Method and device for generating adversarial sample based on partially perceivable patch

By optimizing perturbing the specific areas of the target image, some perceptible adversarial samples are generated, which solves the problem of insufficient concealment and universality in the prior art, and achieves a stable attack effect under different environments and perspectives, improving the robustness and effectiveness of adversarial samples.

CN120298668APending Publication Date: 2025-07-11TIANJIN UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510410988.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-11

Smart Images

  • Figure CN120298668A_ABST
    Figure CN120298668A_ABST
Patent Text Reader

Abstract

The invention discloses an adversarial sample generation method based on a partially perceptible patch, and the method enables a specific region of a target image to be visually close to the characteristics of a natural image through the optimization disturbance of the specific region of the target image, maximizes the interference to a target detection model, and improves the attack effectiveness while maintaining the concealment. The invention further provides a device of the adversarial sample generation method based on the partially perceptible patch. According to the method, color space transformation and random deformation are combined, the adaptability of the adversarial sample in different environments is further enhanced, and the method has higher robustness and universality in practical application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of image processing, and particularly to an adversarial sample generation method and device based on partially perceptible patches. Background Art

[0002] Currently, with the rapid progress in the field of computer vision, deep neural networks play a very important role in tasks such as image classification, object detection, and semantic segmentation. However, the robustness and reliability of these models have been challenged by adversarial samples. Adversarial samples are generated by adding carefully designed perturbations, which can mislead deep neural networks into making incorrect judgments, thus causing some inevitable losses. This phenomenon exposes significant defects in the security and robustness of deep learning, especially in safety-critical fields such as autonomous driving and medical diagnosis, where the potential risks cannot be ignored.

[0003] Research has found that carefully designed adversarial perturbations can significantly reduce the recognition accuracy of models and even lead to serious misjudgments. For example, black-and-white adversarial stickers are applied to traffic signs, which perturb the feature extraction of the model through simple geometric patterns, resulting in incorrect classification by the detector; strong light is projected onto the target surface through a laser beam, instantaneously changing the local pixel distribution, thereby misleading the decision-making process of the model. Although these methods are effective in specific scenarios, their significant visual features or dependence on specific environmental conditions limit their concealment and stability in practical applications. Therefore, how to improve the concealment and generality of adversarial samples while maintaining the effectiveness of the attack has become a key challenge in current research. Summary of the Invention

[0004] The present invention provides an adversarial sample generation method and device based on partially perceptible patches to solve the technical problems existing in the known technology.

[0005] The technical solution adopted by the present invention to solve the technical problems existing in the known technology is:

[0006] An adversarial sample generation method based on partially perceptible patches, which optimizes the perturbation of a specific region of the target image to make it visually close to the characteristics of a natural image, while maximizing the interference to the target detection model, thereby improving the effectiveness of the attack while maintaining concealment.

[0007] Further, the method includes the following steps:

[0008] Step 1, set the optimization objective and constraint conditions for generating adversarial samples; set the following optimization iteration parameters: sample geometric transformation step size, total number of times to update the patch generation area, and patch perceptibility;

[0009] Step 2, initialize the patch position within the mask region of the input sample; initialize the number of times to update the patch generation region.

[0010] Step 3, record the current patch position as the global best patch position; initialize the patch generation parameters and geometric transformation parameters.

[0011] Step 4, make the perceptibility value of the current generated patch = the perceptibility value of the previous generated patch + step size, and determine whether the perceptibility value of the current generated patch exceeds the set value range. If not, execute the next step; if so, directly go to Step 6.

[0012] Step 5, perform color space conversion on the input sample; generate an adversarial patch on the image after color space conversion, and generate a sample with the adversarial patch.

[0013] Step 6, make the value of the current geometric transformation parameter = the value of the previous geometric transformation parameter + step size, and determine whether the value of the current geometric transformation parameter exceeds the set value range. If not, execute the next step; if so, directly go to Step 8.

[0014] Step 7, perform geometric transformation on the sample generated in Step 5.

