General adversarial attack method for gesture recognition system based on acoustic sensing
By constructing an objective function to optimize the perturbation signal and generate adversarial examples, the acoustic wave perception gesture recognition system was trained, which solved the security vulnerabilities of the existing system and effectively improved the performance against adversarial attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2026-04-07
AI Technical Summary
Existing sound wave sensing gesture recognition systems have security vulnerabilities and are susceptible to malicious audio attacks, lacking general and targeted adversarial attack solutions.
A general targeted adversarial attack method is designed for sound wave sensing gesture recognition systems. This method optimizes the perturbation signal by constructing an objective function, generates adversarial samples, and trains the gesture classification model to improve its adversarial attack capability.
Targeted training of the sound wave perception gesture recognition system was achieved, which can make input gestures misclassify into categories predetermined by attackers through physically implemented adversarial examples, revealing and enhancing the system's security vulnerabilities and improving its adversarial attack capabilities.
Smart Images

Figure CN120296418B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of anti-attack, more particularly, to a general targeted adversarial attack method for a gesture recognition system based on acoustic sensing. BACKGROUND
[0002] Acoustic-based human gesture recognition (HGR) systems are widely used in smart home, in-vehicle control and other scenarios due to their hardware versatility and non-invasiveness. These systems generally rely on deep neural networks (DNN) as classification models, and the inherent adversarial vulnerability of deep neural networks makes the systems vulnerable to malicious audio attacks.
[0003] Existing acoustic-based gesture recognition systems follow a typical three-stage process: capturing raw acoustic signals with microphones; pre-processing the signals to extract gesture-related features; and using deep neural networks to map the extracted features to various gestures. Figure 1 is a typical framework of an acoustic-based gesture recognition system. When a user waves his hand near the microphone for air writing, the sound signal received by the microphone is composed of the sound directly emitted by the loudspeaker, the signal reflected by the hand, and the signal reflected by the surrounding environment. Considering that the near-distance environment changes little in the gesture recognition process, the signals other than the hand reflection are basically consistent with the wave source frequency, so the action of the hand can be inferred through the Doppler effect of the hand reflection signal. A common approach is to extract this signal using a filter, convert this part of the signal to a time-frequency spectrogram through short-time Fourier transform, and then learn the features of the spectrogram through a deep learning model and perform classification.
[0004] However, existing research has not considered the potential security vulnerabilities of these acoustic-based gesture recognition methods and systems. Here, the security vulnerability refers to the fact that, for acoustic-based gesture recognition systems, an attacker can create a physically realizable adversarial example, such as an audio recording of ultrasonic waves. In the process of acoustic-based gesture recognition systems, acoustic data is collected through air, and can be maliciously injected with interference. When the system is working, the attacker plays the adversarial audio at the same time, so that the gesture signal superimposed with the adversarial audio is incorrectly classified into other categories.
[0005] After analysis, there is currently no general, targeted adversarial attack scheme directly against acoustic-based gesture recognition systems, so there is a need to improve existing technology to address the potential security risks caused by the inherent adversarial vulnerability of deep neural networks for the acoustic modality. SUMMARY
[0006] The purpose of this invention is to overcome the shortcomings of the prior art and provide a general targeted adversarial attack method for gesture recognition systems based on sound wave perception. This method includes the following steps:
[0007] An objective function is constructed based on maximizing the confidence score of the adversarial signal in the target gesture category. The adversarial signal includes the original signal and the perturbation signal.
[0008] Solve the objective function to obtain the optimized perturbation vector and the optimized perturbation signal;
[0009] Adversarial examples are generated based on the optimized perturbation signal to train the target gesture classification model's ability to resist attacks.
[0010] Compared with the prior art, the advantages of the present invention are that it designs a novel general targeted adversarial attack method that can use a physically implemented adversarial sample interference system to make input gestures misclassify into categories predetermined by the attacker, revealing security vulnerabilities in the sound wave sensing gesture recognition system, and then improving its adversarial attack capability by training the gesture classification model in a targeted manner.
