Method and system for generating highly dissimilar test cases under high imperceptibility constraint

By calculating the pixel contribution degree and SCSM matrix of the test picture, selecting key pixel points to add perturbation, generating highly unaware adversarial test cases, solving the problems of blindness and insufficient quality in the existing methods, and achieving more effective testing of autonomous driving systems.

CN120353716AActive Publication Date: 2025-07-22CIVIL AVIATION UNIV OF CHINA
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510838717.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-07-22
Estimated Expiration
2045-06-23

AI Technical Summary

Technical Problem

The existing highly dissimilar test case generation methods are blind in the autonomous driving system, resulting in adversarial test cases perturbing pixels with low impact on classification, which cannot effectively reveal the vulnerabilities of the DNN model, and the quality of adversarial test cases generated by the existing methods is insufficient.

Method used

By obtaining the classification probability of the test image in the DNN network model, the contribution of each pixel point is calculated, and the SCSM matrix is used to measure the differences between categories, select the pixel points with the highest sorting to add perturbation, generate high-invisibility and high-invisibility test cases, and optimize the invisibility and high-invisibility of multiple indicators.

Benefits of technology

Higher quality adversarial test cases are generated, which can more effectively reveal the vulnerabilities of the DNN model in autonomous driving systems and improve the invisibility and accuracy of the test.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120353716A_ABST
    Figure CN120353716A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of high-quality test case generation, in particular to a highly dissimilar test case generation method under high imperceptibility constraint. Comprising the following steps: acquiring a test picture and inputting the test picture into a DNN network model to obtain a classification probability of the test picture in each test case category; obtaining the contribution degree of each pixel point in the test picture according to the classification probability; obtaining an SCSM matrix of the test image among the test case categories according to the weight of the full connection layer of the last layer of the network model; according to the contribution degree of each pixel point in the test picture and the SCSM matrix, obtaining a sorting index of each pixel to sort the pixel points in the test picture, and selecting the pixel points which are sorted in the front to add disturbance to the test picture; and obtaining a plurality of test pictures and respectively adding perturbation to obtain a test case. According to the method, on the basis of generating the test case with higher quality, vulnerabilities with more test significance in the DNN model required by the automatic driving system can be disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of high-quality test case generation, and specifically relates to a method and system for generating highly dissimilar test cases under highly imperceptible constraints. Background Art

[0002] In the latest application of autonomous driving systems, the Dawn Project test found that the fully autonomous driving system of the car failed to correctly identify children crossing the road to trigger the emergency braking of the FSD protection mechanism, and the system failed to identify the children or identified them as less dangerous and could not trigger the protection mechanism urgently, resulting in the car hitting the fake children used for testing. Also, the "phantom braking" problem common to current widespread autonomous driving systems also reflects that they identify unknown objects as objects requiring emergency braking, which has triggered an urgent need for highly dissimilar error vulnerability testing of DNN models in autonomous driving systems.

[0003] An adversarial attack refers to an intentionally designed input sample aimed at causing a deep learning model to predict an incorrect output; while an imperceptible adversarial attack is a method used in machine learning and deep neural networks to generate small perturbations that are almost invisible to humans but can significantly change the prediction of a classifier or recognition system. This type of attack is usually used to evaluate and improve the security and robustness of models. Especially for models in the field of autonomous driving, due to the higher requirement for imperceptibility to simulate the natural environment. Since the concept of "adversarial severity" was first proposed in 2021, related research includes saturation attacks (NetSat). Highly dissimilar test cases have become crucial for revealing the vulnerabilities of its visual DNN models, but they have obvious deficiencies.

[0004] Currently, taking NetSat as an example, the latest method for generating highly dissimilar test cases still has the following defects: The strategy of modifying all pixels is blind, and adding perturbations to many pixels with low influence on classification is more harmful than beneficial. The adversarial test cases generated by the current method can still improve the highly dissimilarity index, and the highly dissimilarity index DM has room for improvement. Summary of the Invention

[0005] To solve the problems existing in the prior art, the present invention provides a method for generating highly dissimilar test cases under the constraint of high imperceptibility. The method obtains a test image and inputs it into a DNN network model to obtain the classification probabilities of the test image in each test case category; obtains the contribution degree of each pixel point in the test image according to the classification probabilities; obtains the SCSM matrix of the test image between each test case category according to the weights of the fully connected layer of the last layer of the network model; sorts the pixel points in the test image according to the sorting index of each pixel obtained according to the contribution degree of each pixel point in the test image and the SCSM matrix, and selects the pixel points with the top sorting rankings to add perturbations to the test image; obtains multiple test images and adds perturbations to them respectively to obtain test cases. On the basis of generating higher-quality test cases, the present invention helps to reveal more test-significant vulnerabilities in the DNN model required for the autonomous driving system.