[0015] Step 8, input the sample obtained in Step 5 or Step 6 into the target detection model, obtain the model output, and determine whether the attack is successful. If so, go to Step 13; if not, determine whether the perceptibility and geometric transformation of the sample both exceed the set value range. If so, go to Step 9; if not, go to Step 4.

[0016] Step 9, make the current number of times to update the patch generation region = the previous number of times to update the patch generation region + 1, and determine whether the current number of times to update the patch generation region exceeds the total number of times to update the patch generation region set. If not, execute the next step; if so, directly go to Step 11.

[0017] Step 10, select a new patch generation region using the simulated annealing algorithm according to the current global best patch position, and update the current patch position; return to Step 3.

[0018] Step 11, input the newly generated adversarial sample into the target detection model, obtain the model output, and determine whether the attack is successful. If so, go to Step 13; if not, decide whether to update the global best patch position according to the Metropolis criterion. If so, update the global best patch position and go to Step 13; if not, go to the next step.

[0019] Step 12, adjust the following parameters individually or in combination: the geometric transformation step size of the sample, the total number of iterations to update the patch generation region, and the perceptibility of the updated patch; return to Step 2.

[0020] Step 13: Update and output the final adversarial example, and verify its misleading effect on the target detection model.

[0021] Further, in Step 1, let: the given target detection model be f(·), the input original image be x, the true label of the original image x be y, and the generated adversarial example be x adv ; Let the attack target be to generate an adversarial example x adv such that the model's prediction result f(x adv ) ≠ y;

[0022] Set the optimization objective for generating the adversarial example as follows:

[0023]

[0024] Set the constraint condition for generating the adversarial example as follows:

[0025] ‖δ‖ ≤ ∈;

[0026] In the formula:

[0027] L(f(x), y) represents the loss function, which is used to measure the difference between the model's prediction result and the true label;

[0028] means to find the perturbation δ to maximize the loss function;

[0029] δ represents the perturbation added to the input sample x;

[0030] ∈ is the upper limit of the perturbation, usually measured using the L p norm.

[0031] Further, in Step 5, the method for performing color space conversion on the input sample includes the following method steps:

[0032] Convert the input sample from the RGB color space to the LAB color space to separate the luminance and color information; generate partially perceptible patches by modifying the pixels in the L channel; L is the channel in the LAB color space;

[0033] Generate an adversarial patch on the sample after color space conversion according to the following formula:

[0034]

[0035] In the formula:

[0036] represents the L channel value of the patch area of the updated adversarial example;

[0037] L Rect (x) represents the L channel value of the patch area generated in the clean sample;

[0038] α represents the perceptible coefficient of the patch;

[0039] By changing the perceptible coefficient α, the generated patch can be made more obvious or more concealed, so as to evaluate the influence degree of different coefficients on the model prediction; when α = 0, the patch completely disappears; when α = 1, the patch area becomes all white.

[0040] Further, in step 1, the pixels of the L channel and the perceptible coefficient of the patch are used as optimization parameters, and the value ranges and adjustment steps of these two parameters are set; among them, the value range of α is: 0 ≤ α ≤ 1.

[0041] Further, the methods for geometric transformation of the sample include: rotation, scaling, and translation, so that the patch maintains a stable attack effect under different environments and perspectives.

[0042] Further, in step 1, the rotation angle, scaling ratio, and translation size are used as optimization parameters, and the value ranges and adjustment steps of these three parameters are set.

[0043] Further, in step 11, the method for determining whether to update the global best patch position according to the Metropolis criterion includes the following method steps:

[0044] Calculate the adversarial loss difference between the adversarial sample after iteration and the adversarial sample before iteration according to the following formula:

[0045]

[0046] Determine whether to update according to the Metropolis criterion according to the following formula:

[0047]

[0048] In the formula:

[0049] ΔE represents the adversarial loss between the new adversarial sample and the previous adversarial sample;

[0050] represents the adversarial sample generated after the patch is updated;

[0051] represents the adversarial sample after the t-th patch update;

[0052] t represents the number of patch updates;

[0053] T represents the temperature parameter in the simulated annealing algorithm;

[0054] P represents the probability of accepting the new patch generation area;

[0055] Represents the loss function of the adversarial sample generated after patch update;

[0056] Represents the loss function of the adversarial sample before the t-th patch update;

[0057] Gradually reduce the temperature as the number of iterations increases, so that the system gradually converges to a stable state.