[0011] Other features and advantages of the invention will become clear from the following detailed description of exemplary embodiments of the invention with reference to the accompanying drawings. Attached Figure Description
[0012] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments of the invention and, together with their description, serve to explain the principles of the invention.
[0013] Figure 1 This is a typical framework diagram of an existing sound wave-based gesture recognition system;
[0014] Figure 2 This is a schematic diagram of a potential adversarial attack scenario against a sound wave sensing gesture recognition system according to an embodiment of the present invention;
[0015] Figure 3 This is an overall attack flowchart according to an embodiment of the present invention;
[0016] Figure 4 This is a flowchart of a general targeted adversarial attack method for a gesture recognition system based on sound wave perception, according to an embodiment of the present invention.
[0017] Figure 5 This is a schematic diagram of generating a disturbance signal from a disturbance vector according to an embodiment of the present invention;
[0018] Figure 6This is a schematic diagram of the overall process of a general targeted adversarial attack method for a gesture recognition system based on sound wave perception, according to an embodiment of the present invention. Detailed Implementation
[0019] Various exemplary embodiments of the present invention will now be described in detail with reference to the accompanying drawings. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of the invention.
[0020] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the invention or its application or use.
[0021] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.
[0022] In all the examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values.
[0023] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.
[0024] This invention provides a general, targeted adversarial attack method for acoustic wave sensing gesture recognition systems. When the attacker learns some basic information about the attacked system (such as the ultrasonic frequency emitted by the acoustic wave gesture recognition system, the type of spectrum being recognized, and the type of gesture), the attacker can generate a perturbation signal. When this signal is injected, no matter what gesture the attacked system is writing, it will be recognized as the target gesture that the attacker wants the model to recognize.
[0025] For example, the process of generating a perturbation signal includes: converting an initialized random perturbation vector into a perturbation signal using a perturbation signal generation method; superimposing the perturbation signal with the original signal; if the classifier (or gesture classification model, gesture recognition model) does not identify the category expected by the attacker, optimizing the perturbation vector using the particle swarm optimization algorithm; superimposing the optimized vector again and classifying it, iteratively optimizing the vector until the upper limit of the number of optimizations is reached or the superimposed adversarial signal is successfully classified into the category expected by the attacker.
[0026] The generated perturbation signal will be saved as an audio format, to be played or injected during an attack. A carefully crafted perturbation signal can cause the classifier to misclassify, and these potential vulnerabilities could be exploited, leading to serious incidents. For example, in... Figure 2In the scenario illustrated, a user in a car attempts to hang up a phone call using a gesture recognition system that relies on air gestures. An attacker could deceive the system by playing disruptive signals through pre-placed devices or injecting them using microphone access, causing the system to incorrectly interpret the gesture as increasing volume or even accelerating the vehicle. Similarly, in a smart home, a user might want to turn on a light with a gesture, but an attacker could inject malicious signals, causing the gesture to be misclassified as "opening a door" or "turning on the gas." These are potential security vulnerabilities that this invention aims to reveal.
[0027] Attacks can create physically achievable adversarial examples, allowing attackers to trick the system into classifying any input gesture into a specific target category, regardless of the actual gesture performed by the victim. This invention aims to expose security vulnerabilities in acoustic wave-based gesture recognition systems by providing an effective perturbation generation method. This method can penetrate non-differentiable time-frequency transformation processes, resolving the inconsistency between the perturbation space (one-dimensional signal) and the classifier input space (two-dimensional time-frequency spectrum). Furthermore, it employs a particle swarm optimization algorithm with linearly decreasing weights, combined with an iterative method to update the universal perturbation vector for different target samples, thereby optimizing the perturbation signal. Finally, the desired perturbation signal is obtained and saved for constructing adversarial examples.