[0006] The present invention adopts the following technical solutions. A method for generating highly dissimilar test cases under the constraint of high imperceptibility includes: Obtain a test image and input it into a DNN network model to obtain the classification probabilities of the test image in each test case category; Obtain the contribution degree of each pixel point in the corresponding test image according to the classification probabilities; Obtain the SCSM matrix of the test image between each test case category according to the weights of the fully connected layer of the last layer of the network model; Perform weighted calculation according to the contribution degree of each pixel point in the test image and the SCSM matrix to obtain the sorting index of each pixel; Sort the pixel points in the test image according to the sorting index of each pixel, and select the pixel points with the top sorting rankings to add perturbations to the test image; Obtain multiple test images and add perturbations to them respectively to obtain test cases.

[0007] Further, obtaining the contribution degree of each pixel point in the corresponding test image includes: Input the test image into a DNN network model to obtain the classification probabilities corresponding to each parameter category in the network model for the test image; Perform a partial derivative operation on the classification probabilities corresponding to each parameter category at the position of each pixel point in the test image to obtain the contribution degree corresponding to each pixel point.

[0008] Further, obtaining the SCSM matrix of the test image between each test case category includes: Obtain the weight values corresponding to each test case category for the weights of the fully connected layer of the last layer in the network model; Calculate the cosine similarity between two test case categories according to the weight values corresponding to each test case category; Build the SCSM matrix based on the cosine similarity between pairwise test case categories.

[0009] Furthermore, perform weighted calculation according to the contribution degree of each pixel point in the test image and the SCSM matrix to obtain the sorting index of each pixel. The expression is: ; where assigns the contribution degree parameters of each pixel corresponding to k categories to their distance indicators in the SCSM matrix respectively, represents the contribution degree of the pixel point to each category, is the contribution degree of the i-th pixel point to the k-th category. If it is positive, it remains unchanged. If it is negative, it is assigned 0.

[0010] Furthermore, after selecting the pixel points with the top sorting ranks and adding perturbations to the test image, it also includes: Select different proportions of pixel points from multiple test images and add perturbations respectively to obtain test images corresponding to multiple different perturbation proportions; Evaluate the accuracy of the test images corresponding to different perturbation proportions, and select the test image with the lowest accuracy according to the evaluation results; Take the perturbation proportion corresponding to the test image with the lowest accuracy as the determined proportion.

[0011] Furthermore, after obtaining the test cases, it also includes: Obtain the imperceptibility index of the test cases; Optimize according to the imperceptibility index of the test cases, and evaluate the high dissimilarity of the test cases according to the optimized imperceptibility index.

[0012] The present invention further proposes a highly dissimilar test case generation system under high imperceptibility constraints, which adopts any of the above test case generation methods. The system specifically includes: a pixel position contribution degree index generation module, an SCSM matrix search module, a sorting module, an adversarial test case generation module, and a test effect evaluation module; The pixel position contribution degree index generation module is used to obtain a test image and input it into the DNN network model to obtain the classification probability of the test image in each test case category; obtain the contribution degree of each pixel point in the corresponding test image according to the classification probability; The SCSM matrix search module is used to obtain the SCSM matrix of the test image between each test case category according to the weights of the fully connected layer of the last layer of the network model; The sorting module is used to perform weighted calculation according to the contribution degree of each pixel point in the test image and the SCSM matrix to obtain the sorting index of each pixel; The adversarial test case generation module is used to sort the pixel points in the test image according to the sorting index of each pixel, select the pixel points with the top sorting ranks to add perturbations to the test image; obtain multiple test images and add perturbations respectively to obtain test cases; The test effect evaluation module is used to obtain the imperceptibility index of the test case; optimize according to the imperceptibility index of the test case, and evaluate the high dissimilarity of the test case according to the optimized imperceptibility index.