[0058] Furthermore, in step 13, the update rule of the adversarial sample is:

[0059]

[0060] In the formula:

[0061] Represents the adversarial sample after the (t + 1)-th patch update;

[0062] r represents a random number between 0 and 1.

[0063] The present invention also provides a device for an adversarial sample generation method based on partially perceptible patches, including a memory and a processor, where the memory is used to store a computer program; the processor is used to execute the computer program and implement the steps of the adversarial sample generation method based on partially perceptible patches as described above when executing the computer program.

[0064] The advantages and positive effects of the present invention are: By optimizing the perturbation of specific regions of the target image, the present invention makes it visually close to the characteristics of natural images, while maximizing the interference to the target detection model, thereby improving the effectiveness of the attack while maintaining concealment. In addition, this method combines color space transformation and random deformation, further enhancing the adaptability of adversarial samples in different environments, making it have higher robustness and versatility in practical applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 Is a flowchart of the working process of an adversarial sample generation method based on partially perceptible patches of the present invention.

[0066] Figure 2 Is a working principle diagram of an adversarial sample generation method based on partially perceptible patches of the present invention.

[0067] Figure 2 In Represents the Kronecker product. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0068] The present invention will be described in detail below with reference to embodiments. It should be understood that the preferred embodiments described herein are only for explaining and illustrating the present invention, and are not used to limit the present invention.

[0069] The Chinese meanings of the following English words, abbreviations and phrases are as follows:

[0070] Conv: Convolution layer.

[0071] Relu: Activation layer.

[0072] MaxPool: Max pooling layer.

[0073] FC: Fully connected layer.

[0074] if: If.

[0075] else: Otherwise.

[0076] The Chinese name of the Metropolis criterion is the "Metropolis criterion", which is a probability criterion used to accept new states in the simulated annealing algorithm.

[0077] Please refer to Figures 1 to 2 , a method for generating adversarial samples based on partially perceptible patches, which optimizes perturbations on specific regions of the target image to make it visually close to the characteristics of natural images, while maximizing the interference to the target detection model, thereby improving the effectiveness of the attack while maintaining concealment.

[0078] Preferably, the method may include the following steps:

[0079] Step 1, set the optimization objective and constraint conditions for generating adversarial samples; set the following optimization iteration parameters: sample geometric transformation step size, total number of times to update the patch generation region, and patch perceptibility.

[0080] Step 2, initialize the patch position within the masked region of the input sample; initialize the number of times to update the patch generation region.

[0081] Step 3, record the current patch position as the global best patch position; initialize the patch generation parameters and geometric transformation parameters.

[0082] Step 4, make the current generated patch perceptibility value = the previous generated patch perceptibility value + step size, and judge whether the current generated patch perceptibility value exceeds the set value range. If not, execute the next step; if so, directly go to Step 6.

[0083] Step 5, perform color space conversion on the input sample; generate adversarial patches on the image after color space conversion, and generate samples with adversarial patches.

[0084] Step 6, set the current geometric transformation parameter value = the previous geometric transformation parameter value + step size, and determine whether the current geometric transformation parameter value exceeds the set value range. If not, proceed to the next step; if so, directly go to Step 8.

[0085] Step 7, perform geometric transformation on the samples generated in Step 5.

[0086] Step 8, input the samples obtained in Step 5 or Step 6 into the target detection model, obtain the model output, and determine whether the attack is successful. If so, go to Step 13; if not, determine whether both the perceptibility of the sample and the geometric transformation exceed the set value range. If so, go to Step 9; if not, go to Step 4.

[0087] Step 9, set the current number of times of updating the patch generation area = the previous number of times of updating the patch generation area + 1, and determine whether the current number of times of updating the patch generation area exceeds the total number of times of updating the patch generation area set. If not, proceed to the next step; if so, directly go to Step 11.

[0088] Step 10, select a new patch generation area using the simulated annealing algorithm according to the current global best patch position, and update the current patch position; return to Step 3.

