition system, which solves the system's security vulnerabilities and improves the model's ability to fight attacks, and is suitable for scenarios such as smart homes and smart driving.

CN120296418AActive Publication Date: 2025-07-11SHENZHEN UNIV
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202510364546.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-07-11
Estimated Expiration
2045-03-26

AI Technical Summary

Technical Problem

The existing sound wave-aware gesture recognition system has security vulnerabilities, and attackers can interfere with gesture recognition by creating physically achievable adversarial audio signals, resulting in misclassification and lack of effective targeted attack solutions.

Method used

A general targeted adversarial attack method for acoustic wave-aware gesture recognition system is designed. By constructing an objective function, optimizing perturbation signals, using particle swarm algorithm to generate perturbation vectors, generating adversarial samples, and training gesture classification models to improve their adversarial attack capabilities.

Benefits of technology

It realizes that input gesture errors are classified into attackers in the sound wave-aware gesture recognition system, revealing the system's security vulnerabilities and improving the model's ability to fight attacks, and is suitable for fields such as smart homes and smart driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296418A_ABST
    Figure CN120296418A_ABST
Patent Text Reader

Abstract

The invention discloses a universal targeted attack resisting method for a gesture recognition system aiming at sound wave sensing. The method comprises the steps that a target function is constructed based on confidence score maximization of confrontation signals in a target gesture category, and the confrontation signals comprise original signals and disturbance signals; solving the objective function to obtain an optimized disturbance vector and an optimized disturbance signal; and generating a confrontation sample based on the optimized disturbance signal, wherein the confrontation sample is used for training the attack confrontation capability of the target gesture classification model. According to the method, the confrontation sample can be constructed, so that the input gesture is wrongly classified into a category predetermined by an attacker, the security vulnerability problem in a sound wave sensing gesture recognition system is revealed, and the attack confrontation capability of the sound wave sensing gesture recognition system is improved by training the gesture classification model in a targeted manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of anti-attack technology, and more specifically, to a universal targeted anti-attack method for a gesture recognition system for sound wave perception. Background Art

[0002] Acoustic-based Human Gesture Recognition (HGR) systems are widely used in smart home, vehicle control and other scenarios due to their hardware versatility and non-intrusiveness. These systems generally rely on deep neural networks (DNNs) as classification models, and the inherent adversarial vulnerabilities of deep neural networks make the systems vulnerable to malicious audio attacks.

[0003] Existing acoustic-based gesture recognition systems follow a typical three-stage process: capturing raw acoustic signals with a microphone; preprocessing the signals to extract gesture-related features; and using deep neural networks to map the extracted features to various gestures. Figure 1 It is a typical framework of gesture recognition system based on sound wave perception. When the user waves his hand near the microphone to write in the air, the sound signal received by the microphone is composed of the sound directly emitted by the speaker, the signal reflected by the hand, and the signal reflected by the surrounding environment. Considering that the close environment does not change much during the gesture recognition process, the signal other than the hand reflection is basically consistent with the wave source frequency, so the hand movement can be inferred by the Doppler effect of the hand reflection signal. A common practice is to extract the signal with a filter, transform this part of the signal into a time-frequency spectrum through short-time Fourier transform, and then learn the characteristics of the spectrum through a deep learning model and classify it.

[0004] However, existing research has not considered the possible security vulnerabilities of these acoustic-based gesture recognition methods and their systems. The security vulnerability here means that for the acoustic wave perception gesture recognition system, an attacker can create a physically feasible adversarial example, such as an audio recording of ultrasonic waves. In the process of the acoustic wave perception gesture recognition system, the acoustic wave data is collected through the air and can be maliciously injected for interference. When the system is working, the attacker plays the adversarial audio at the same time, so that the gesture signal superimposed with the adversarial audio will be misclassified into other categories.

[0005] After analysis, it is found that there is currently no general and targeted adversarial attack scheme directly targeting the sound wave perception gesture recognition system. Therefore, it is necessary to improve the existing technology to compensate for the potential security risks caused by the inherent adversarial vulnerabilities of deep neural networks in the sound wave modality. Summary of the invention

[0006] The object of the present invention is to overcome the defects of the above-mentioned prior art and provide a general targeted adversarial attack method for a gesture recognition system for acoustic wave perception. The method includes the following steps:

[0007] Based on the goal of maximizing the confidence score of the adversarial signal in the target gesture category, construct an objective function, where the adversarial signal includes an original signal and a perturbation signal;

[0008] Solve the objective function to obtain an optimized perturbation vector and an optimized perturbation signal;

[0009] Generate an adversarial sample based on the optimized perturbation signal for training the ability of the target gesture classification model to resist adversarial attacks.