[0028] Figure 3 The overall attack process includes: the user makes a gesture, and the attacker simultaneously superimposes sound waves; the attacked system preprocesses the collected sound waves; the system puts the preprocessed data into a model for classification; and outputs the result expected by the attacker.
[0029] To address typical attack patterns, this invention provides a general targeted adversarial attack method for gesture recognition systems based on sound wave perception. See also Figure 4 As shown, the method includes the following steps:
[0030] Step S410: Based on maximizing the confidence score of the adversarial signal in the target gesture category as the target, construct the target function of the attack, where the adversarial signal includes the original signal and the perturbation signal.
[0031] The ultimate goal of the attack is to generate a suitable perturbation δ, and the overall objective is to maximize the probability that the adversarial signal x+δ is identified as a specific class τ. For example, the problem of generating the perturbation δ can be formulated as an optimization problem:
[0032] F(x+δ)=max(O(x+δ) τ )
[0033] Where x represents the original signal generated by the gesture recognition system, O(x+δ) τ This represents the confidence score of the adversarial signal x+δ in class τ. More specifically, O(x+δ) can be used as the confidence score. τRepresented as E(H(x+δ)) τ Here, H(·) represents the preprocessing steps of the original signal, such as Butterworth filter and short-time Fourier transform; E(·) represents the gesture classification model. When the internal structure of the classification model E(·) is completely unknown, only the output probabilities of the model are accessible.
[0034] Step S420: Design a disturbance signal generation method to generate a disturbance signal based on a disturbance vector.
[0035] In one embodiment, the disturbance signal δ is obtained by optimizing the objective function F, expressed as:
[0036] δ * =argmax δ (F(x+δ))
[0037] Where, δ * The optimized perturbation signal faces optimization challenges because directly setting the dimensions of δ and x to be the same (e.g., a 1-second signal with a sampling rate of 44100Hz would have a dimension of 44100) would lead to optimization difficulties and would not be able to penetrate the non-differentiable preprocessing module. Therefore, a perturbation signal generation method was designed. It can pass the perturbation vector p (e.g., 100-dimensional) through Generate a 44100-dimensional perturbation signal. Furthermore, argmax can be achieved using particle swarm optimization or other swarm intelligence algorithms. δ Thus, δ * .
[0038] Combination Figure 5 As shown, using The process of generating a disturbance signal from a disturbance vector includes:
[0039] Step 101: Randomly initialize a 1×100 array with values between 0 and 0.1 as the perturbation vector p.
[0040] Step 102: Change the dimension of the perturbation vector p to 10×10, which is equivalent to 10 10×1 vectors, each vector representing the composite wave within 0.1 seconds.
[0041] Step 103: For each 10×1 vector, its 10 values will serve as the amplitude A of 10 sine waves at 18900Hz, 18920Hz, 18940Hz...19080Hz. i This generates 10 sine waves.
[0042] Step 104: For each 10×1 vector, superimpose 10 sine waves to obtain 10 composite waves.
[0043] For example, superposition can be simulated using the Overlay function in the Pydub library of Python, which can produce 10 composite waves, each corresponding to a composite wave with a time interval of 0.1 seconds.
[0044] Step 105: Assemble the composite waves in sequence.
[0045] For example, these composite waves with a duration of 0.1 seconds can be spliced together in sequence to form a composite wave with a duration of 1 second.
[0046] Step 106: Derive the composite wave as an audio signal δ, and obtain the perturbation vector δ generated by the perturbation vector p.
[0047] It should be noted that the designed disturbance signal generation method It can generate high-dimensional perturbation signals based on low-dimensional perturbation vectors, and the array dimension, initial numerical range, etc. can be set to other values according to actual needs.
[0048] Step S430: By solving the objective function, the optimized perturbation vector and the corresponding optimized perturbation signal are obtained.