[0013] The beneficial effects of the present invention are as follows: Based on the current high-quality requirement of high imperceptibility of adversarial test cases, the present invention reduces the number of perturbed pixels by finding the idea of key pixels to achieve better imperceptibility; in the process of finding the ranking of key pixels, the search strategy for high dissimilarity is integrated, so that adding perturbations to the found key pixels with top ranks can increase the confidence of a more highly dissimilar class from the original class; specifically, the present invention further obtains the contribution degree parameter of each picture to it at each pixel position of the picture in the model; obtains the SCSM matrix that describes the gap size between each category through the classification weights of the last layer of the DNN model; according to the contribution degree parameter at each pixel position and the SCSM matrix, obtains the sorting index by weighting according to our purpose, and then sorts all pixel positions; when generating adversarial test cases, only select the pixel positions with top ranks to control the perturbation amplitude and add perturbations; comprehensively evaluate the imperceptibility by weighting multiple indicators, and optimize the weighted classification confidence of the evaluation indicators when evaluating the high dissimilarity of the generated adversarial test cases; through the method of the present invention, it is possible to generate adversarial test cases with high-quality imperceptibility, and at the same time ensure better results for the classification vulnerabilities with high dissimilarity in the DNN model related to testing the autonomous driving system. Description of the Drawings

[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0015] Figure 1 It is a schematic diagram of the steps of the method for generating highly dissimilar test cases under the constraint of high imperceptibility according to the embodiment of the present invention; Figure 2Schematic flowchart of the method for generating highly dissimilar test cases under the constraint of high imperceptibility according to an embodiment of the present invention; Figure 3 Schematic diagram of the relationship curve between the adversarial test cases generated by modifying the pixel positions of different proportions after sorting with a constant perturbation size and the recognition accuracy according to an embodiment of the present invention; Figure 4 SCSM matrix sorted by calculating different model weight parameters according to an embodiment of the present invention; Figure 5 Ratio of the adversarial test cases with classification errors to the adversarial test cases under a fixed same imperceptibility according to an embodiment of the present invention; Figure 6 Clustering diagram of the original image and the adversarial test cases under the same imperceptibility for the same dataset model according to an embodiment of the present invention; Figure 7 Schematic diagram of the number of error categories with classification errors when generating adversarial test cases with the same imperceptibility for the MNIST dataset and the corresponding model under different methods according to an embodiment of the present invention; Figure 8 Schematic diagram of the number of error categories with classification errors when generating adversarial test cases with the same imperceptibility for the CIFAR-10 dataset and the corresponding model under different methods according to an embodiment of the present invention; Figure 9 Schematic diagram of the number of error categories with classification errors when generating adversarial test cases with the same imperceptibility for the STL-10 dataset and the corresponding model under different methods according to an embodiment of the present invention; Figure 10 Schematic diagram of the ADM index results when generating adversarial test cases with the same imperceptibility for the MNIST dataset and the corresponding model under different methods according to an embodiment of the present invention; Figure 11 Schematic diagram of the ADM index results when generating adversarial test cases with the same imperceptibility for the CIFAR-10 dataset and the corresponding model under different methods according to an embodiment of the present invention; Figure 12 Schematic diagram of the ADM index results when generating adversarial test cases with the same imperceptibility for the STL-10 dataset and the corresponding model under different methods according to an embodiment of the present invention; Figure 13 Schematic diagram of the ADM index results of generating 500 adversarial test cases with classification errors by different methods within a certain imperceptibility index range for different dataset models according to an embodiment of the present invention; Figure 14 Schematic structural diagram of a highly dissimilar test case generation system under the constraint of high imperceptibility according to an embodiment of the present invention. Detailed implementation manners

[0016] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0017] As Figure 1 and Figure 2 shown, the embodiments of the present invention provide a method for generating highly dissimilar test cases under high imperceptibility constraints, including the following steps: S11. Obtain the contribution degree parameters of the classification probability of each picture in the model at each pixel position of the picture; In the embodiments of the present invention, the test pictures obtained are exemplified by the CIFAR-10 dataset, and the DNN network model is exemplified by the VGG16 model. First, a test picture set of 1000 original pictures with 100 pictures in each of 10 categories is delimited in the test set. Each picture is cyclically traversed and put into the trained VGG16 model parameters to obtain the classification probabilities of 10 categories. These ten classification probabilities can obtain ten values at each pixel through the forward gradient formula. These ten values represent the contribution degree parameters of this pixel position to these ten classifications. If the contribution degree parameter obtained for a certain category is a larger positive value, it means that adding perturbations to this pixel can maximize the increase in the classification probability of the model for this category. If the contribution degree parameter obtained for a certain category is a larger negative value, it means that adding perturbations to this pixel position will maximize the reduction of the classification probability of this category.

