Adversarial texture generation method

Through the adversarial texture generation method, the security challenges of the autonomous driving system at the image perception level are solved, and the adversarial texture with rich details is generated, which improves the robustness and obscureness of the system and enhances the anti-interference ability of the autonomous driving system.

CN120355589APending Publication Date: 2025-07-22BEIHANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510522326.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

At the image perception level, existing autonomous driving systems face the problems of limited generalization capabilities of model, unstable attack effects, poor dynamic adaptability, trade-offs on concealment and complexity, and low efficiency of adversarial sample generation. In addition, the spectral interference technology has strong environmental dependence, low concealment, high legal risks, and high manufacturing of physical attribute enhancement technology is difficult, high cost, and limited universality.

Method used

Adversarial texture generation method is adopted, by obtaining the original image of autonomous driving perception, extracting data features and adding perturbation features, using wavelet analysis and Fourier transform for multi-scale decomposition and perturbation, combining the generation of adversarial network and a physics-based simulation platform, a detailed adversarial texture is generated to enhance robustness and occultness.

Benefits of technology

The generated adversarial texture has high environmental similarity and unpredictability, effectively disrupts the image recognition system, improves the anti-interference ability of the autonomous driving system under the variable conditions of the real world, and enhances the safety and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120355589A_ABST
    Figure CN120355589A_ABST
Patent Text Reader

Abstract

The invention discloses an adversarial texture generation method. The method comprises the following steps: acquiring an original image sensed by automatic driving; extracting data features in the original image, wherein the data features comprise shape and boundary information, local features and frequency distribution features; disturbance is added to the data features, disturbance features are obtained, and the disturbance features comprise the first image, disturbance local features and disturbance frequency distribution features; performing inverse wavelet transform on the disturbance local feature to obtain a second image; performing inverse Fourier transform on the disturbance frequency distribution characteristics to obtain a third image; fusing the first image, the second image and the third image to obtain a to-be-optimized confrontation texture; and processing the original image and the to-be-optimized confrontation texture by using an adjacent environment sample generation module to obtain an optimized confrontation texture. According to the method, the confrontation with rich details and relatively high environmental similarity is generated, and the robustness and the concealment of the physical world attack confrontation sample are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of image data processing. Specifically, it relates to an adversarial texture generation method. Background Art

[0002] In the field of intelligent transportation, with the deep integration of advanced technologies such as deep learning, computer vision, high-precision positioning and navigation, autonomous driving vehicles demonstrate significant potential for improving safety and optimizing operation efficiency with their precise environmental perception, real-time decision-making and control capabilities. However, along with technological progress, the security challenges of autonomous driving systems have become increasingly prominent, especially at the level of image perception of the external environment, which has become an important breakthrough for hacker attacks and malicious interference.

[0003] In the prior art, the technology of single-iteration training has problems such as limited model generalization ability, unstable attack effect and single attack strategy; the dynamic adaptive attack technology faces challenges of real-time adaptability, trade-off between concealment and complexity, and the problem of adversarial sample generation efficiency; the spectral interference technology is highly dependent on the environment, has low concealment and is restricted by legal risks, while the physical property enhancement technology faces difficulties and high costs in manufacturing, requirements for persistence and maintenance, and limited generality. Summary of the Invention

[0004] The present invention is precisely proposed based on the above-mentioned needs of the prior art. The technical problem to be solved by the present invention is to provide an adversarial texture generation method to generate adversarial textures with rich details and high environmental similarity, and improve the robustness and concealment of physical-world attack adversarial samples.

[0005] To solve the above problems, the present invention is implemented by adopting the following technical solutions:

[0006] A method for generating adversarial textures is provided, which includes: obtaining the original image sensed by autonomous driving; extracting the data features in the original image, including: performing digital morphological processing on the original image to obtain shape and boundary information; performing multi-scale decomposition on the original image using wavelet analysis to obtain local features of different frequencies; performing Fourier transform on the original image to obtain frequency distribution features; adding perturbations to the data features to obtain perturbation features, including: adding perturbations to the shape and boundary information through depolarization noise to obtain the first image; adding random phase perturbations to the local features using phase decay noise to obtain perturbed local features; perturbing the frequency distribution features using amplitude decay noise to obtain perturbed frequency distribution features; performing inverse wavelet transform on the perturbed local features to obtain the second image; performing inverse Fourier transform on the perturbed frequency distribution features to obtain the third image; fusing the first image, the second image, and the third image to obtain the adversarial texture to be optimized; using the neighboring environment sample generation module to process the original image and the adversarial texture to be optimized to obtain the optimized adversarial texture, and the neighboring environment sample generation module includes a generative adversarial network and a physics-based simulation platform.