[0049] Furthermore, in order to solve argmax δ To obtain an optimized perturbation signal, in one embodiment, a heuristic algorithm, Linearly Decreasing Inertial Weighted Particle Swarm Optimization (LDIW-PSO), is combined with the aforementioned signal generation method to create the perturbation signal. Particle Swarm Optimization (PSO) is a population-based optimization algorithm that solves problems by simulating the social behavior of organisms such as birds. It can efficiently search the solution space and perform optimization without gradient information. In PSO, each solution (typically a vector) is considered a "particle" in the search space, representing a potential solution to the problem. The particle updates its position and velocity by tracking two "best" values: the individual best (pbest) and the velocity. i There are two optimal solutions: individual optimal (GBest) and global optimal (GBest). Individual optimal is the best solution found for the particle itself, while global optimal is the best solution found for the entire particle swarm.
[0050] For example, the position and velocity of each particle are updated according to the following formula:
[0051]
[0052] Where v i `x` represents the velocity of particle `i`. `w` is the inertia weight, used to control how much the particle retains its current velocity. `c1` and `c2` are the individual and global learning factors, respectively, used to control the step size towards the individual and global optimal positions. `rand()` represents a random number typically in the range (0,1). iThis represents the position of particle i. Relatively large values of c1 or c2 can enhance the particle's ability to follow its individual optimal solution and the global optimal solution, respectively. Inertia weights control the proportion of the particle that retains its current velocity during the update process. For example, the linearly decreasing inertia weight method updates the weights using the formula:
[0053]
[0054] Where t is the current iteration number and T is the total number of iterations. In this way, the inertia weight w gradually decreases during the iteration process, allowing the algorithm to perform a broad search in the early stages and fine-tune in the later stages. This dynamic adjustment strategy helps balance the algorithm's global and local search capabilities, thereby improving its convergence performance and the quality of the solution.
[0055] In the process of solving the optimized perturbation vector and perturbation signal based on the particle swarm optimization algorithm, the input includes the original signal x, the original label α, the target label τ, and the particle set. Initial inertia weight w max The final inertial weight w min Learning factors c1 and c2, and the maximum number of iterations T. The output includes the optimal solution p. * and the corresponding optimal perturbation signal δ * Specifically, it includes the following steps:
[0056] Step 201: Given a set of particles The number of particles;
[0057] Step 202: Randomly initialize the position x of each particle. i and velocity v i ;
[0058] Step 203: Calculate and initialize the individual optimal solution pbest i ;
[0059] Step 204: Calculate and compare to determine the global optimal solution gbest at this point;
[0060] Step 205: Update the inertia weight w using formula (3);
[0061] Step 206: Update the velocity v of each particle using formula (1) i ;
[0062] Step 207: Update the position x of each particle using formula (2) i ;
[0063] Step 208: Calculate and compare to determine the individual optimal solution pbest for each particle at this point. i ;
[0064] Step 209: Calculate and compare to determine the global optimal solution gbest at this point;
[0065] Step 210: Repeat steps 204-209 until the number of iterations t reaches the set threshold T.
[0066] Step S440: Use the optimized perturbation signal to generate adversarial examples and train the target gesture classification model to enhance the ability to resist attacks.
[0067] The obtained optimized perturbation signals can be used to construct adversarial examples, which can then be used to train a target gesture classification model to improve the model's resistance to attacks. Figure 6 As shown, adversarial examples are obtained by adding certain perturbations to the original samples. Training and testing a gesture classification model using adversarial examples can verify the model's resistance to attacks. For example, the target model can be processed with adversarial examples, and its output can be tested to see if it matches the label of the original sample corresponding to the adversarial example. If they match, it indicates that the target model has a certain ability to resist adversarial attacks; otherwise, it indicates that the target model needs further optimization to improve its resistance to attacks. Furthermore, adversarial examples and their actual labels can be used as training data to further train the target model to improve its resistance to attacks. In this way, black-box attack scenarios can be effectively addressed.