[0018] A forward gradient calculation formula given in the embodiments of the present invention is as follows: ; In the formula represents the forward gradient matrix, F j (X) represents the classification probability value of the jth category, x i represents the ith pixel position of the original picture, M is the number of pixels, N is the number of categories. Taking CIFAR-10 as an example, a matrix of 3072 ×10 will be finally obtained, indicating that each of the 3072 pixel positions will have contribution degree parameters for 10 categories. In addition, it should be noted that the same pixel position in different channels can be repeatedly selected when finally selecting key pixels.

[0019] S12. Obtain the SCSM matrix describing the differences between categories through the classification weights of the last layer of the DNN model; In an embodiment of the present invention, for the weights of the activation function of the last layer of model parameters with respect to the classification output result, the weights of two categories are fixed each time and the cosine similarity is calculated. If the calculated value is larger, it indicates that the degree of dissimilarity between these two categories for the model's classification is greater. The traditional dissimilarity metric (DM) is a redefinition and expression of the average visual confusion, aiming to quantify the deviation between the categories predicted by the model and the true categories of the original data on the perturbed dataset. The core purpose of this metric is to evaluate the degree and nature of the damage to the structure of the original dataset. However, manually annotating the visual similarity between categories is impractical in deep learning models with a large number of categories. Therefore, the DM metric does not rely on artificial similarity annotations, but extracts information from the learning structure of the model itself to measure the similarity between different categories.

[0020] In an embodiment of the present invention, the similarity between categories is calculated by the following cosine similarity formula: ; where CSM i,j represents the cosine similarity between category i and category j, and represent the weights of model category i and category j respectively, T is the transpose of the matrix. By fixing an original category i and calculating its similarity with all other categories j, a matrix reflecting the degree of difference between categories can be obtained, and this matrix is called the SCSM matrix (Similarity-based Class Similarity Matrix).

[0021] Such as Figure 4The SCSM matrices calculated from the model parameters obtained by training the LeNet-5 model, VGG16 model, and ResNet18 model on the MNIST dataset, CIFAR-10 dataset, and STL-10 dataset respectively in the embodiments of the present invention are shown. The classification of the MNIST dataset by category is relatively intuitive, where 0-9 represent the classifications corresponding to the handwritten digits. For the CIFAR-10 dataset and STL-10 dataset, 0-9 respectively correspond to their categories of airplane, automobile, bird, cat, deer, dog, frog, horse, ship, truck, and airplane, bird, automobile, cat, deer, dog, horse, monkey, ship, truck. It comprehensively shows the similarity distribution pattern between categories and can more intuitively reveal the impact of perturbations on model classification. In this way, the SCSM provides a systematic measurement method for the prediction changes on the perturbed dataset. In each matrix, the first column 0-9 represents the original categories, and then the categories closer to it represent that the model believes the semantics between their categories are more similar, with a smaller degree of high dissimilarity. While the categories farther from the original category represent that the model believes the semantics between their categories are more distant, with a greater degree of high dissimilarity. Then, according to the relationship between other categories and the original category in the column distance in this matrix, in the embodiments of the present invention, the ten columns are assigned distance metrics DM of ten equal parts starting from the original category on the leftmost side. Under the original category of the original image in a certain row, the category of the classification result of the generated adversarial test case is the category of which column, and then it is assigned the corresponding number from 0-9 to measure the size of its high dissimilarity.

[0022] S13. After obtaining the sorting index by weighting according to the contribution degree parameter at each pixel position and the SCSM matrix, all pixel positions are sorted; In the embodiments of the present invention, the contribution degree parameters of each pixel position to each category are obtained through the above steps. The positive and negative values of these parameters can intuitively reflect whether adding perturbations to this pixel position has a positive promoting effect or a negative inhibitory effect on the classification result of a certain category. At the same time, the CSM calculated through cosine similarity i,j By combining and calculating the category difference size between a fixed original category i and other categories j each time, the SCSM matrix reflecting the difference between categories can be constructed. This matrix can measure which categories are highly dissimilar (farther away) and which categories are more similar (closer) to a certain fixed category, thus providing a quantitative representation for classification similarity.