[0007] Optionally, based on digital morphology, the original image is processed to obtain shape and boundary information, and its expression is: where D(L,B) represents the set of pixel points obtained after performing morphological dilation operation on the original image L, z represents the position of the pixel points expanded after the dilation operation, l represents the position of the pixel points in the original image, L represents the original image, B(l) represents the structural element, ≤ represents the relative position relationship, and E(L,B) represents the set of pixel points obtained after performing morphological erosion operation on the original image L.

[0008] Optionally, using wavelet analysis to perform multi-scale decomposition on the original image to obtain local features of different frequencies, and its expression is: where, ψ j,k (x1) represents the wavelet basis function at scale j and position k, j represents the scale parameter, ψ() represents the wavelet basis function, x1 represents the spatial coordinate in the original image, k represents the position parameter, W j (x1) represents the local feature of the image at scale j, w j,k represents the wavelet coefficient.

[0009] Optionally, using Fourier transform to process the original image to obtain frequency distribution features, and its expression is: where F(u,v) represents the frequency distribution feature, u represents the horizontal frequency, v represents the vertical frequency, f(x,y) represents the original image, i represents the imaginary unit, x represents the horizontal coordinate in the spatial domain, and y represents the horizontal coordinate in the spatial domain.

[0010] Optionally, perturbations are added to the shape and boundary information through depolarizing noise to obtain a first image, including: where f shape (x, y) is the first image, ρ represents the shape and boundary information, I is the identity matrix, and p is the depolarization probability.

[0011] Optionally, random phase perturbations are added to the local features using phase decay noise to obtain perturbed local features, and its expression is: where Γ Z (t) is the perturbed local feature, φ(t) is the phase perturbation factor of the local feature W j (x1) under cumulative phases at different times, σ z is the Pauli-Z matrix, used to describe the projection of the quantum state on the z-axis, and γ z (t′) is the phase decay rate, t represents the current time, and t′ represents the integral variable time of the decay rate.

[0012] Optionally, the frequency distribution features are perturbed using amplitude decay noise to obtain perturbed frequency distribution features, and its expression is: where F(u, v)′ is the perturbed frequency distribution feature, represents the conjugate transpose of M0, represents the conjugate transpose of M1, and γ is the decay parameter, representing the coupling strength with the environment in terms of energy.

[0013] Optionally, the influence of quantum fidelity evaluation noise on the data features is evaluated, and its expression is: where F(a, b) represents the quantum fidelity, Tr is the trace operation, a represents the perturbed feature, and b represents the data feature.

[0014] Optionally, the inverse wavelet transform is performed on the perturbed local features to obtain a second image, and its expression is: where f local (x1) represents the second image, and w′ j,k represents the perturbed wavelet coefficients.

[0015] Optionally, the inverse Fourier transform is performed on the perturbed frequency distribution features to obtain a third image, and its expression is: f freq (x, y) = ∫∫F(u, v)′e i2π(ux+vy) du dv, where f frq (x, y) represents the third image.

[0016] Compared with the prior art, the present invention provides an adversarial texture generation method to improve the robustness and concealment of physical world attacks by generating a quantum noise sequence with high unpredictability and aperiodicity. The random nature of random texture generation makes it difficult to be recognized and filtered by traditional defense algorithms, effectively disrupting the image recognition system and inducing misjudgment. By introducing a generative adversarial network and physics-based simulation, the generated adversarial texture has a high environmental similarity and is not easily detectable. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the embodiments of this specification. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0018] Figure 1 It is a flowchart of an adversarial texture generation method provided in this embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0020] For ease of understanding of the embodiments of the present invention, the following will further explain with specific embodiments with reference to the drawings. The embodiments do not limit the scope of protection of the present invention.

[0021] This embodiment provides an adversarial texture generation method, as Figure 1 shown, including:

[0022] S1 Obtain the original image sensed by autonomous driving.

[0023] In this embodiment, the data collected from the sensors is integrated and processed to ensure the high quality and real-time nature of the data. The data collected from sensors such as vehicle images and lidar is synchronized to ensure the temporal consistency of the data of each sensor. Specifically, within a set time window, the data of each sensor is aligned and normalized according to the timestamp to reduce the delay and error caused by the difference in the response speed of different sensors and ensure the accuracy of the data.