[0010] Compared with the prior art, the advantages of the present invention are that the present invention designs a new general targeted adversarial attack method, which can interfere with the system through physically realizable adversarial samples, making the input gesture be misclassified into the category predetermined by the attacker, revealing the security vulnerability problem in the acoustic wave perception gesture recognition system, and then improving its ability to resist adversarial attacks by training the gesture classification model in a targeted manner.

[0011] Through the following detailed description of the exemplary embodiments of the present invention with reference to the accompanying drawings, other features and advantages of the present invention will become clear. Description of the Drawings

[0012] The drawings incorporated in the specification and constituting a part of the specification illustrate embodiments of the present invention and, together with the description, are used to explain the principles of the present invention.

[0013] Figure 1 is a framework diagram of a typical acoustic wave perception-based gesture recognition system in the prior art;

[0014] Figure 2 is a schematic diagram of a potential adversarial attack scenario for an acoustic wave perception-based gesture recognition system according to an embodiment of the present invention;

[0015] Figure 3 is an overall attack flow chart according to an embodiment of the present invention;

[0016] Figure 4 is a flow chart of a general targeted adversarial attack method for an acoustic wave perception-based gesture recognition system according to an embodiment of the present invention;

[0017] Figure 5 is a schematic diagram of generating a perturbation signal from a perturbation vector according to an embodiment of the present invention;

[0018] Figure 6It is a schematic diagram of the overall process of a general targeted adversarial attack method for gesture recognition systems based on acoustic wave perception according to an embodiment of the present invention. Detailed implementation manners

[0019] Now, various exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. It should be noted that: Unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions, and numerical values set forth in these embodiments do not limit the scope of the present invention.

[0020] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way a limitation on the present invention or its application or use.

[0021] Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the said technologies, methods, and devices should be regarded as part of the specification.

[0022] In all the examples shown and discussed herein, any specific values should be construed as merely exemplary and not as a limitation. Thus, other examples of the exemplary embodiments may have different values.

[0023] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.

[0024] The present invention provides a general and targeted adversarial attack method for acoustic wave perception gesture recognition systems. When some basic information of the attacked system is known (such as the ultrasonic frequency emitted by the acoustic wave gesture recognition system, the type of spectrum recognized, and the type of gesture, etc.), a perturbation signal required by the attacker can be generated. When injecting this signal, no matter what gesture the attacked person is writing, it will be recognized as the target gesture that the attacker wants the model to recognize.

[0025] For example, the process of generating the perturbation signal includes: converting an initialized random perturbation vector into a perturbation signal using a perturbation signal generation method; superimposing the perturbation signal on the original signal. If the result recognized by the classifier (or gesture classification model, gesture recognition model) is not the category expected by the attacker, the particle swarm algorithm is used to optimize the perturbation vector; the optimized vector is superimposed again and classified, and the vector is iteratively optimized until the upper limit of the optimization times is reached or the superimposed adversarial signal is successfully classified as the category expected by the attacker.

[0026] The generated perturbation signal will be saved in audio format and wait to be played or injected during the attack. A carefully designed perturbation signal may cause misclassification of the classifier, and these potential vulnerabilities may be exploited, leading to serious accidents. For example, in Figure 2In the scenario shown, the user in the car attempts to hang up the phone through an air-sensing gesture recognition system. An attacker can play a perturbation signal through a pre-arranged device or inject a perturbation signal using the microphone permission to deceive the system, causing the system to misclassify the gesture as increasing the volume or even accelerating the vehicle. Another example is in a smart home, where the user wants to turn on the light through a gesture, but the attacker injects a malicious signal, resulting in it possibly being classified as "opening the door" or "turning on the gas". These are all potential security vulnerabilities that the present invention aims to reveal.

[0027] An attack can create physically realizable adversarial examples, enabling the attacker to deceive the system into classifying any input gesture as a specific target class, regardless of the gesture class actually made by the attacked user. To reveal the security vulnerabilities against a sound-wave sensing gesture recognition system, the present invention provides an effective perturbation generation method, which can penetrate the non-differentiable time-frequency transformation process and solve the inconsistency problem between the perturbation space (one-dimensional signal) and the classifier input space (two-dimensional time-frequency spectrogram). Moreover, a particle swarm optimization algorithm with linearly decreasing weights is adopted, combined with an iterative method to update the general perturbation vectors of different target samples, thereby optimizing the perturbation signal. Finally, the required perturbation signal is obtained and saved for constructing adversarial samples.