[0089] Step 11, input the newly generated adversarial sample into the target detection model, obtain the model output, and determine whether the attack is successful. If so, go to Step 13; if not, decide whether to update the global best patch position according to the Metropolis criterion; if so, update the global best patch position and go to Step 13; if not, go to the next step.

[0090] Step 12, adjust the following parameters individually or in combination: sample geometric transformation step size, total number of iterations of updating the patch generation area, perceptibility of the updated patch; return to Step 2.

[0091] Step 13, update and output the final adversarial sample, and verify its misleading effect on the target detection model.

[0092] Preferably, in Step 1, it can be set that: given the target detection model as f(·), the input original image is x, the true label of the original image x is y, and the generated adversarial sample is x adv ; set the attack target as generating the adversarial sample x adv when the prediction result f(x adv ) ≠ y.

[0093] The optimization objective of generating the adversarial sample can be set as follows:

[0094]

[0095] The constraint conditions for generating the adversarial sample can be set as follows:

[0096] ‖δ‖≤∈;

[0097] Where:

[0098] L(f(x), y) represents the loss function, which is used to measure the difference between the model prediction result and the true label;

[0099] It means to find the perturbation δ to maximize the loss function;

[0100] δ represents the perturbation added to the input sample x;

[0101] ∈ is the upper limit of the perturbation, usually measured using the L p norm.

[0102] Preferably, in step 5, the method for performing color space conversion on the input sample may include the following method steps:

[0103] Convert the input sample from the RGB color space to the LAB color space to separate the luminance and color information; generate a partially perceptible patch by modifying the pixels of the L channel; L is the channel of the LAB color space;

[0104] Generate an adversarial patch on the sample after color space conversion according to the following formula:

[0105]

[0106] Where:

[0107] represents the L channel value of the patch area of the updated adversarial sample;

[0108] L Rect (x) represents the L channel value of the patch area generated in the clean sample;

[0109] α represents the perceptible coefficient of the patch.

[0110] By changing the perceptible coefficient α, the generated patch can be made more obvious or more concealed, so as to evaluate the influence degree of different coefficients on the model prediction; when α = 0, the patch completely disappears; when α = 1, the patch area becomes all white.

[0111] Preferably, in step 1, the pixels of the L channel and the perceptible coefficient of the patch can be used as optimization parameters, and the value ranges and adjustment steps of these two parameters are set; among them, the value range of α is: 0 ≤ α ≤ 1. The step of the perceptible coefficient α of the patch can be selected as 0.05, 0.1, 0.15.

[0112] Preferably, the method for geometric transformation of the sample may include: rotation, scaling, and translation, so that the patch maintains a stable attack effect under different environments and perspectives.

[0113] Preferably, in step 1, the rotation angle, scaling ratio, and translation size can be used as optimization parameters, and the value ranges and adjustment steps of these three parameters can be set. The step of the rotation angle can be selected as 10°, 20°, 30°, 45°, 50°. The step of the scaling ratio can be selected as 10%, 20%, 30%, 40%, 50%.

[0114] Preferably, in step 11, the method for determining whether to update the global best patch position according to the Metropolis criterion may include the following method steps:

[0115] The adversarial loss difference between the adversarial sample after iteration and the adversarial sample before iteration can be calculated according to the following formula:

[0116]

[0117] It can be determined whether to update according to the Metropolis criterion according to the following formula:

[0118]

[0119] In the formula:

[0120] ΔE represents the adversarial loss between the new adversarial sample and the previous adversarial sample;

[0121] represents the adversarial sample generated after the patch update;

[0122] represents the adversarial sample after the t-th patch update;

[0123] t represents the number of patch updates;

[0124] T represents the temperature parameter in the simulated annealing algorithm;

[0125] P represents the probability of accepting the new patch generation area;

[0126] represents the loss function of the adversarial sample generated after the patch update;

[0127] represents the loss function of the adversarial sample before the t-th patch update.

[0128] The temperature is gradually reduced as the number of iterations increases, so that the system gradually converges to a stable state.