[0024] The sensor data is subjected to multi-source fusion to obtain the original image, and its expression is:

[0025]

[0026] Among them, L represents the original image, and Z i represents the data of the i-th sensor, and w i represents the weight of the i-th sensor. The weight w i is dynamically adjusted according to the data requirements under different environmental conditions to obtain a more reliable data fusion effect in different situations. The process of weighted fusion is based on an optimization algorithm for dynamic weight allocation to ensure the accuracy and stability in the integration of multi-source data, thereby achieving high-quality data processing results.

[0027] S2 Extract the data features in the original image.

[0028] The data features include shape and boundary information, local features, and frequency distribution features.

[0029] In this step, it includes:

[0030] S200 Process the original image based on digital morphology to obtain shape and boundary information.

[0031]

[0032] Among them, D(L, B) represents the set of pixel points obtained after performing a morphological dilation operation on the original image L, z represents the position of the pixel points expanded after the dilation operation, l represents the position of the pixel points in the original image, L represents the original image, B(l) represents the structural element, represents the relative position relationship, and E(L, B) represents the set of pixel points obtained after performing a morphological erosion operation on the original image L.

[0033] The shape and boundary information plays an important role in describing the basic structure of the data and directly reflects the contour and overall shape of the object.

[0034] S210 Use wavelet analysis to perform multi-scale decomposition on the original image to obtain local features of different frequencies.

[0035] The local features are decomposed and expressed through different scales of wavelet transform, and can capture the detailed information of the image at various scales and positions.

[0036]

[0037] Among them, ψ j,k (x1) represents the wavelet basis function at scale j and position k, j represents the scale parameter, ψ() represents the wavelet basis function, x1 represents the spatial coordinate in the original image, k represents the position parameter, and W j(x1) represents the local feature of the image at scale j, and w j,k represents the wavelet coefficient.

[0038] S220 processes the original image using the Fourier transform to obtain the frequency distribution feature.

[0039] Through the Fourier transform, the data is transformed from the spatial domain to the frequency domain to obtain the frequency distribution feature of the data. Its expression is:

[0040]

[0041] where F(u, v) represents the frequency distribution feature, u represents the horizontal frequency, v represents the vertical frequency, f(x, y) represents the original image, i represents the imaginary unit, x represents the horizontal coordinate in the spatial domain, and y represents the horizontal coordinate in the spatial domain.

[0042] The frequency distribution feature reflects the distribution of data in different frequency components. The high-frequency components correspond to the details and edge information of the image, while the low-frequency components correspond to the overall structure of the image.

[0043] S3 adds perturbations to the data features to obtain the perturbed features.

[0044] The perturbed features include the first image, the perturbed local feature, and the perturbed frequency distribution feature.

[0045] In this step, it includes:

[0046] S300 adds perturbations to the shape and boundary information through depolarizing noise to obtain the first image.

[0047] The shape and boundary information is sensitive to small-amplitude random perturbations. Therefore, depolarizing noise can effectively simulate the effects of edge blurring and morphological random fluctuations, thereby increasing the robustness of the system. Its expression is:

[0048]

[0049] where f shape (x, y) is the first image, ρ represents the shape and boundary information, I is the identity matrix, p is the depolarization probability, and its value range is 0 ≤ p ≤ 1.

[0050] In this embodiment, the value of p is appropriately adjusted so that the influence of depolarizing noise on the shape and boundary information is controllable to simulate the blurring effects of edges and shape contours under noise conditions. A higher p value will result in a greater degree of blurring, while a lower p value can maintain the relative clarity of the boundary.

[0051] S310 adds random phase perturbations to the local feature using phase decay noise to obtain the perturbed local feature.

[0052] For local features, phase decay noise is used to simulate the random phase perturbations of detailed features at different scales. Phase decay noise introduces an uncertainty, causing phase perturbations at different levels of detail, which conforms to the variation trend of detailed features in the actual noise environment. The expression of phase decay noise is as follows:

[0053]

[0054] where Γ Z (t) is the perturbed local feature, φ(t) is the phase perturbation factor of the local feature W j (x1) under cumulative phases at different times, σ Z is the Pauli-Z matrix, used to describe the projection of the quantum state on the z-axis, and γ Z (t′) is the phase decay rate, t represents the current time, and t′ represents the integration variable time of the decay rate.

[0055] By adjusting the value of γ Z (t′), the degree of phase decay can be controlled, thereby introducing phase perturbations at different scales, enabling local features to maintain a certain robustness under random phase changes.

