Self-adaptive evolutionary adversarial attack method for insulator defect detection model

Through the adaptive evolution of the adversarial attack method, translucent circular perturbation is generated and the perturbation vector is optimized, which solves the problem of the high-dimensional search space of the insulator defect detection model in black box attack, achieves an efficient and undetectable attack effect, and improves the safety and reliability of the power system.

CN120410982APending Publication Date: 2025-08-01ZHEJIANG XIANGFENG ENG DESIGN CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510407608.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing insulator defect detection models have high-dimensional search space challenges when facing black box attacks, and are susceptible to minor perturbations that lead to misprediction, affecting the safety and reliability of the power system.

Method used

Adaptive evolutionary adversarial attack method is adopted, by generating translucent circular perturbations and RGB values perturbations, combining adaptive differential evolution algorithm to optimize the perturbation vector, adjust the pixel value using a repair function, and design the adaptive fitness function to maximize the attack success rate and imperceptibility.

Benefits of technology

It significantly improves the efficiency and success rate of black box attacks, ensures that disturbances deceive the detection model when it is difficult for human eyes to detect, enhances the security protection capabilities of the smart grid system, and the attack success rate can reach 81.25%, improving the robustness of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120410982A_ABST
    Figure CN120410982A_ABST
Patent Text Reader

Abstract

The invention relates to a self-adaptive evolution adversarial attack method for an insulator defect detection model. The method comprises the following steps: acquiring an original insulator image; based on the original insulator image, generating an initial disturbance vector by adopting a semitransparent circle and RGB value disturbance generation method, and superposing the initial disturbance vector into the original insulator image to obtain an initial confrontation image; optimizing the generation process of the initial disturbance vector based on an adaptive differential evolution algorithm to obtain an optimized disturbance vector and an optimized confrontation image; carrying out restoration processing on the optimized confrontation image to obtain a restored confrontation image; and inputting the repaired confrontation image into an insulator defect detection model, and outputting an attack success rate to complete a confrontation attack process. Compared with the prior art, the method has the advantages of optimizing the attack effect and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of adversarial attacks, and in particular, to an adaptive evolutionary adversarial attack method for an insulator defect detection model. Background Art

[0002] With the development of smart grid technology, the requirements for the safety and reliability of equipment in the power system are becoming increasingly stringent. Patent CN118038343B discloses a smart grid adversarial image generation method, device, storage medium, and terminal device, which improve the robustness of the smart grid by generating an adversarial image corresponding to the original image of the target to be detected in the smart grid. And patent application CN112149609A discloses a black-box adversarial sample attack method for a neural network classification model of power quality signals, which improves the attack success rate by generating adversarial signals and has a high probability of misclassifying the power quality signals by the target neural network system.

[0003] Insulators, as key components in the power transmission system, their defect detection is crucial for ensuring the stable operation of the power system. However, although existing insulator defect detection models based on deep neural networks (DNNs) have achieved good results on large-scale datasets, these models are still vulnerable to adversarial attacks. Adversarial attacks can cause the detection model to produce incorrect predictions through tiny perturbations, which may pose serious risks in the security monitoring of the power system. Therefore, researching adversarial attacks against insulator defect detection models and their defense mechanisms has become an important research direction for improving the robustness of the models.

[0004] Current research on adversarial attacks mainly focuses on white-box attack methods, which usually require access to the internal structure and parameters of the model and have certain limitations. In contrast, black-box attack methods only rely on input-output behavior and have stronger practical application significance, but face the challenge of high-dimensional search spaces. Summary of the Invention

[0005] The purpose of the present invention is to provide an adaptive evolutionary adversarial attack method for an insulator defect detection model that maximizes the attack success rate.

[0006] The purpose of the present invention can be achieved through the following technical solutions:

[0007] An adaptive evolutionary adversarial attack method for an insulator defect detection model includes the following steps:

[0008] Obtain the original insulator image;

[0009] Based on the original insulator image, generate an initial perturbation vector using a semi-transparent circle and an RGB value perturbation generation method, and superimpose it on the original insulator image to obtain an initial adversarial image;

[0010] Optimizing the generation process of the initial perturbation vector based on an adaptive differential evolution algorithm to obtain an optimized perturbation vector and an optimized adversarial image;

[0011] Performing restoration processing on the optimized adversarial image to obtain a restored adversarial image;

[0012] The repaired adversarial image is input into the insulator defect detection model, and the attack success rate is output to complete the adversarial attack process.