[0129] Preferably, in step 13, the update rule of the adversarial sample can be:

[0130]

[0131] In the formula:

[0132] represents the adversarial sample after the (t + 1)-th patch update;

[0133] r represents a random number between 0 and 1.

[0134] The present invention also provides a device for the method of generating adversarial samples based on partially perceptible patches, including a memory and a processor. The memory is used to store a computer program; the processor is used to execute the computer program and implement the steps of the method of generating adversarial samples based on partially perceptible patches as described above when executing the computer program.

[0135] The working process and working principle of the present invention will be further described below with a preferred embodiment of the present invention:

[0136] Step A, set the attack target and initialize the parameters:

[0137] Given the target detection model as f(·), the input original image is x, the true label of the original image x is y, and the generated adversarial sample is x adv ; set the attack target as generating the adversarial sample x adv such that the prediction result of the model f(x adv ) ≠ y; at the same time, define the attack constraint conditions, including the maximum perturbation intensity, the color channel adjustment range, and the patch area limit. The goal of adversarial sample generation can usually be defined as the following optimization problem:

[0138]

[0139] In the formula:

[0140] L(f(x), y) represents the loss function, which is used to measure the difference between the model prediction result and the true label;

[0141] represents finding the perturbation δ to maximize the loss function;

[0142] δ represents the perturbation added to the input sample x;

[0143] ∈ is the upper limit of the perturbation, usually measured using the L p norm.

[0144] Step B, initialize the position of the initial generated patch and find the sensitive area of the image:

[0145] Initialize the position of the patch within the mask region of the input sample, and record this position as the global best patch position for subsequent patch optimization.

[0146] Step C: Perform color space conversion on the input sample:

[0147] Convert the input sample from the RGB color space to the LAB color space to separate the luminance and color information, facilitating the control of the perceptual effect of the patch. By modifying the pixels in the L channel, the purpose of generating partially perceptible patches can be achieved.

[0148] Step D: Adjust the invisibility of the patch based on the color space conversion analysis:

[0149] Generate adversarial patches on the image after color space conversion:

[0150]

[0151] In the formula:

[0152] represents the L channel value of the patch region of the updated adversarial sample;

[0153] L Rect (x) represents the L channel value of the patch region generated in the clean sample;

[0154] α represents the perceptible coefficient of the patch.

[0155] By changing the perceptible coefficient, the generated patch can be made more obvious or more invisible, in order to evaluate the influence degree of different coefficients on the model prediction. When α = 0, the patch completely disappears; when α = 1, the patch region becomes all white.

[0156] Step E: Perform physical transformations on the image such as rotation, scaling, and translation:

[0157] When implementing adversarial attacks in the real world, the effectiveness of the patch is affected by various uncertain factors, including lighting changes, perspective shifts, shooting distances, image noise, object surface deformations, etc. By performing physical transformations such as rotation, scaling, and translation on the image, the patch maintains a stable attack effect under different environments and perspectives, significantly enhancing its adaptability and robustness in the real world.

[0158] The optimization goal of the patch is to maximize the prediction loss of the model under all perturbation scenarios. This process is optimized through backpropagation. During the optimization process, the patch is tested under multiple perturbation scenarios in each iteration, and the patch parameters are adjusted according to the feedback. This optimization mechanism under multiple scenarios and multiple perturbations ensures that the patch can significantly interfere with the deep learning model under different perspectives, different lighting conditions, and different noise conditions.

[0159] Step F: Input the image with the adversarial patch into the target detection model to obtain the model output. If the attack is successful, go to Step 9; otherwise, continue to optimize.

[0160] Step G: Update the patch generation area using the simulated annealing algorithm:

[0161] In each iteration, select a new patch generation area according to the globally optimal patch position, and calculate the adversarial loss difference between the new adversarial sample and the previous adversarial sample according to the following formula:

[0162]

[0163] where ΔE represents the adversarial loss between the new adversarial sample and the previous adversarial sample;

[0164] represents the adversarial sample generated after patch update;

[0165] represents the adversarial sample after the t-th patch update;

[0166] t represents the number of patch updates;

[0167] represents the loss function of the adversarial sample generated after patch update;

[0168] represents the loss function of the adversarial sample before the t-th patch update.