[0056] In this step, various random perturbations faced by a real quantum system are mainly simulated based on the decoherence process in quantum mechanics. These perturbations can stem from environmental interactions, control errors, material defects, etc., and are manifested as phenomena such as decoherence, phase decay, and amplitude decay of qubit states. Using quantum randomness to interfere with the image sensor of an autonomous vehicle, resulting in target detection failure and incorrect road condition understanding, enhances the attack effect; its unpredictability makes the attack behavior difficult to identify. By finely controlling the intensity and distribution of quantum noise, it is ensured that while the attack behavior interferes with the target system, it does not cause excessive perturbations to the surrounding environment.

[0057] S320 uses amplitude decay noise to perturb the frequency distribution characteristics, obtaining perturbed frequency distribution characteristics.

[0058] For the frequency distribution characteristics, amplitude decay noise is used for interference to obtain the perturbed frequency distribution characteristics, and its expression is:

[0059]

[0060] where F(u,v)′ is the perturbed frequency distribution characteristic, M0 is the Kraus operator of the amplitude decay channel, represents the conjugate transpose of M0, M1 is the Kraus operator of the amplitude decay channel, Denote the conjugate transpose of M1, and γ is the attenuation parameter, representing the coupling strength with the environment in terms of energy. By controlling the value of γ, random amplitude variations can be introduced in the high-frequency components of the spectrum, thereby simulating the variations of different frequency distribution characteristics in a noisy environment.

[0061] The introduction of amplitude attenuation noise can simulate the fluctuations in amplitude of frequency components, especially in the high-frequency part, and enhance the tolerance to high-frequency noise through randomly varying amplitude interference.

[0062] Furthermore, to evaluate the impact of noise on data characteristics, quantum fidelity is adopted as a quantization index to ensure the robustness of the system under different noise conditions. Quantum fidelity is used to measure the similarity between perturbed characteristics and data characteristics, and its expression is:

[0063]

[0064] Among them, F(a, b) represents quantum fidelity, Tr is the trace operation, a represents the perturbed characteristics, and b represents the data characteristics.

[0065] If the fidelity value is higher, it indicates that the perturbation of noise to data characteristics is smaller and the anti-interference ability is stronger; if the fidelity is lower, it means that the impact of noise on data characteristics is larger and the robustness is lower. Through the calculation of the fidelity value, the quantitative analysis of the effect of quantum noise injection is realized, and the depolarization probability p, the phase attenuation rate γ Z (t′) and the amplitude attenuation parameter γ noise parameter are adjusted according to needs, so as to realize the robustness optimization of characteristic data.

[0066] S4 performs an inverse wavelet transform on the perturbed local characteristics to obtain the second image.

[0067] Perform an inverse wavelet transform on the local characteristics after wavelet decomposition to restore it from the wavelet domain to the spatial domain, and its expression is:

[0068]

[0069] Among them, f local (x1) represents the second image, and w′ j,k represents the perturbed wavelet coefficients.

[0070] This step restores the perturbed local characteristics from the multi-scale decomposition representation to the spatial domain, enabling it to maintain a consistent representation form with other characteristics during fusion.

[0071] S5 performs an inverse Fourier transform on the perturbed frequency distribution characteristics to obtain the third image.

[0072] Perform an inverse Fourier transform on the perturbed frequency distribution characteristics to convert it from the frequency domain back to the spatial domain, and its expression is:

[0073] f freq (x, y) = ∫∫F(u, v)'e i2π(ux+vy) du dv

[0074] where f freq (x, y) represents the third image.

[0075] Regress the perturbation frequency distribution feature to the original spatial domain so as to fuse it with other features in the same domain.

[0076] S6 Fuse the first image, the second image and the third image to obtain the adversarial texture to be optimized.

[0077] For the shape and boundary information, since this feature has completed operations in the spatial domain and no additional inverse transformation steps are required, directly fuse the first image f shape (x, y), the second image f local (x) and the third image f freq (x, y). In the fusion stage, superimpose or combine the above feature images restored to the spatial domain to generate the final perturbation image f final (x, y), which contains the random perturbations of each layer of features. The fusion process can be expressed as:

[0078] f final (x, y) = αf shape (x, y) + βf local (x, y) + ηf freq (x, y)

[0079] where α represents the fusion weight parameter of the first image, β represents the fusion weight parameter of the second image, and η represents the fusion weight parameter of the third image, which are used to control the contribution degrees of different features in the final image. By adjusting these weights, the interference effects of shape, local features and frequency distribution features can be balanced in the generated image to make it more in line with the actual application requirements.