[0013] Furthermore, the step of generating an initial disturbance vector includes:

[0014] Define the perturbation vector δ and initialize it with random initialization or initial value based on insulator characteristics, where each perturbation vector δ i The parameters include the coordinates of the center of the circle (δ i1 ,δ i2 ), circle radius δ i3 , RGB color value (δ i4 ,δ i5 ,δ i6 ) and transparency δ i7 ;

[0015] According to each disturbance vector δ i , generating a semi-transparent circular disturbance;

[0016] The multiple semi-transparent circular disturbances are spliced according to the disturbance vector δ to form an overall initial disturbance vector δ.

[0017] Furthermore, the process of generating the semi-transparent circular disturbance includes:

[0018] According to each disturbance vector δ i Parameters, determine the center position (x, y) of the circle, and set the radius of the circle;

[0019] According to the insulator characteristics, the RGB color value is set, and then the transparency value is set to obtain a semi-transparent circular disturbance.

[0020] Furthermore, the step of obtaining the optimized disturbance vector includes:

[0021] Population initialization: Latin hypercube sampling is used to uniformly generate an initial population in the high-dimensional search space, where the population is the generated initial perturbation vector;

[0022] Parallel evolution: For each population member in the initial population, calculate the fitness of each population member in parallel and perform evolutionary operations in parallel. Select the population members with better fitness to enter the next generation population, where the evolutionary operations include mutation, crossover recombination, and selection operations;

[0023] Adaptive mutation factor adjustment: Dynamically adjust the mutation factor in the mutation operation according to the diversity and fitness variance of the population;

[0024] Enhanced selection mechanism: Based on the current population, comprehensively evaluate the fitness of each candidate solution by combining global comparison, local comparison, and comparison of current population members, and select the optimal solution, where the candidate solution is a trial solution generated from the original individuals based on evolutionary operations in the current iteration.

[0025] Furthermore, the Latin hypercube sampling method is used for the population initialization operation.

[0026] Furthermore, the optimized adversarial image is adjusted pixel by pixel through a repair function for repair processing to obtain the repaired adversarial image.

[0027] Furthermore, the steps of repair processing through the repair function include:

[0028] Pixel value range limitation: For each pixel of the optimized adversarial image, ensure that each pixel value satisfies:

[0029]

[0030] where I adv (i) is the pixel value of the optimized adversarial image at position i, ∈∈[0,1] is the defined perturbation limit, and I(i) is the pixel value of the original image at position iii;

[0031] Pixel value adjustment: Traverse all pixels of the optimized adversarial image and perform pixel-by-pixel adjustment according to the set pixel value range to obtain the repaired adversarial image.

[0032] Furthermore, the following steps are also included:

[0033] Before generating the optimized adversarial image, based on the optimized perturbation vector, use the Hungarian matching algorithm to match the predicted bounding box and the ground truth bounding box to construct an adaptive fitness function to evaluate the optimized perturbation, so as to further guide the perturbation optimization. The specific construction process includes:

[0034] Use the insulator defect detection model to perform classification prediction on the repaired adversarial image to obtain the classification prediction result;

[0035] Calculate the classification loss according to the classification prediction result;

[0036] Calculate the difference from the ground truth bounding box according to the predicted bounding box in the classification prediction result to obtain the bounding box loss;

[0037] Obtain the Generalized IoU loss according to the Generalized IoU between the predicted bounding box and the ground truth bounding box in the classification prediction result;

[0038] According to the classification loss, the bounding box loss, and the Generalized IoU loss, and combined with the corresponding weight parameters, obtain an adaptive fitness function, where the adaptive fitness function is used as the total loss function of the perturbation generation process, and the perturbation optimization is guided by minimizing the total loss function. The expression of the total loss function is:

[0039] L total = λ cls ·L cls + λ bbox ·L bbox + λ giou ·L giou

[0040] In the formula, L total is the total loss, λ cls , λ bbox , λ giou are weight parameters, L cls is the classification loss, L bbox is the bounding box loss, and L giou is the Generalized IoU loss.