[0028] Figure 3 This is the overall attack process, including: the user makes a gesture, and the attacker simultaneously superimposes a sound wave; the attacked system preprocesses the collected sound wave; the system puts the preprocessed data into the model for classification; and the result expected by the attacker is output.

[0029] For the general attack process, the present invention provides a general targeted adversarial attack method for a sound-wave sensing gesture recognition system. Refer to Figure 4 As shown, this method includes the following steps:

[0030] Step S410, based on the goal of maximizing the confidence score of the adversarial signal in the target gesture class, construct the objective function of the attack, where the adversarial signal includes the original signal and the perturbation signal.

[0031] The ultimate goal of the attack is to generate an appropriate perturbation δ, and the overall goal of the attack is to maximize the probability that the adversarial signal x + δ is recognized as a specific class τ. For example, formulating the problem of generating the perturbation δ as an optimization problem:

[0032] F(x + δ) = max(O(x + δ) τ )

[0033] where x represents the original signal generated by the gesture recognition system, and O(x + δ) τ represents the confidence score of the adversarial signal x + δ in class τ. More specifically, O(x + δ) τDenoted as E(H(x + δ)) τ , where H(·) represents the preprocessing steps of the original signal, such as Butterworth filter, short-time Fourier transform; E(·) represents the gesture classification model. When the internal structure of the classification model E(·) is completely unknown, only the output probability of this classification model can be accessed.

[0034] Step S420, design a perturbation signal generation method to generate a perturbation signal based on the perturbation vector.

[0035] In one embodiment, by optimizing the objective function F, the perturbation signal δ is obtained, denoted as:

[0036] δ * = argmax δ (F(x + δ))

[0037] where δ * is the optimized perturbation signal. Since directly setting the dimensions of δ and x to be the same (for example, a 1-second signal with a sampling rate of 44100Hz, its dimension is 44100) will lead to difficult optimization and cannot penetrate the non-differentiable preprocessing module, a perturbation signal generation method is designed that can generate a 44100-dimensional perturbation signal from a perturbation vector p (such as 100-dimensional). And the particle swarm algorithm or other swarm intelligence algorithms can be used to implement argmax to obtain δ δ . * .

[0038] Combined with Figure 5 shown, the process of generating a perturbation signal from a perturbation vector includes: Step 101: Randomly initialize a 1×100 array with values between 0 and 0.1 as the perturbation vector p.

[0039] Step 102: Change the dimension of the perturbation vector p to 10×10, which is equivalent to 10 10×1 vectors, and each vector represents a composite wave within 0.1 seconds.

[0040] Step 103: For each 10×1 vector, their 10 values will be used as the amplitudes A

[0041] of 10 sine waves at 18900Hz, 18920Hz, 18940Hz... 19080Hz i to generate 10 sine waves.

[0042] Step 104: For each 10×1 vector, superimpose its 10 sine waves to obtain 10 composite waves.

[0043] For example, the superposition is simulated and implemented through the Overlay function of the Pydub library in Python, so that 10 composite waves can be obtained, and each wave corresponds to a composite wave in a 0.1-second period at this time.

[0044] Step 105: Splice the composite waves in sequence.

[0045] For example, splice these composite waves in a 0.1-second period in sequence at this time as a composite wave with a duration of 1 second.

[0046] Step 106: Export this composite wave as an audio signal δ to obtain the perturbation vector δ generated by the perturbation vector p.

[0047] It should be noted that the designed perturbation signal generation method can generate high-dimensional perturbation signals based on low-dimensional perturbation vectors, and the dimensions, initial value ranges, etc. of the arrays can be set to other values according to actual needs.

[0048] Step S430, obtain the optimized perturbation vector and the corresponding optimized perturbation signal by solving the objective function.

[0049] Further, in order to solve argmax δ , to obtain the optimized perturbation signal, in one embodiment, the linear decreasing inertia weight particle swarm optimization (LDIW-PSO) heuristic algorithm is combined with the above signal generation method to create a perturbation signal. Particle swarm optimization (PSO) is a population-based optimization algorithm that solves problems by simulating the social behavior of organisms such as birds, and can effectively search the solution space and perform optimization without gradient information. In PSO, each solution (usually a vector) is regarded as a "particle" in the search space, representing a potential solution to the problem. The particles update their positions and velocities by tracking two "best" values, namely the personal best (pbest i ) and the global best (gbest). The personal best is the best solution found for the particle itself. The global best is the best solution found for the entire particle swarm.