[0080] S7 Use the neighboring environment sample generation module to process the original image and the adversarial texture to be optimized to obtain the optimized adversarial texture.

[0081] The neighboring environment sample generation module is a physical information generation adversarial network for neighboring environment synthesis. The neighboring environment sample generation module includes a generative adversarial network and a physics-based simulation platform. By combining the powerful generation ability of the generative adversarial network with the realism of the physics-based simulation platform, samples with rich details and high environmental similarity are generated. First, collect the real environment data distribution P from vehicle images, lidar, etc. data, and then extract the key features of the input data. Finally, by continuously iterating and optimizing the generator and discriminator in the generative adversarial network, more realistic samples are generated. By learning the features and physical laws in the real environment, the adversarial generation produces samples with correct light and shadow, similar to the environmental materials, and dynamic changes. The physical information generative adversarial network expression for neighboring environment synthesis is as follows:

[0082]

[0083] Among them, V(D, G) represents the target value, G represents the generator network, and D represents the discriminator network. denotes the expectation calculation for the sample x sampled from the real data distribution P data , where x ∼ P data means that the sample x follows the distribution P of the real environment data. data , denotes the expectation calculation for the random vector z sampled from the noise data distribution P z . E represents the expected value, and P data represents the real environment data distribution. D(x) is the probability that the discriminator gives for the input x being real data. P z represents the noise data distribution, where z ∼ P z refers to the prior perturbation distribution P z from which a random vector is drawn as the input to the generator. G(z, φ) means that after the generator G receives the inputs of the perturbation z and the physical parameter φ, it generates an output with a high environmental approximation degree.

[0084] Furthermore, evaluate the effect of the adversarial samples in the actual environment and their impact on the system. By comparing with the original image, calculate the probability that the adversarial samples cause misjudgment of the model. Specifically, set the evaluation criteria and metrics, collect the response data of the model under normal and adversarial samples, and evaluate the effectiveness of the adversarial samples through statistical analysis methods such as error rate analysis. The calculation formula for the evaluation metrics is as follows:

[0085]

[0086] Among them, P represents the probability that the adversarial samples cause misjudgment, N represents the number of test samples, and σ represents the sigmoid activation function, which is used to convert the output of the loss function into a probability. represents the loss function, which measures the difference between the model prediction and the true label. y i represents the true label of the i-th sample, f represents the deep learning model for evaluation, and x′ i represents the i-th adversarial sample.

[0087] According to the evaluation results, further adjust the generation of the texture, iterate and optimize the attack strategy to ensure the effectiveness of the attack. Specifically, an optimizer based on gradient descent is adopted to adjust the parameters of the generative adversarial network by minimizing the adversarial loss function between the generator network and the discriminator network. The adversarial loss function consists of two parts: the loss of the generator network and the loss of the discriminator network. The loss objective of the generator network is to minimize the output of the discriminator, while the loss objective of the discriminator network is to maximize the output of the discriminator.

[0088] Furthermore, the method further includes using a metasurface holographic optical camouflage module to produce a high-fidelity optical camouflage, providing visual misleading elements for physical attacks. The metasurface holographic optical camouflage module integrates metamaterial science, holographic imaging technology and intelligent control strategies. In the metasurface holographic optical camouflage module, an ultrathin film constructed by sub-wavelength artificial structures is used to achieve precise manipulation of the incident light field. The metasurface unit can finely control the phase, amplitude, polarization and even wavelength of light at the nanoscale, thereby forming a highly complex light field distribution in space. The metasurface holographic optical camouflage module enhances the attack power by generating high-fidelity illusions that blend in with the environment, such as pseudo-signs and obstacles, to induce the vehicle to make wrong decisions; at the same time, it can match the ambient light and background in real time and does not require physical occlusion, making the attack device invisible.

[0089] In this embodiment, by extracting the key features of the input data, adversarial textures with rich details and high environmental similarity are generated, and the generated adversarial textures are unpredictable and non-periodic, improving the test and evaluation capabilities of the autonomous driving system under various real-world conditions (such as different lighting and angles), enhancing the anti-interference ability of the autonomous driving system, effectively improving the defense ability of the autonomous driving system against covert attacks, and increasing the overall security and reliability of the system.