[0041] Furthermore, the insulator defect detection model includes a model constructed by using any one or more of MSFFT, DETR, YOLO series, and Faster R-CNN networks.

[0042] Furthermore, it further includes the following steps:

[0043] Quantitatively evaluate the visual quality of the repaired adversarial image by using the peak signal-to-noise ratio and the structural similarity index.

[0044] Compared with the prior art, the present invention has the following beneficial effects:

[0045] (1) The present invention uses a semi-transparent shape with RGB values to generate perturbations, simulating the insulator shape and characteristic attributes, effectively reducing the high-dimensional search space, improving the efficiency of black-box attacks. At the same time, through the combination of the adaptive differential evolution algorithm and the enhanced adaptive repair operation, the imperceptibility of the perturbations is ensured, and the attack success rate is maximized.

[0046] (2) The present invention introduces an adaptive differential evolution algorithm to adaptively optimize the initial perturbation. Through operations such as parallel evolution, adaptive mutation factor adjustment, and enhanced selection mechanism, this algorithm not only improves the convergence speed of the algorithm but also improves the quality of the solution, that is, it improves the processing speed and the generated adversarial perturbation has powerful attack ability and high efficiency.

[0047] (3) The present invention adjusts each pixel value through a repair function to ensure that the pixel values of the perturbed image are still within the specified range and maintain similarity with the original image, so that the perturbation can effectively deceive the detection model when it is difficult to be detected by the human eye, improving the concealment and effectiveness of the adversarial attack; a fitness optimization function is used to optimize the effectiveness of the perturbation, and then guide the optimization of the attack strategy; through repair and fitness optimization, it is ensured that the perturbation is almost imperceptible to the human eye, thus enhancing the security protection ability of the smart grid system.

[0048] (4) The present invention generates imperceptible tiny perturbations, enhancing the mining and attack effects on the vulnerable points of existing detection models. Experiments show that it can achieve an attack success rate of up to 81.25% in a variety of existing detection models, significantly improving the efficiency of adversarial attacks. By retraining the model, the robustness of adversarial samples can be increased to effectively enhance the model's ability to resist adversarial attacks. In addition, the present invention can not only analyze the vulnerabilities of existing insulator defect detection models but also provide an effective technical means for improving the security and reliability of the smart grid. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 is a schematic flow chart of the method of the present invention;

[0050] Figure 2 is a schematic flow chart of the method of the embodiment of the present invention;

[0051] Figure 3 is the semi-transparent circle perturbation of the embodiment of the present invention;

[0052] Figure 4 is the parallel computing process of the embodiment of the present invention;

[0053] Figure 5 is the process of adding an unconstrained perturbation δ to the original image of the embodiment of the present invention;

[0054] Figure 6 is the influence of the adversarial attack on the MSFFT model and the detection results before and after the attack in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. This embodiment is implemented on the premise of the technical solution of the present invention, and gives the detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to the following embodiments.

[0056] This embodiment provides an adaptive evolutionary adversarial attack method for an insulator defect detection model. As Figure 1 shown, this method includes the following steps:

[0057] This embodiment provides an adaptive evolutionary adversarial attack method for an insulator defect detection model, abbreviated as AIEA. As Figure 1 shown, this method reveals the vulnerability of these models in the smart grid environment by introducing adversarial attacks into the existing insulator defect detection models. Specifically, the AIEA method generates perturbations using semi-transparent shapes with RGB values, effectively reducing the high-dimensional search space, and optimizes the attack effect by combining an adaptive differential evolution strategy (EDEAS). Without significantly changing the image content, it successfully causes the detection model to misjudge. This method aims to solve the problem that adversarial attacks in current insulator defect detection technologies are vulnerable due to model vulnerability. Existing insulator defect detection models are prone to produce incorrect predictions in the face of minor perturbations, thus affecting the safety and reliability of the power system. For this reason, the present invention enhances the mining of vulnerable points and the attack effect on existing detection models by generating imperceptible minor perturbations.