[0068] To further verify the effectiveness of the invention, experimental verification was conducted, including physical signal simulation and real-world scenario testing.
[0069] During the validation process, a common sound wave-based gesture recognition system was reproduced as an Android mobile application. The system's main function is to control the speaker and microphone on the mobile device to transmit a 19kHz sinusoidal modulated audio signal and receive the echo at a 44.1kHz sampling rate. The acquired sound signal is fed into a filter for noise reduction and then converted into a Doppler spectrum using a short-time Fourier transform to train the gesture classification model. Ten participants (six men and four women) were recruited to repeat each digit gesture "0" to "9" 20 times in two environments (a lab and a lounge) using a mobile device (such as a Samsung S2 tablet). A total of 4002 samples were collected. A ResNet18 deep learning model was trained, achieving a base classification accuracy of 96.5% for the gestures. For physical signal simulation, by superimposing audio in Python software and utilizing the attack method of this invention, the attack success rate (defined as: number of samples successfully changed to the expected category / total number of samples × 100%) reached an average of 83.6% for classes "0", "1", "3", "5", "6", "7", "8", and "9". In real-world scenario tests, including real audio signal playback, airborne transmission and superposition, and even attacks through a glass door, an attack success rate approaching 50% was achieved.
[0070] In summary, compared with the prior art, the present invention has the following advantages:
[0071] 1) This invention combines a perturbation generation method using time-domain and frequency-domain coordinates, which can convert perturbation vectors into composite waves. This signal generation method can overcome the limitations of non-differentiable preprocessing modules such as short-time Fourier transform, and places greater emphasis on the frequency domain characteristics of the signal. This is significantly different from the approach in the speech domain, which directly uses the signal as the raw input and performs iterative optimization.
[0072] 2) This invention utilizes a particle swarm optimization algorithm with linearly decreasing weights, combined with a designed iterative method to update the universal perturbation vector among different active samples. This heuristic iterative method enables a general and targeted adversarial attack.
[0073] 3) This invention discovers that the amplitude spectrum has a covering effect, meaning that a signal x1 with a higher amplitude can cover a signal x2 with a lower amplitude in terms of color, brightness, and display status on the amplitude spectrum. This ensures that signals of complex gestures can also be altered through perturbation, weakening the characteristics of the original signal and allowing them to be classified into categories with simpler spectral characteristics.
[0074] 4) Compared to more general adversarial attack methods, this invention targets sound wave perception gesture recognition systems and has conducted a feasibility assessment in real-world scenarios. It can be used in fields such as smart homes and intelligent driving to address potential threats to gesture recognition systems.
[0075] 5) The adversarial attack method designed in this invention includes how to convert a perturbation vector into a perturbation signal, how to optimize the perturbation vector and feed it back to the adversarial signal, and how to conduct adversarial attacks in real-world scenarios. The entire attack process can be reproduced and implemented, making it a feasible real-time attack scheme for real-world scenarios, not just a theoretical possibility of manipulating existing data. Analyzing the attack scheme helps to support real-world defense.
[0076] 6) This invention analyzes the coverage effect and uses power spectral density to better resist this adversarial attack.
[0077] 7) This invention attacks one-dimensional audio signals, directly superimposing the original speech signal rather than superimposing it on an image, thus posing a greater practical threat. Existing technologies only involve superimposition in the image domain or traditional speech signal superimposition, where the speech signal does not need to undergo preprocessing steps such as short-time Fourier transform, and operations on one-dimensional signals are preserved. Addressing the difficulty of directly transferring traditional image-based adversarial attack techniques to the acoustic domain, this invention proposes a method that combines time and frequency domains to generate feasible adversarial perturbation signals in a physical environment.
[0078] 8) This invention achieves general and targeted adversarial attacks under a black-box model, and the designed optimization algorithm can generate effective perturbations without the internal details of the model.