[0023] Based on the contribution degree parameter of the pixel position and the SCSM matrix, each pixel position is further weighted. Specifically, for each category at a certain pixel position, in the embodiments of the present invention, the contribution degree parameter of this category is multiplied by its distance score relative to the fixed category in the SCSM matrix. This weighting method can effectively integrate the intensity of the pixel's contribution to classification and the dissimilarity between categories. At the same time, in order to ensure that the direction of the perturbation conforms to the expectation, in the embodiments of the present invention, only the categories with positive contribution degree parameters are weighted, because a negative contribution degree parameter means that adding perturbation will reduce the classification probability of the model for this category, which is contrary to the goal of generating effective adversarial samples. Therefore, for the categories with negative contribution degree parameters, they are directly assigned a value of 0 to avoid interference.

[0024] Use the contribution degree parameter at each pixel position and the SCSM matrix to calculate the sorting formula of the pixel positions with higher contribution degrees to more highly dissimilar categories at each pixel position, expressed as: ; Where is to assign the contribution degree parameters of k categories corresponding to each pixel to their distance indicators in the SCSM matrix, represents the contribution degree of the pixel point to each category, is the contribution degree of the i-th pixel point to the k-th category. If it is positive, it remains unchanged; if it is negative, it is assigned a value of 0.

[0025] After the above weighting calculation is completed, each pixel position is sorted according to the principle of from large to small according to the results. This sorting can reflect which pixel positions have higher contribution degrees to the categories that are highly dissimilar to the fixed category. By selecting the pixel positions with higher rankings, the key pixels that are more helpful for distinguishing the fixed category from other categories can be identified.

[0026] It should be noted that when determining the proportion of pixel positions for adding perturbation, since the process of adding perturbation is actually to superimpose a certain amplitude of perturbation parameters on the pixel positions, selecting too high a proportion of pixel positions may lead to a significant decrease in the overall contrast of the image, thereby having a negative impact on the classification test effect of the adversarial samples. As the proportion of perturbed pixels increases, the test effect may not only not improve, but may instead decline. In addition, due to the different image characteristics of different data sets, the optimal perturbation proportion needs to be optimized separately according to the specific situation of the data set to ensure that the generated adversarial samples can maximize the test effect without damaging the perceptual quality of the image.

[0027] S14. When generating adversarial test cases, only select the pixel positions with higher rankings to control the perturbation amplitude and add perturbation; In the embodiments of the present invention, after perturbing different proportions of pixels in each data set with perturbations of several fixed values, the accuracy rate of the adversarial test cases is obtained as a measurement index, so as to determine the key pixel proportion with the lowest accuracy rate for this data set as the perturbation proportion, and further as a fixed parameter for subsequent experiments.

[0028] First, determine the optimal proportion of pixel positions to be selected when generating adversarial test cases. For the test data sets of different data sets, 100 test original images of each category, a total of 1000 test original images, after fixing the perturbation size, select different proportions of pixel positions to add perturbations, and then compare the magnitudes of their accuracy rates to determine what the key pixel selection proportion for this data set is. As Figure 3 shown, in the MNIST, CIFAR-10, and STL-10 data sets, in the embodiments of the present invention, this proportion is determined to be 55%, 41%, and 18% respectively, thus initially generating adversarial test cases.

[0029] The embodiments of the present invention further calculate the imperceptibility index of the adversarial test cases, including: ; Among them, represents the generated adversarial test case, represents the name of the test case, represents the original sample, n is the number of adversarial test cases generated by the adversarial attack, represents the P-norm. In the formula, the smaller the value of the average normalized distortion (ALD P ), the smaller the difference perceived by the naked eye, that is, the better the imperceptibility. In addition, in the embodiments of the present invention, the following SSIM index is also used. It is considered an effective method for measuring human eye perception. By comparing brightness, contrast, and structure to measure the similarity between two images, it is expressed as: ; In the formula, and are the mean and variance of the original sample respectively, and are the mean and variance of the adversarial test case respectively. C1 and C2 are constants set to stabilize the denominator. The SSIM value range is between [-1, 1]. The value closer to 1 indicates that the two images are more similar, and the value closer to -1 indicates that the two images are less similar.