[0050] For example, the position and velocity of each particle are updated according to the following formula:

[0051]

[0052] where v i is the velocity of particle i. w is the inertia weight, which is used to control the degree to which the particle retains its current velocity. c1 and c2 are the individual and global learning factors respectively, which are used to control the step sizes towards the personal best and global best positions. rand() represents a random number usually in the range (0,1). x iis the position of particle i. Relatively large values of c1 or c2 can enhance the ability of the particle to follow its individual best solution and the global best solution respectively. The inertia weight controls the proportion of the current velocity retained by the particle during the update process. For example, the linearly decreasing inertia weight method updates the weight through the formula:

[0053]

[0054] where t is the current iteration number and T is the total number of iterations. In this way, the inertia weight w gradually decreases during the iteration process, which enables the algorithm to conduct a wide search in the early stage and fine-tune in the later stage. This dynamic adjustment strategy helps to balance the global search and local search capabilities of the algorithm, thereby improving its convergence performance and the quality of the solution.

[0055] In the process of solving the optimized perturbation vector and perturbation signal based on the particle swarm algorithm, the inputs include the original signal x, the original label α, the target label τ, the particle set the initial inertia weight w max , the final inertia weight w min , the learning factors c1 and c2, and the maximum number of iterations T. The outputs include the optimized solution p * and the corresponding optimized perturbation signal δ * . Specifically, it includes the following steps:

[0056] Step 201: Given the number of particles in the particle set ;

[0057] Step 202: Randomly initialize the position x i and velocity v i of each particle;

[0058] Step 203: Calculate and initialize the individual best solution pbest i ;

[0059] Step 204: Calculate and compare to determine the global best solution gbest at this time;

[0060] Step 205: Update the inertia weight w using formula (3);

[0061] Step 206: Update the velocity v i of each particle using formula (1);

[0062] Step 207: Update the position x i of each particle using formula (2);

[0063] Step 208: Calculate and compare to determine the individual best solution pbest i of each particle at this time;

[0064] Step 209: Calculate and compare to determine the global optimal solution gbest at this time;

[0065] Step 210: Repeat steps 204 - 209 until the iteration number t reaches the set threshold T.

[0066] Step S440: Generate adversarial samples using the optimized perturbation signal and train the target gesture classification model to enhance the ability to resist attacks.

[0067] The obtained optimized perturbation signal can be used to construct adversarial samples, which can then be used to train the target gesture classification model to improve the model's ability to resist attacks. As shown in Figure 6 The adversarial samples are obtained by adding a certain amount of perturbation data to the original samples. Training and testing the gesture classification model with the adversarial samples can verify the model's ability to resist attacks. For example, the target model can be used to process the adversarial samples to test whether the output result is consistent with the label of the original sample corresponding to the adversarial sample. If it is consistent, it indicates that the target model has a certain ability to resist adversarial attacks; otherwise, it indicates that the target model needs to be further optimized to provide the ability to resist attacks. Another example is that the adversarial samples and their actual labels can also be used as training data to further train the target model to improve its ability to resist attacks. In this way, the black - box attack scenario can be effectively addressed.

[0068] To further verify the effectiveness of the present invention, experimental verification was carried out, including physical signal simulation and actual scenario testing.

[0069] During the verification process, a common acoustic-wave-based gesture recognition system was reproduced in the form of an Android mobile application. The main function of this system is to control the speaker and microphone on the mobile device, transmit a sine-modulated audio signal at 19 kHz, and receive the echo at a sampling rate of 44.1 kHz. The collected acoustic signals are sent to a filter for noise reduction and then converted into Doppler spectrograms through short-time Fourier transform to train the gesture classification model. Ten participants (6 males and 4 females) were recruited, and each digital gesture from "0" to "9" was repeated 20 times in two environments (such as a laboratory and a lounge) using a mobile device (such as a Samsung Galaxy Tab S2). A total of 4002 samples were collected. And a ResNet18 deep learning model was trained, which has a basic classification accuracy of 96.5% for gestures. For physical signal simulation, by superimposing audio in Python software and using the attack method of the present invention, the attack success rate (the attack success rate is defined as: the number of samples whose classification category is successfully changed to the expected category / the total number of samples × 100%) for classes "0", "1", "3", "5", "6", "7", "8", "9" reached 83.6%. For the actual scenario test, in the scenario of playing real audio signals, propagating through the air and superimposing, and even including the scenario of attacking through a glass door, an attack success rate close to 50% was achieved.