[0058] Specifically, as Figure 1 shown, this method adopts the following technical means:

[0059] 1. Construct a perturbation generation module

[0060] The present invention proposes a perturbation generation method based on semi-transparent circles and RGB values. This method uses circular perturbations similar to insulators to deceive the detection model by adding circular perturbations with lower transparency in the image, thereby improving the effectiveness of adversarial attacks.

[0061] Step 1: Definition and initialization of perturbation parameters: Define the perturbation vector δ as composed of the splicing of multiple circular perturbations, and each circular perturbation δ i contains the center coordinates (δ i1 , δ i2 ), the circle radius δ i3 , the RGB color values (δ i4 , δ i5 , δ i6 ) and the transparency δ i7 and other parameters. This method significantly reduces the high-dimensional search space by simulating the insulator shape and characteristic attributes, and improves the efficiency of the attack.

[0062] Step 2: Generation of semi - transparent circular perturbations: According to the perturbation vector δ i , generate semi - transparent circular perturbations, as shown in Figure 3 . Specifically, the generation process of each perturbation is as follows:

[0063] In the present invention, δ i represents the perturbation of the i - th circle, which includes the following seven parameters:

[0064] a) δ i1 , δ i2 : The center coordinates of the circle, that is, the center position of the circle, expressed as x and y coordinates, i.e., (x, y).

[0065] b) δ i3 : The radius of the circle, representing the size of the circle.

[0066] c) δ i4 , δ i5 , δ i6 : The RGB color value of the circle, ensuring that the color is similar to the insulator characteristics.

[0067] d) δ i7 : The transparency value of the circle, with a value range of (0, 1), representing the transparency degree of the circle.

[0068] Each perturbation δ i can be represented by a vector containing seven elements, that is:

[0069] δ i =(δ i1 , δ i2 , δ i3 , δ i4 , δ i5 , δ i6 , δ i7 ) T (1)

[0070] Step 3: Perturbation splicing and image superposition: Splice multiple semi - transparent circular perturbations according to the perturbation vector δ to form the overall perturbation vector δ and superimpose the generated perturbations onto the original image to generate the adversarial image I adv . By continuously iteratively adding these semi - transparent circular perturbations, the present invention can effectively mislead the detection model and enhance the success rate of the adversarial attack.

[0071] 2. Introduction of the Adaptive Differential Evolution Algorithm (EDEAS)

[0072] Based on the Differential Evolution Algorithm (DE), this invention proposes an improved differential evolution algorithm, namely the Adaptive Differential Evolution Algorithm (EDEAS), which optimizes the perturbation generation process to improve the attack success rate. By introducing parallel computing and adaptive adjustment strategies, the convergence speed and solution quality of the algorithm are enhanced. EDEAS uses PyTorch for parallel computing, accelerating the mutation, recombination, and selection operations during the evolution process. The key steps include:

[0073] Step 1: Population initialization: First, use the Latin Hypercube Sampling (LHS) method to uniformly generate the initial population in the high-dimensional search space to ensure the diversity of the population and prevent the algorithm from falling into local optima. Then, according to the complexity of the attack task and computing resources, set an appropriate population size to balance the search efficiency and optimization effect.

[0074] Step 2: Parallel computing implementation:: EDEAS uses PyTorch to perform parallel processing on multiple cores, reducing the computing burden and accelerating the convergence process. Specifically, based on the PyTorch framework, utilize its parallel computing ability to simultaneously perform mutation, recombination, and selection operations on a multi-core processor, significantly accelerating the evolution process. To reasonably allocate computing resources, optimize the scheduling and execution of parallel computing tasks, and improve the overall efficiency and response speed of the algorithm. The specific parallel computing process is as Figure 4 shown. First, start the parallel evolution algorithm and generate the initial population, then divide the population into multiple subsets and allocate them to each core. After receiving the corresponding individual sets, multiple cores (such as CORE 1, CORE 2 to CORE n) independently execute the evolution operations simultaneously, including mutation vector generation, trial vector recombination, boundary repair, and fitness evaluation and selection. During the evolution process, to enhance the global search ability and information exchange, based on the parallel execution of each core, enhance the population diversity through individual migration and inter-population competition to improve the diversity maintenance ability and convergence stability of the algorithm. Finally, after each round of evolution, determine whether the termination condition (such as the maximum number of iterations or fitness threshold) is met. If not, continue the iteration until the algorithm converges to obtain the optimal solution.