[0030] Since SSIM is only calculated for a single image, while the average structural similarity (ASS) calculates the average SSIM between all adversarial test case data sets and their original sample data sets, the embodiments of the present invention further define the average structural similarity (ASS) as: ; Among them, is the structural similarity, is the number of adversarial test cases, represents the generated adversarial test cases, represents the name of the test case, represents the original sample.

[0031] Since the imperceptibility of a single image is measured by multiple metrics, which provides higher precision for the image, the embodiments of the present invention use two metrics, namely the average normalized distortion (ALD P ), and the structural similarity (ASS). Therefore, it is necessary to unify these two metrics into a single parameter to measure the imperceptibility of the adversarial test cases, and it is named Imperceptibility.

[0032] The embodiments of the present invention first calculate the average normalized distortion (ALD P ) and the structural similarity (ASS) of the adversarial test cases, and normalize them to the range of 0 to 1 to obtain ALD PN and ASS N . Since the meaning of the imperceptibility metric is that the larger the value, the better, while the meaning of the ALD P metric is exactly the opposite, the value of ALD P is expressed as 1 - ALD P . Finally, the calculation of the imperceptibility metric (Imperceptibility) is finally expressed as the following formula: ; In the formula, is the normalized average normalized distortion, is the normalized structural similarity.

[0033] Due to the importance of these two metrics, the embodiments of the present invention select 0.5 as the importance parameter in front of these two metrics. Additionally, on the basis of keeping the imperceptibility metric basically similar above, the embodiments of the present invention conduct experiments on feature extraction using VGG16, dimensionality reduction using UMAP, and clustering using HDBSCAN to verify that the generated adversarial test cases in the embodiments of the present invention are of higher quality: as Figure 6 shown, in Figure 6In the clustering diagram, if the distance between two types of images is closer, it indicates that the model believes that these two types of images are more similar in features. According to the results in the diagram, it can be found that in the three datasets and models, the imperceptibility of the adversarial test cases generated by different methods is about the same. The clustering results of the adversarial test cases generated by the method adopted in the embodiments of the present invention and the original images after feature extraction are better than those of other methods, indicating that the adversarial test cases generated by the present invention are closer to the original images in terms of imperceptibility and features, and the image quality is higher.

[0034] S15. Comprehensively evaluate the high dissimilarity of the generated adversarial test cases by the optimization index.

[0035] In the embodiments of the present invention, for the adversarial test case generation method proposed by the present invention and other methods used for comparison and measurement, after the adversarial test cases that have been generated similarly, the DM index only represents the size of the high dissimilarity between the classification category of an original test image and the classification category of the adversarial test case. What needs to be measured in the evaluation of the embodiments of the present invention is the average DM size of all the generated adversarial test cases, which is defined as ADM. In addition, in the embodiments of the present invention, the probability of the misclassified category is also considered, and the change in the confidence of the model when facing adversarial samples is particularly concerned when evaluating the effectiveness of the adversarial attack, which reflects the effectiveness of the generated adversarial test cases.

[0036] Current existing research points out that if the adversarial test cases can significantly reduce the confidence of the model in the original category or increase the confidence of the model in the wrong category, this means that the model has a high vulnerability to these adversarial samples. The high confidence of the model in the wrong classification indicates that it is very sensitive to perturbations, showing the potential vulnerability of the model. In addition, the difference in the confidence response of the model to the adversarial test cases generated by different attack methods reveals the high sensitivity of the model's structure to specific attacks; therefore, in the index proposed in the embodiments of the present invention, the DM value obtained for each adversarial test case needs to be multiplied by the classification probability P of the wrong category adv, The average DM of all adversarial test cases is defined by the following formula: ; where represents the high dissimilarity index of all adversarial test cases, is the classification probability of the wrong category.