[0169] Decide whether to update according to the Metropolis criterion:

[0170]

[0171] where T represents the temperature parameter in the simulated annealing algorithm; P represents the probability of accepting the new patch generation area; gradually reduce the temperature as the number of iterations increases to make the system gradually converge to a stable state.

[0172] The update rule for the new adversarial sample is:

[0173]

[0174] In the formula:

[0175] represents the adversarial sample after the (t + 1)-th patch update;

[0176] r represents a random number between 0 and 1.

[0177] Step H: Input the newly generated adversarial sample into the target detection model to determine whether the attack is successful. If the attack is successful, update the best patch position; otherwise, continue to optimize.

[0178] If the attack is not successful, decide whether to update the globally best patch position according to the Metropolis criterion.

[0179] Step I: Repeat Steps C - H until the attack is successful or the maximum number of iterations is reached. Output the final adversarial sample and verify its misleading effect on the model.

[0180] In the case where the attack is not successful, continue to optimize cyclically, gradually adjust the patch parameters, and enhance the misleading ability of the model. When the attack is successful or the maximum number of iterations is reached, input the final adversarial sample into the target detection model. If the attack fails, repeat Steps B - H until the attack is successful.

[0181] The embodiments described above are only used to illustrate the technical ideas and features of the present invention, and the purpose is to enable those skilled in the art to understand the content of the present invention and implement it accordingly. The patent scope of the present invention cannot be limited only by these embodiments. That is, any equivalent changes or modifications made based on the spirit disclosed in the present invention still fall within the patent scope of the present invention.

Claims

1. A method for generating adversarial samples based on partially perceptible patches, characterized in that, This method optimizes and perturbs specific regions of the target image to make it visually close to the characteristics of natural images while maximizing the interference to the target detection model, thereby improving the effectiveness of the attack while maintaining concealment.

2. The method for generating adversarial samples based on partially perceptible patches according to claim 1, wherein This method includes the following steps: Step 1, set the optimization objective and constraint conditions for generating adversarial samples; Set the following optimization iteration parameters: the step size of sample geometric transformation, the total number of times to update the patch generation area, and the patch perceptibility; Step 2, initialize the patch position within the masked area of the input sample; initialize the number of times to update the patch generation area; Step 3, record the current patch position as the global best patch position; initialize the patch generation parameters and geometric transformation parameters; Step 4, make the value of the current generated patch perceptibility = the value of the previous generated patch perceptibility + the step size, and judge whether the value of the current generated patch perceptibility exceeds the set value range. If not, execute the next step; if so, directly go to Step 6; Step 5, perform color space conversion on the input sample; Generate adversarial patches on the image after color space conversion to generate a sample with adversarial patches; Step 6, make the value of the current geometric transformation parameter = the value of the previous geometric transformation parameter + the step size, and judge whether the value of the current geometric transformation parameter exceeds the set value range. If not, execute the next step; if so, directly go to Step 8; Step 7, perform geometric transformation on the sample generated in Step 5; Step 8, input the sample obtained in Step 5 or Step 6 into the target detection model to obtain the model output, and judge whether the attack is successful. If so, go to Step 13; if not, judge whether the perceptibility and geometric transformation of the sample both exceed the set value range. If so, go to Step 9; if not, go to Step 4; Step 9, make the current number of times to update the patch generation area = the previous number of times to update the patch generation area + 1, and judge whether the current number of times to update the patch generation area exceeds the set total number of times to update the patch generation area. If not, execute the next step; if so, directly go to Step 11; Step 10, according to the current global best patch position, use the simulated annealing algorithm to select a new patch generation area and update the current patch position; return to Step 3; Step 11, input the newly generated adversarial sample into the target detection model to obtain the model output, and judge whether the attack is successful. If so, go to Step 13; if not, decide whether to update the global best patch position according to the Metropolis criterion. If so, update the global best patch position and go to Step 13; if not, go to the next step; Step 12, adjust the following parameters individually or in combination: the step size of sample geometric transformation, the total number of iterations of updating the patch generation area, and the perceptibility of the updated patch; return to Step 2; Step 13, update and output the final adversarial sample, and verify its misleading effect on the target detection model.