[0070] In summary, compared with the prior art, the present invention has the following advantages:

[0071] 1) The present invention combines a perturbation generation method for time-domain and frequency-domain coordinates, which can convert the perturbation vector into a composite wave. This signal generation method can break through non-differentiable preprocessing modules such as short-time Fourier transform and pays more attention to the frequency-domain characteristics of the signal. This is significantly different from directly taking the signal as the original input in the speech field and performing iterative optimization.

[0072] 2) The present invention uses a particle swarm optimization algorithm with linearly decreasing weights and combines a designed iterative method to update the common perturbation vector between different active samples. This heuristic iterative method realizes general and targeted adversarial attacks.

[0073] 3) The present invention discovers that the amplitude spectrum has a covering effect, which means that a signal x1 with a higher amplitude can cover a signal x2 with a lower amplitude in terms of color, brightness, and display status on the amplitude spectrum. This ensures that the signals of complex gestures can also be changed through perturbation, weakening the characteristics of the original signal and allowing them to be classified into categories with simpler spectral characteristics.

[0074] 4) Compared with more general adversarial attack methods, the present invention targets acoustic wave perception gesture recognition systems and conducts feasibility evaluations in real-world scenarios, which can be used in fields such as smart homes and intelligent driving to address potential threats to gesture recognition systems.

[0075] 5) The adversarial attack method designed in the present invention includes how to convert the perturbation vector into a perturbation signal, how to optimize the perturbation vector and feedback it to the adversarial signal, and how to conduct adversarial attacks in real scenarios. The overall attack process can be reproduced and implemented, which is a real-time attack scheme feasible in real scenarios, not just a theoretical possibility of operating on existing data. Analyzing the attack scheme helps to provide support for real-world defense.

[0076] 6) The present invention analyzes the covering effect, and using the power spectral density can better resist this kind of adversarial attack.

[0077] 7) The attack of the present invention is on one-dimensional audio signals, and the perturbation can be directly superimposed on the original voice signal instead of on images. Therefore, it poses a more practical threat compared with the prior art which only involves superimposition in the image domain or traditional voice signal superimposition. For the problem that traditional image adversarial attack techniques are difficult to directly migrate to the acoustic field, the present invention proposes a method to generate achievable adversarial perturbation signals in the physical environment by combining the time domain and the frequency domain.

[0078] 8) The present invention realizes general and targeted adversarial attacks under a black-box model, and the designed optimization algorithm can generate effective perturbations without the internal details of the model.

[0079] 9) The present invention can ensure the coverage of the perturbation on the spectrogram without destroying the system input features, ensuring that the adversarial perturbation can be hidden in the normal signal in practical applications and can have an attack effect on different gesture signals.

[0080] The present invention can be a system, a method, and / or a computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for causing a processor to implement various aspects of the present invention.

[0081] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but is not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device such as a punched card or raised structures in grooves having instructions stored thereon, and any suitable combination of the foregoing. The computer-readable storage medium as used herein is not construed to be an instantaneous signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.

[0082] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include a copper transmission cable, an optical fiber transmission, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.

[0083] The computer program instructions for performing the operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine - related instructions, microcode, firmware instructions, state - setting data, or source code or object code written in any combination of one or more programming languages, including object - oriented programming languages such as Smalltalk, C++, Python, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer - readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand - alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or, alternatively, may be connected to an external computer (e.g., via an Internet service provider through the Internet). In some embodiments, by using the state information of the computer - readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field - programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer - readable program instructions to implement various aspects of the present invention.

[0084] Aspects of the present invention are described herein with reference to the flowchart and / or block diagram of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart and / or block diagram, and combinations of blocks in the flowchart and / or block diagram, can be implemented by computer - readable program instructions.

[0085] These computer - readable program instructions can be provided to a processor of a general - purpose computer, a special - purpose computer, or other programmable data - processing apparatus to produce a machine such that the instructions, when executed by the processor of the computer or other programmable data - processing apparatus, create a means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer - readable program instructions can also be stored in a computer - readable storage medium, which causes a computer, a programmable data - processing apparatus, and / or other devices to operate in a particular manner, so that the computer - readable medium storing the instructions comprises a manufacture, which includes instructions for implementing various aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0086] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.