[0037] The experimental results given in the embodiments of the present invention are as Figure 7 、 Figure 8 、 Figure 9As shown, after the three dataset models generate adversarial test cases using different methods, it is shown that FGSM, as a strong perturbation method for model faults, although generates a relatively large number of adversarial test cases with incorrect categories, but due to the relatively small number of adversarial test cases with classification categories far from the original categories, ultimately in Figure 10 、 Figure 11 、 Figure 12 , the ADM metrics for each category do not exceed the method proposed in the present invention. The present invention generally performs better in terms of ADM metrics for all categories. It should be noted here that the original purpose of the saturation attack (NetSat) method is to obtain adversarial test cases with classification results far from the true labels, but in Figure 10 、 Figure 11 、 Figure 12 , it can be found that its effect is even worse than FGSM in many categories. This is because the experimental premise of the method proposed in the present invention is to control the perturbation size of the generated adversarial test cases, that is, imperceptible, and compare their ADM metrics under basically the same conditions. However, due to the different ways of adding perturbations by different methods, the sensitivities to perturbations after generating adversarial test cases are also different, so it is more valuable to compare other effects under a fixed perturbation.

[0038] Meanwhile Figure 13 shows that the present invention controls the Imperceptibility metric within a certain imperceptible range, and then compares the experimental results of different methods generating a total of 500 adversarial test cases for each category at different imperceptible levels. The ADM metric shows that the adversarial test case method proposed in the present invention is always superior to other methods.

[0039] In another embodiment of the present invention, as Figure 14 shown, a highly dissimilar test case generation system under high imperceptibility constraints is also proposed. This system is a system corresponding to the highly dissimilar test case generation method under high imperceptibility constraints in the corresponding embodiment of Figure 1 , that is, it realizes the highly dissimilar test case generation method under high imperceptibility constraints in the corresponding embodiment of Figure 1 through a virtual system. Each virtual module constituting the system corresponding to the highly dissimilar test case generation method under high imperceptibility constraints can be executed by an electronic device, such as a network device, a terminal device, or a server. Specifically, the system includes: a pixel position contribution metric generation module 01, an SCSM matrix search module 02, a sorting module 03, an adversarial test case generation module 04, and a test effect evaluation module 05, where: The pixel position contribution metric generation module 01 is used to obtain the contribution parameter size of each pixel position to the classification of each category; The SCSM matrix search module 02 is used to obtain the SCSM matrix that describes the gap between each category through the classification weights of the activation function of the last layer of the DNN model by using the formula of cosine similarity; The sorting module 03 is used to calculate and judge that the contribution degree parameter of each category at each known pixel position and the SCSM matrix obtained for the high dissimilarity between the evaluation model categories have a higher contribution degree to the more highly dissimilar categories through weighted calculation, and then sort all pixels from large to small according to the results of each pixel for the next step; The adversarial test case generation module 04 is used to determine the optimal proportion of pixel positions to be selected when generating adversarial test cases. For 1000 original test pictures of 100 for each category in the test data sets of different data sets, after fixing the perturbation size, pixel positions with different proportions of pixel rankings are selected, and perturbations are added, and then the accuracy is compared to determine what the key pixel selection proportion of this data set is. As Figure 3 shown, in the MNIST, CIFAR-10, and STL-10 data sets, this proportion is determined to be 55%, 41%, and 18% respectively. After obtaining the proportion of perturbed pixel selection, different perturbation sizes of adversarial test cases are generated by adjusting the perturbation amplitude. Then, some existing adversarial test case generation methods NetSat and FGSM integrated in the system are used to generate adversarial test cases with basically similar imperceptibility to wait for the next module to evaluate the test effect of revealing model vulnerabilities.

[0040] The test effect evaluation module 05 is used to compare the efficiency of the adversarial test cases generated by different adversarial test case generation methods obtained by the above modules under the condition that the known imperceptibility is as similar as possible, and the generated test cases can reflect the errors of the model vulnerabilities, that is, the classification result is not equal to the category of the original picture, that is, the classification is incorrect. By Figure 5 Under different data sets and models, when the imperceptibility of the adversarial test cases generated by each method is fixed at basically the same size, the proportion of classification errors of the adversarial test cases generated by each method for 1000 original pictures in the test data set is observed. It is found that the efficiency of the present invention has not decreased too much, and through multiple experiments, it is found that it remains at about 1%-2%.