3. The method for generating adversarial samples based on partially perceptible patches according to claim 2, wherein In step 1, assume that: the given object detection model is f(·), the input original image is x, the true label of the original image x is y, and the generated adversarial sample is x adv ; assume that the attack target is to generate the adversarial sample x adv such that the prediction result of the model f(x adv ) ≠ y; Set the optimization objective for generating adversarial samples as follows: Set the constraint conditions for generating adversarial samples as follows: ‖δ‖≤∈; In the formula: L(f(x),y) represents the loss function, which is used to measure the difference between the model prediction result and the true label; Denote finding the perturbation δ to maximize the loss function; δ represents the perturbation added to the input sample x; ∈ is the upper limit of the perturbation, usually measured using the L p norm.

4. The method for generating adversarial samples based on partially perceptible patches according to claim 2, wherein In step 5, the method for performing color space conversion on the input sample includes the following method steps: Convert the input sample from the RGB color space to the LAB color space to separate the luminance and color information; generate a partially perceptible patch by modifying the pixels of the L channel; L is the channel of the LAB color space; Generate an adversarial patch on the sample after color space conversion according to the following formula: In the formula: Indicates the L-channel value of the patch region representing the updated adversarial example; L Rect (x) represents the L-channel value of the generated patch region in the clean sample; α represents the perceptible coefficient of the patch; By changing the perceptible coefficient α, make the generated patch more obvious or more concealed, so as to evaluate the influence degree of different coefficients on the model prediction; When α = 0, the patch completely disappears; when α = 1, the patch area becomes all white.

5. The method for generating adversarial samples based on partially perceptible patches according to claim 4, wherein In step 1, use the pixels of the L channel and the perceptible coefficient of the patch as optimization parameters, and set the value ranges and adjustment steps of these two parameters; among them, the value range of α is: 0 ≤ α ≤ 1.

6. The method for generating adversarial examples based on partially perceptible patches according to claim 2, wherein The method for performing geometric transformation on the sample includes: rotation, scaling, and translation, so that the patch maintains a stable attack effect under different environments and perspectives.

7. The adversarial sample generation method based on partially perceptible patches according to claim 6, characterized in that, In step 1, use the rotation angle, scaling ratio, and translation size as optimization parameters, and set the value ranges and adjustment steps of these three parameters.

8. The method for generating adversarial samples based on partially perceptible patches according to claim 2, wherein In step 11, the method for determining whether to update the global best patch position according to the Metropolis criterion includes the following method steps: Calculate the adversarial loss difference between the adversarial sample after iteration and the adversarial sample before iteration according to the following formula: Determine whether to update according to the Metropolis criterion according to the following formula: In the formula: ΔE represents the adversarial loss between the new adversarial sample and the previous adversarial sample; Denote adversarial examples generated after patch update; Denote the adversarial sample after the t-th patch update; t represents the number of patch updates; T represents the temperature parameter in the simulated annealing algorithm; P represents the probability of accepting the new patch generation area; Represents the loss function of the adversarial samples generated after the patch update; Denote the loss function of adversarial samples before the t-th patch update; Gradually reduce the temperature as the number of iterations increases, so that the system gradually converges to a stable state.

9. The method for generating adversarial samples based on partially perceptible patches according to claim 8, wherein In step 13, the update rule of the adversarial sample is: In the formula: Denote the adversarial sample after the (t + 1)-th patch update; r represents a random number between 0 and 1.

10. An apparatus for an adversarial sample generation method based on partially perceptible patches, comprising a memory and a processor, characterized in that, The memory is used to store a computer program; the processor is used to execute the computer program and implement the method steps of the adversarial sample generation method based on a partially perceptible patch as described in any one of claims 1 to 9 when executing the computer program.

Citation Information

Cited By

  • Target detection model-oriented distributed physical adversarial patch generation method and system

    CN121329781A

  • Anti-attack patch generation method based on particle swarm optimization

    CN121457501A

  • A method for generating adversarial attack patches based on particle swarm optimization

    CN121457501B