[0075] Step 3: Adaptive mutation factor adjustment: First, dynamically adjust the mutation factor F according to the diversity and fitness variance of the current population to ensure that the algorithm has good exploration and exploitation capabilities at different stages. Combine the change trend of the population fitness to adjust the value of F to balance the exploration ability and local search ability of the population and improve the convergence speed and solution quality of the algorithm.

[0076] Step 4: Enhance the selection mechanism: First, adopt a combination of global comparison, local comparison, and current member comparison to comprehensively evaluate the fitness of each candidate solution and select the optimal solution. Then, screen out individuals with excellent performance at different levels, retain the optimal members, maintain the diversity of the population, and prevent the algorithm from falling into local optima.

[0077] Through the application of EDEAS, the perturbation generation process can search for effective perturbations more efficiently, significantly improving the success rate and optimization efficiency of adversarial attacks, and ensuring that the finally generated adversarial perturbations have strong attack capabilities and high efficiency.

[0078] 3. Repair function design

[0079] The present invention designs a repair function to ensure that the generated adversarial image remains visually similar to the original image. The repair operation adjusts each pixel value to ensure that the pixel values of the perturbed image are still within the specified range, maintaining similarity with the original image. The specific implementation steps are as follows:

[0080] Step 1: Pixel value range limitation: Perform per-pixel adjustment on the perturbed image I adv to ensure that each pixel value satisfies the following conditions:

[0081]

[0082] where: I adv (i) is the pixel value of the adversarial image at position i, I(i) is the pixel value of the original image at position i, and ∈∈[0,1] is the user-defined perturbation limit.

[0083] This repair function ensures that the value of each pixel remains within the range of [I(i) - ∈, I(i) + ∈], so that the perturbation can effectively deceive the detection model without being easily noticed by the human eye.

[0084] Step 2: Pixel value adjustment: Traverse all pixels of the adversarial image and adjust each pixel value according to the above formula to ensure that the perturbed image is highly visually similar to the original image and avoid obvious visual differences.

[0085] Step 3: Generated image after repair: Output the adversarial image I adv processed by the repair function for subsequent evaluation by the detection model to ensure visual consistency of the image and concealment of the perturbation.

[0086] Through the design of the repair function, it is ensured that the adversarial perturbation can successfully deceive the detection model without significantly changing the appearance of the image, enhancing the concealment and effectiveness of the adversarial attack. Figure 5 Shows the process of adding an unconstrained perturbation δ to the original image and then using the repair function for adjustment.

[0087] 4. Adaptive Fitness Function Design and Optimization

[0088] The present invention designs a fitness function to evaluate the deception effect of the generated adversarial perturbation on the detection model. This function is based on the performance of the adversarial perturbation-generated image during the model inference process and measures the interference ability of the perturbation on the detection result. To ensure the accuracy and rationality of loss calculation, the Hungarian Matching algorithm is introduced after the model output to optimally allocate the predicted bounding boxes and the ground truth bounding boxes, thus avoiding the error caused by multiple predicted bounding boxes matching the same target. This matching process enhances the fairness and stability of subsequent loss evaluation by minimizing the overall matching cost. The fitness function calculates the loss obtained from the matching result after the image generated by the adversarial perturbation is processed by the detection model (such as MSFFT) and the Hungarian Matching. Specifically, the fitness function includes the following three parts:

[0089] Step 1: Classification loss (Lcls) calculation: The classification loss (L cls ): Measures the accuracy of target class recognition.

[0090] Step 2: Bounding box loss (L bbox ) calculation: The bounding box loss (L bbox ): Measures the accuracy of target bounding box prediction.

[0091] Step 3: Generalized IoU loss (L giou ) calculation: The generalized IoU loss (L giou ): Measures the overlap degree between the predicted bounding box and the ground truth bounding box.