[0079] 9) This invention can ensure the coverage of the disturbance on the spectrum without destroying the system input characteristics, ensure that the anti-disturbance can be hidden in the normal signal in practical applications, and can be effective against different gesture signals.
[0080] This invention can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of the invention.
[0081] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination thereof. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0082] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0083] The computer program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, Python, etc., and conventional procedural programming languages such as "C" or similar languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing state information from the computer-readable program instructions. This electronic circuitry can execute the computer-readable program instructions to implement various aspects of the invention.
[0084] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0085] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0086] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0087] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions. It will be known to those skilled in the art that implementation in hardware, implementation in software, and implementation using a combination of software and hardware are equivalent.
[0088] The various embodiments of the present invention have been described above. These descriptions are exemplary and not exhaustive, and are not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or technical improvements to the embodiments in the market, or to enable others skilled in the art to understand the embodiments disclosed herein. The scope of the invention is defined by the appended claims.
Claims
1. A general targeted adversarial attack method for gesture recognition systems based on sound wave perception, characterized in that, Includes the following steps: An objective function is constructed based on maximizing the confidence score of the adversarial signal in the target gesture category. The adversarial signal includes the original signal and the perturbation signal. Solve the objective function to obtain the optimized perturbation vector and the optimized perturbation signal; Adversarial examples are generated based on the optimized perturbation signal to train the target gesture classification model's ability to resist attacks; The objective function is set as follows: in: in, It is the original signal. It is a signal of resistance In target gesture category The confidence score, and Represented as , This indicates the preprocessing process of the original signal. This represents a gesture classification model; The objective function is solved according to the following steps: Given a set of particles The number of particles, where each solution is treated as a particle in the search space; Randomly initialize the position of each particle and speed , where i is the particle index; Calculate and initialize individual optimal solutions ; The current global optimal solution is determined through calculation and comparison. ; Before the set iteration stopping condition is met, perform the following steps: Update the inertia weights in a manner that decreases with the number of iterations. ; The velocity of each particle is updated according to the following formula: Update the position of each particle according to the following formula: in, It is the velocity of particle i. and These are individual and global learning factors, Represents a random number. Here, t represents the position of particle i, and t represents the current iteration number. Indicates global best. This represents the individual optimal value for particle i; Calculate and compare to determine the individual optimal solution for each particle. ; Calculate and compare to determine the current global optimal solution. Then, based on the final global optimal solution, the optimized perturbation vector and the corresponding perturbation signal are obtained; The inertial weight Updated according to the following formula: in, It is the total number of iterations. It is the maximum value of the inertia weight. It is the minimum value of the inertia weight; The optimized perturbation vector and the optimized perturbation signal are set as follows: in, It is a pre-designed method for generating disturbance signals; By designing a perturbation signal generation method, the low-dimensional perturbation vector pass Generating high-dimensional perturbation signals includes the following steps: Randomly initialize a one-dimensional array of a set length. As a perturbation vector, the values of this one-dimensional array range from 0 to 0.1; The dimension of the disturbance vector is transformed into a two-dimensional array, which contains multiple column vectors, each column vector representing a composite wave within a set time period; For each column vector, the corresponding sine wave is generated by taking their values as the amplitude of the sine wave; For each column vector, superimpose its corresponding sine wave to obtain the corresponding composite wave; By splicing the composite waves in the order described above, a spliced wave is obtained; The spliced waveform is derived as an audio signal, resulting from the perturbation vector. Generated disturbance signal .
2. The method according to claim 1, characterized in that, The target gesture classification model is a deep neural network.
3. The method according to claim 1, characterized in that, The preprocessing process of the original signal It includes filtering using Butterworth filters and short-time Fourier transform.
4. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 3.
5. A computer device comprising a memory and a processor, wherein a computer program capable of running on the processor is stored in the memory, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Speech recognition attack defense method based on PSO algorithm
CN110767216A
Sticker attack resisting method based on scores
CN115424098A