[0041] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for generating highly dissimilar test cases under the constraint of high imperceptibility, characterized in that including: Obtain a test image and input it into the DNN network model to obtain the classification probabilities of the test image in each test case category; Obtain the contribution degree of each pixel point in the corresponding test image according to the classification probability; Obtain the SCSM matrix of the test image between each test case category according to the weights of the fully connected layer of the last layer of the network model; Perform weighted calculation according to the contribution degree of each pixel point in the test image and the SCSM matrix to obtain the sorting index of each pixel; Sort the pixel points in the test image according to the sorting index of each pixel, and select the pixel points with the top sorting ranks to add perturbations to the test image; Obtain multiple test images and add perturbations respectively to obtain test cases.

2. The method for generating highly dissimilar test cases under high imperceptibility constraints according to claim 1, wherein: Obtain the contribution degree of each pixel point in the corresponding test image, including: Input the test image into the DNN network model to obtain the classification probabilities of the test image corresponding to each parameter category in the network model; Perform a partial derivative operation on the classification probability corresponding to each parameter category at the position of each pixel point in the test image to obtain the contribution degree corresponding to each pixel point.

3. The method for generating highly dissimilar test cases under a high imperceptibility constraint according to claim 1, characterized in that: Obtain the SCSM matrix of the test image between each test case category, including: Obtain the weight values corresponding to each test case category of the weights of the fully connected layer of the last layer in the network model; Calculate the cosine similarity between every two test case categories according to the weight values corresponding to each test case category; Establish the SCSM matrix according to the cosine similarity between every two test case categories.

4. The method for generating highly dissimilar test cases under the constraint of high imperceptibility according to claim 1, wherein: Perform weighted calculation according to the contribution degree of each pixel point in the test image and the SCSM matrix to obtain the sorting index of each pixel, and the expression is: ; Among them The contribution degree parameters corresponding to each pixel for k categories are respectively assigned the distance metrics in the SCSM matrix Indicates the contribution degree of the pixel point to each category Is the contribution degree of the i-th pixel point to the k-th category. If it is positive, it remains unchanged. If it is negative, it is assigned 0 5. The method for generating highly dissimilar test cases under the constraint of high imperceptibility according to claim 1, characterized in that: After selecting the pixel points with the top sorting ranks to add perturbations to the test image, it further includes: Select pixel points with different ratios for multiple test images to add perturbations respectively to obtain test images corresponding to different perturbation ratios; Evaluate the accuracy of the test images corresponding to different perturbation ratios, and select the test image with the lowest accuracy according to the evaluation results; Take the perturbation ratio corresponding to the test image with the lowest accuracy as the determined ratio.

6. The method for generating highly dissimilar test cases under the constraint of high imperceptibility according to claim 1, characterized in that: After obtaining the test cases, it further includes: Obtain the imperceptibility index of the test cases; Optimize according to the imperceptibility index of the test cases, and evaluate the high dissimilarity of the test cases according to the optimized imperceptibility index.

7. A highly dissimilar test case generation system under high imperceptibility constraints, adopting the highly dissimilar test case generation method under high imperceptibility constraints described in any one of claims 1-6, characterized in that, including: Pixel position contribution degree index generation module, SCSM matrix search module, sorting module, adversarial test case generation module and test effect evaluation module; The pixel position contribution degree index generation module is used to obtain a test image and input it into the DNN network model to obtain the classification probabilities of the test image in each test case category; obtain the contribution degree of each pixel point in the corresponding test image according to the classification probability; The SCSM matrix search module is used to obtain the SCSM matrix of the test image between each test case category according to the weights of the fully connected layer of the last layer of the network model; The sorting module is used to perform weighted calculation according to the contribution degree of each pixel point in the test image and the SCSM matrix to obtain the sorting index of each pixel; The adversarial test case generation module is used to sort the pixel points in the test image according to the sorting index of each pixel, and select the pixel points with the top sorting ranks to add perturbations to the test image; Obtain multiple test images and add perturbations to them respectively to obtain test cases; The test effect evaluation module is used to obtain the imperceptibility index of the test cases; optimize according to the imperceptibility index of the test cases, and evaluate the high dissimilarity of the test cases according to the optimized imperceptibility index.

Citation Information

Patent Citations

  • Screening method and application method and system of image semantic information sensitive pixel domain based on adversarial attack

    CN114220097A

  • Adversarial sample generation method, device and equipment and readable storage medium

    CN114331829A

  • Adversarial sample generation method and system based on multi-mode image

    CN116883759A

  • Method for generating disturbance sample

    CN117392431A

  • Gradient-guided test case generation method and system

    CN118193399A