[0092] Total loss calculation: According to the preset weight parameters λ cls , λ bbox , λ giou , calculate the total loss. The total loss function serves as the adaptive fitness function, and the fitness function is calculated by the following formula:

[0093] L total = λ cls · L cls + λ bbox · L bbox + λ giou · L giou (3)

[0094] Where λ cls , λ bbox , λ giou represent the weights of each loss term respectively, and through this function, the effectiveness of the perturbation can be quantified, thereby guiding the optimization of the attack strategy.

[0095] Fitness evaluation and optimization: By minimizing the total loss L total , evaluate the effectiveness of the perturbation and guide the EDEAS to optimize the perturbation generation strategy to improve the success rate of adversarial attacks. The feedback information of the fitness function is used to adjust the parameters and perturbation generation strategy of EDEAS to ensure that the generated perturbation has both efficient deception ability and imperceptibility.

[0096] Through the design and optimization of the fitness function, it is ensured that the generated perturbation can effectively deceive the detection model, while maintaining the smallness and imperceptibility of the perturbation, improving the overall effect and concealment of adversarial attacks.

[0097] Through the collaborative work of the above four modules, the AIEA method of the present invention can efficiently generate adversarial perturbations and optimize the attack effect through the adaptive differential evolution algorithm. This method has achieved a high attack success rate on mainstream insulator defect detection models, and at the same time ensures that the perturbation is almost imperceptible to the human eye through repair and fitness optimization, thereby enhancing the security protection ability of the smart grid system.

[0098] According to the above design, as Figure 2 shown, the overall implementation process of the AIEA method of the present invention is as follows:

[0099] Step 1: Input the original image:

[0100] Input the insulator image to be subjected to adversarial attack into the AIEA system as the basic data for the attack.

[0101] Step 2: The perturbation generation module generates an initial perturbation:

[0102] Through the perturbation generation module, according to the perturbation vector δ, generate an initial semi-transparent circular perturbation and superimpose it on the original image to obtain the initial adversarial image I adv .

[0103] Step 3: EDEAS optimizes the perturbation:

[0104] Use EDEAS to optimize the perturbation vector δ, generate more effective perturbations through multiple iterations, gradually improve the deception effect on the detection model, and ensure the optimal distribution of the perturbation in the high-dimensional search space.

[0105] Step 4: The repair function adjusts the adversarial image:

[0106] Perform repair processing on the optimized adversarial image I adv to ensure that the perturbation is highly similar to the original image visually and avoid obvious visual differences affecting the image quality.

[0107] Step 5: Fitness function evaluation:

[0108] Calculate the total loss L of the perturbation through the fitness function total , evaluate the effectiveness of the perturbation, and further guide the optimization of the perturbation according to the evaluation results to ensure the continuous improvement and optimization of the attack strategy.

[0109] Step 6: Output the final adversarial image:

[0110] Output the final adversarial image I after optimization and repair processing adv , which is used to attack the detection model in testing and actual applications to ensure the maximization of the attack effect and the optimization of the image quality.

[0111] Through the above steps, the AIEA method realizes the efficient generation and optimization of the perturbation, ensures a high success rate of attacking the detection model, and at the same time maintains the visual consistency of the image and the imperceptibility of the perturbation.

[0112] 6. Performance Evaluation and Large-Scale Testing

[0113] To verify the effectiveness and practicality of the AIEA method of the present invention, systematic performance evaluation and large-scale testing were carried out. The specific implementation steps are as follows:

[0114] 1): Preparation of the test dataset: Collect a large amount of insulator image data covering various states such as normal, damaged, and flashover, etc., for evaluating the attack effect of the AIEA method in different scenarios. And clean, crop, and normalize the collected image data to ensure the data quality and consistency, providing a reliable basis for subsequent attacks and evaluations.

[0115] 2): Evaluation of the attack success rate: First, use the AIEA method to generate adversarial images and attack mainstream insulator defect detection models (such as MSFFT, DETR, YOLO series, Faster R-CNN), and record the attack success rate. Then, compare and analyze the attack success rate of the AIEA method with traditional adversarial attack methods to verify the superiority and wide applicability of the AIEA on different models.