[0090] The specific embodiments described above further elaborate on the purpose, technical solutions and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for generating adversarial textures, characterized in that, Including: Obtain the original image of autonomous driving perception; Extract the data features in the original image, including: processing the original image based on digital morphology to obtain shape and boundary information; performing multi-scale decomposition on the original image using wavelet analysis to obtain local features of different frequencies; performing Fourier transform on the original image to obtain frequency distribution features; Add perturbations to the data features to obtain perturbed features, including: adding perturbations to the shape and boundary information through depolarization noise to obtain a first image; adding random phase perturbations to the local features using phase decay noise to obtain perturbed local features; perturbing the frequency distribution features using amplitude decay noise to obtain perturbed frequency distribution features; Perform inverse wavelet transform on the perturbed local features to obtain a second image; perform inverse Fourier transform on the perturbed frequency distribution features to obtain a third image; fuse the first image, the second image, and the third image to obtain the adversarial texture to be optimized; Use the neighboring environment sample generation module to process the original image and the adversarial texture to be optimized to obtain the optimized adversarial texture, and the neighboring environment sample generation module includes a generative adversarial network and a physics-based simulation platform.

2. The anti-texture generation method according to claim 1, wherein Processing the original image based on digital morphology to obtain shape and boundary information, and its expression is: Where D(L,B) represents the set of pixel points obtained after performing morphological dilation operation on the original image L, z represents the position of the pixel points expanded after the dilation operation, l represents the position of the pixel points in the original image, L represents the original image, B(l) represents the structural element, ≤ represents the relative position relationship, and E(L,B) represents the set of pixel points obtained after performing morphological erosion operation on the original image L.

3. A method for generating an adversarial texture according to claim 1, wherein Performing multi-scale decomposition on the original image using wavelet analysis to obtain local features of different frequencies, and its expression is: Among them, ψ j,k (x1) represents the wavelet basis function at scale j and position k, where j represents the scale parameter, ψ( ) represents the wavelet basis function, x1 represents the spatial coordinate in the original image, k represents the position parameter, and W j (x1) represents the local feature of the image at scale j, and w j,k represents the wavelet coefficient.

4. A method for generating an adversarial texture according to claim 1, characterized in that Performing Fourier transform on the original image to obtain frequency distribution features, and its expression is: Where F(u,v) represents the frequency distribution feature, u represents the horizontal frequency, v represents the vertical frequency, f(x,y) represents the original image, i represents the imaginary unit, x represents the horizontal coordinate in the spatial domain, and y represents the horizontal coordinate in the spatial domain.

5. A method for generating an adversarial texture according to claim 1, characterized in that Adding perturbations to the shape and boundary information through depolarization noise to obtain a first image, including: Among them, f shape (x, y) is the first image, ρ represents the shape and boundary information, I is the identity matrix, and p is the depolarization probability.

6. A method for generating an adversarial texture according to claim 3, characterized in that, Adding random phase perturbations to the local features using phase decay noise to obtain perturbed local features, and its expression is: Among them, Γ z (t) is the perturbed local feature, and φ(t) is the phase perturbation factor of the local feature W j (x1) under different time accumulations, and σ z is the Pauli-Z matrix, which is used to describe the projection of the quantum state on the z-axis, and γ z (t′) is the phase decay rate, t represents the current time, and t′ represents the integral variable time of the decay rate.

7. A method for generating an adversarial texture according to claim 4, characterized in that, Perturbing the frequency distribution features using amplitude decay noise to obtain perturbed frequency distribution features, and its expression is: Among them, F(u, v)′ is the disturbance frequency distribution characteristic, denotes the conjugate transpose of M0, denotes the conjugate transpose of M1, and γ is the attenuation parameter, representing the coupling strength with the environment in terms of energy.

8. A method for generating an adversarial texture according to claim 1, characterized in that, Evaluating the influence of quantum fidelity assessment noise on the data features, and its expression is: Where F(a,b) represents the quantum fidelity, Tr is the trace operation, a represents the perturbed feature, and b represents the data feature.

9. A method for generating an adversarial texture according to claim 6, wherein Performing inverse wavelet transform on the perturbed local features to obtain a second image, and its expression is: Among them, f local (x1) represents the second image, and w′ j,k represents the wavelet coefficients after perturbation.

10. A method for generating an adversarial texture according to claim 7, characterized in that, Performing inverse Fourier transform on the perturbed frequency distribution features to obtain a third image, and its expression is: f freq (x, y) = ∫∫F(u, v)'e i2π(ux+vy) du dv Among them, f freq (x, y) represents the third image.