[0087] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or by a combination of dedicated hardware and computer instructions. It is well known to those skilled in the art that implementation by hardware, implementation by software, and implementation by a combination of software and hardware are all equivalent.

[0088] The embodiments of the present invention have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of the terms used herein is intended to best explain the principles of the embodiments, the practical application, or the improvement of technology in the market, or to enable other ordinary skilled persons in the art to understand the embodiments disclosed herein. The scope of the present invention is defined by the appended claims.

Claims

1. A general targeted adversarial attack method for a gesture recognition system for acoustic wave perception, comprising the following steps: Based on the goal of maximizing the confidence score of the adversarial signal in the target gesture category, construct an objective function, where the adversarial signal includes an original signal and a perturbation signal; Solve the objective function to obtain an optimized perturbation vector and an optimized perturbation signal; Generate an adversarial sample based on the optimized perturbation signal to train the adversarial attack ability of the target gesture classification model.

2. The method according to claim 1, wherein Set the objective function as: δ * = argmax δ (F(x + δ)) Where: F(x + δ) = max(O(x + δ) τ ) Among them, x is the original signal, and O(x + δ) τ is the confidence score of the adversarial signal x + δ in the target gesture category τ, and O(x + δ) τ is denoted as E(H(x + δ)) τ , where H(·) represents the preprocessing process of the original signal, and E(·) represents the gesture classification model.

3. The method according to claim 1, wherein Solve the objective function according to the following steps: Given the number of particles in the particle set P, where each solution is a particle in the search space; Randomly initialize the position x of each particle i and the velocity v i , where i is the particle index; Calculate and initialize the personal best solution pbest i ; Determine the current global optimal solution gbest by calculation and comparison; Before the set iteration stop condition is met, perform the following steps: Update the inertia weight w in a way that decreases with the number of iterations; Update the velocity of each particle according to the following formula: Update the position of each particle according to the following formula: where v i is the velocity of particle i, c1 and c2 are the individual and global learning factors respectively, rand() represents a random number, x i is the position of particle i, t represents the current iteration number, gBest represents the global best, and pBest i represents the individual best value of particle i; Calculate and compare to determine the individual optimal solution pbest of each current particle i ; Calculate and compare to determine the current global optimal solution gbest, and then obtain the optimized perturbation vector and the corresponding perturbation signal according to the final global optimal solution.

4. The method according to claim 3, characterized in that, The inertia weight w is updated according to the following formula: where T is the total number of iterations, w max is the maximum value of the inertia weight, w min is the minimum value of the inertia weight.

5. The method according to claim 3, characterized in that, Set the optimized perturbation vector and the optimized perturbation signal as: p * = gBest Among them, is a pre-designed perturbation signal generation method.

6. The method according to claim 5, characterized in that, By designing a perturbation signal generation method The low-dimensional perturbation vector p is passed through Generate a high-dimensional perturbation signal δ, including the following steps: Randomly initialize a one-dimensional array of a set length as the perturbation vector p, where the values of this one-dimensional array range from 0 to 0.1; Change the dimension of the perturbation vector to a two-dimensional array, which contains multiple column vectors, and each column vector represents a composite wave within a set time period; For each column vector, generate a corresponding sine wave with its value as the amplitude of the sine wave; For each column vector, superimpose its corresponding sine wave to obtain the corresponding composite wave; Stitch the composite waves in sequence to obtain a stitched wave; Export the stitched wave as an audio signal to obtain the perturbation vector δ generated by the perturbation vector p.

7. The method according to claim 1, characterized in that The target gesture classification model is a deep neural network.

8. The method according to claim 2, characterized in that The preprocessing process H(·) of the original signal includes filtering with a Butterworth filter and short-time Fourier transform.

9. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.

10. A computer device, comprising a memory and a processor, and a computer program capable of running on the processor is stored on the memory, characterized in that When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • An inverse face recognition method based on PSO

    CN109214327A

  • Face recognition attack defense method based on Rosenbrock-PSO

    CN109858368A

  • Speech recognition attack defense method based on PSO algorithm

    CN110767216A

  • Deep learning adversarial sample generation method based on second-order method

    CN111325324A

  • Adversarial sample generation method based on high-concealment general disturbance

    CN111680292A