[0116] 3): Evaluation of the imperceptibility of the perturbation: Through expert visual evaluation, subjectively judge the imperceptibility of the repaired adversarial image to ensure that the perturbation is difficult to detect by the human eye. And use objective indicators such as PSNR (Peak Signal-to-Noise Ratio) and SSIM (Structural Similarity Index) to quantitatively evaluate the visual quality of the adversarial image to ensure that the perturbation can effectively deceive the detection model without affecting the image quality.

[0117] 4): Robustness and generalization ability test: Test the AIEA method on insulator images under different environmental conditions and different types to evaluate its robustness and generalization ability, and ensure the stability and effectiveness of the method in various practical application scenarios. Also verify the generalization ability of the AIEA method among different detection models to ensure that the perturbations have wide applicability and efficient attack performance.

[0118] 5): Computational efficiency evaluation: Measure the computational time and resource consumption of the AIEA method in the process of generating and optimizing perturbations, and evaluate its feasibility and efficiency in practical applications. Also improve the computational efficiency of the AIEA method by optimizing parallel computing and algorithm parameters to ensure its practicality and efficiency in large-scale applications.

[0119] 6): Enhancement of model robustness: Retrain the insulator defect detection model by mixing adversarial perturbation images with clear images to significantly reduce its sensitivity to adversarial attacks. Also evaluate the robustness of the retrained model against AIEA attacks to ensure the effective improvement of the security and reliability of the model in complex environments.

[0120] The test results show that the AIEA method of the present invention achieves a high attack success rate on mainstream insulator defect detection models (such as reaching 81.25% on the MSFFT model). At the same time, through the repair function and fitness optimization, the imperceptibility of the perturbations and the visual similarity of the images are ensured. In addition, the introduction of EDEAS significantly improves the efficiency and optimization effect of perturbation generation, making the AIEA method perform excellently in large-scale applications. Through the mixed training of adversarial samples and clear images, the robustness of the detection model is significantly enhanced, reducing its sensitivity to AIEA attacks and further improving the overall security and reliability of the smart grid system. Figure 6 Shows the impact of the adversarial attack on the MSFFT model and the detection results before and after the attack. The first row shows the original image, the second row shows the image with adversarial perturbations, the third row shows the detection result of the original image, and the fourth row shows the detection result after the attack. The third row shows the detection result of the original image, and the fourth row shows the detection result after the attack. The detection result after the attack. It looks better when magnified.

[0121] In summary, through the organic combination of the perturbation generation module, the adaptive differential evolution algorithm, the repair function and the fitness function, the present invention realizes the efficient application of the AIEA method in the insulator defect detection model, not only improving the attack success rate, but also ensuring the concealment of the perturbations and the visual consistency of the images, with significant practical application value and broad application prospects. At the same time, through the model robustness enhancement strategy, the security protection ability of the smart grid system is further improved to ensure its reliable operation in complex environments.

[0122] When the above functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., all kinds of media that can store program codes.

[0123] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes. The solutions in the embodiments of the present invention can be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript.

[0124] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0125] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in this computer-readable memory generate a manufactured article including an instruction device, and this instruction device realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0126] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable apparatus provide steps for realizing the functions specified in one process or multiple processes and / or blocks Figure 1 one process or multiple processes and / or blocks Figure 1 or steps for realizing the functions specified in multiple blocks.

[0127] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to cover the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.

[0128] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. An adaptive evolutionary adversarial attack method for an insulator defect detection model, characterized in that It includes the following steps: Obtain the original insulator image; Based on the original insulator image, generate an initial perturbation vector by using a method for generating perturbations of a semi-transparent circle and RGB values, and superimpose it on the original insulator image to obtain an initial adversarial image; Optimize the generation process of the initial perturbation vector based on an adaptive differential evolution algorithm to obtain an optimized perturbation vector and an optimized adversarial image; Perform restoration processing on the optimized adversarial image to obtain a restored adversarial image; Input the restored adversarial image into an insulator defect detection model, output the attack success rate, and complete the adversarial attack process.

2. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 1, characterized in that The step of generating the initial perturbation vector includes: Define the perturbation vector δ and initialize it using random initialization or an initial value based on insulator characteristics, where each perturbation vector δ i has parameters including the center coordinates (δ i1 , δ i2 ), the circle radius δ i3 , the RGB color values (δ i4 , δ i5 , δ i6 ), and the transparency δ i7 ; According to each of the perturbation vectors δ i , generate a semi-transparent circular perturbation; Stitch multiple semi-transparent circular perturbations according to the perturbation vector δ to form an overall initial perturbation vector δ.

3. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 2, characterized in that, The process of generating the semi-transparent circular perturbation includes: Based on the parameters of each perturbation vector δ i determine the center position (x, y) of the circle and set the radius size of the circle; Set the RGB color value according to the insulator characteristics, and then set the transparency value to obtain a semi-transparent circular perturbation.

4. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 1, characterized in that, The step of obtaining the optimized perturbation vector includes: Population initialization: Uniformly generate an initial population in a high-dimensional search space, where the population is the generated initial perturbation vector; Parallel evolution: For each population member in the initial population, calculate the fitness of each population member in parallel and perform evolution operations in parallel, and select population members with better fitness to enter the next generation population, where the evolution operations include mutation, crossover recombination, and selection operations; Adaptive mutation factor adjustment: Dynamically adjust the mutation factor in the mutation operation according to the diversity and fitness variance of the population; Enhanced selection mechanism: Based on the current population, comprehensively evaluate the fitness of each candidate solution by combining global comparison, local comparison, and comparison of current population members, and select the optimal solution, where the candidate solution is a trial solution generated from the original individuals based on the evolution operation in the current iteration.

5. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 4, characterized in that Use the Latin hypercube sampling method to perform the population initialization operation.

6. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 1, characterized in that Perform pixel-by-pixel adjustment on the optimized adversarial image through a repair function to perform restoration processing to obtain the restored adversarial image.

7. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 6, characterized in that, The steps of performing restoration processing through the repair function include: Pixel value range limitation: For each pixel of the optimized adversarial image, ensure that each pixel value satisfies: where I adv (i) is the pixel value of the optimized adversarial image at position i, ∈∈[0,1] is the defined perturbation limit, and I(i) is the pixel value of the original image at position iii; Pixel value adjustment: Traverse all pixels of the optimized adversarial image, and perform pixel-by-pixel adjustment according to the set pixel value range to obtain a restored adversarial image.

8. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 1, characterized in that, It also includes the following steps: Before generating the optimized adversarial image, based on the optimized perturbation vector, use the Hungarian matching algorithm to match the predicted bounding box and the ground truth bounding box to construct an adaptive fitness function to evaluate the optimized perturbation, so as to further guide the perturbation optimization. The specific construction process includes: Use the insulator defect detection model to perform classification prediction on the restored adversarial image to obtain a classification prediction result; Calculate the classification loss according to the classification prediction result; Calculate the difference from the ground truth bounding box according to the predicted bounding box in the classification prediction result to obtain a bounding box loss; Obtain the generalized IoU loss according to the generalized IoU between the predicted bounding box and the ground truth bounding box in the classification prediction result. According to the classification loss, bounding box loss, and generalized IoU loss, and combined with the corresponding weight parameters, an adaptive fitness function is obtained, where the adaptive fitness function serves as the total loss function for the perturbation generation process, and the perturbation optimization is guided by minimizing the total loss function. The expression of the total loss function is as follows: L total = λ cls ·L cls + λ bbox ·L bbox + λ giou ·L giou where, L total is the total loss, λ cls , λ bbox , λ giou are weight parameters, L cls is the classification loss, L bbox is the bounding box loss, L giou is the generalized IoU loss.

9. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 1, characterized in that, The insulator defect detection model includes a model constructed using any one or more of MSFFT, DETR, YOLO series, and Faster R-CNN networks.

10. An adaptive evolutionary adversarial attack method for an insulator defect detection model according to claim 1, characterized in that, It further includes the following steps: Using the peak signal-to-noise ratio and structural similarity index to quantitatively evaluate the visual quality of the repaired adversarial image.

Citation Information

Patent Citations

  • Black box adversarial sample attack method for electric energy quality signal neural network classification model

    CN112149609A

  • Smart grid adversarial image generation method, device, storage medium and terminal equipment

    CN118038343B