Biological information verification method based on backward Euler residual architecture
By combining the backward Euler residual architecture designed by implicit backward Euler method and explicit neural network, the robustness of biological information verification in complex environments and adversarial attacks is solved, and good performance and efficient training are achieved under adversarial samples, improving the security and real-time nature of the biological information verification system.
Patent Information
- Application Number
- CN202510519913.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-08-05
AI Technical Summary
Existing bioinformatics verification technologies are not robust enough in complex environments and adversarial attacks, making it difficult to maintain stable and reliable predictive outputs, especially in facial and fingerprint recognition, which are susceptible to environmental perturbations and malicious attacks.
Using a biological information verification method based on the backward Euler residual architecture, combined with the implicit backward Euler method and explicit neural network design, the WideResNet model based on the backward Euler residual module is designed, and the adversarial samples are generated by PGD attack for training, optimizing the robustness of the model in the adversarial environment.
It significantly improves the model robustness of biometric data in dynamic noise environments and combats attacks, shortens training time, and improves the security and real-time nature of the biometric information verification system.
Smart Images

Figure CN120431381A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of bioinformatics verification, and in particular relates to a bioinformatics verification method based on a backward Euler residual architecture. Background Art
[0002] In the field of biometric verification, facial recognition systems, for example, must accurately identify individuals despite interference from complex lighting, occlusion, changes in expression, and posture. Fingerprint recognition, on the other hand, must address image deformation and quality degradation caused by factors such as acquisition pressure, rotation, and contamination. Traditional methods typically rely on rule-based algorithms based on template matching (such as minutiae matching), statistical models (such as Bayesian networks for identity discrimination), and hand-crafted feature extraction methods (such as Gabor filters for fingerprint texture processing). While these methods have demonstrated some effectiveness in specific environments, they generally suffer from weak feature representation, sensitivity to noise, and poor generalization in open environments, making them difficult to handle dynamic interference or malicious adversarial attacks that may arise during biometric verification.
[0003] With the development of deep learning technology, deep neural networks (DNNs) have achieved high-level representations of biometric features such as faces and fingerprints through end-to-end learning, effectively improving the accuracy of identity verification tasks. For example, convolutional neural networks (CNNs) can automatically extract multi-scale texture features from facial images, residual network (ResNet) structures achieve deeper feature fusion in fingerprint images, and attention mechanisms further enhance the recognition of key areas (such as the corners of the eyes and the center of the fingerprint). However, since biometric verification scenarios are susceptible to environmental perturbations and adversarial attacks in real-world applications, DNN systems still face significant challenges in terms of robustness.
[0004] In practical applications, the robustness of DNN models is particularly problematic. Adversarial perturbations (APs) involve the addition of carefully crafted, subtle noise to input data, causing the DNN to produce imperceptible mispredictions. This attack exploits the high-dimensional complexity of DNNs and their high sensitivity to input distribution, causing the model to make completely incorrect classification decisions even when presented with seemingly normal inputs. These deliberately modified inputs are called adversarial examples (AEs). Because neural networks are extremely sensitive to small perturbations in input data, they are prone to misclassification under adversarial examples. In biometric verification tasks, APs manifest as malicious manipulation of face or fingerprint images. For example, by adding nearly invisible pixel perturbations to a face image, the verification system can misidentify the target as an attack target or incorrectly reject legitimate users. In fingerprint images, subtle ridge artifacts or image reconstructions can disrupt the consistency of minutiae used by traditional matching algorithms. These attacks often exploit the spatial structure of face and fingerprint images. For example, even small changes to key areas such as the corners of the eyes, the wings of the nose, or the center of the fingerprint can cause verification to fail. In addition, dynamic noise common in the actual acquisition process (such as camera module lighting fluctuations and humidity interference of fingerprint sensors) can also cause input distribution shifts, further affecting the generalization ability and stability of the model. For example, in cross-device face recognition tasks, differences in resolution, color response, or viewing angles of different cameras may cause the same face image to show significant shifts in the feature space; in mobile fingerprint recognition, differences in fingerprint sensor material or pressure can also cause local distortion of the ridge structure. The combination of these factors significantly reduces the performance of the model in real environments. Therefore, how to improve the robustness of neural networks so that they can maintain stable and reliable prediction outputs in complex environments and adversarial scenarios is one of the key issues in current deep learning research.
[0005] To address the robustness issues of neural networks, researchers have proposed various strategies to improve them, including regularization, data augmentation, adversarial training, and robust optimization techniques. Traditional regularization methods (such as L2 regularization and dropout) improve generalization by constraining parameter size or introducing randomness. However, in biometric verification scenarios, these methods have limited effectiveness against adversarial perturbations. For example, in face recognition tasks, while L2 regularization can mitigate overfitting, it struggles to defend against adversarial examples generated by fine-scale pixel perturbations. In fingerprint recognition, the dropout mechanism can disrupt ridge continuity or local minutiae structure, thereby reducing matching accuracy. Data augmentation techniques, which apply transformations such as rotation, scaling, blurring, and noise injection to training samples, aim to improve the model's adaptability to diverse inputs. However, they still have limitations in practical biometric verification. Large-angle rotations or occlusion simulations of facial images can result in missing information in key areas (such as the eyes or corners of the mouth). Affine transformations of fingerprint images can easily disrupt the ridge topology, causing the augmented samples to deviate from the true distribution and interfering with model learning. Adversarial training methods improve robustness by adding adversarial samples during training, and have shown certain effects in face and fingerprint verification tasks. However, since these images are usually high-resolution and complex in structure, generating high-quality adversarial samples has a high computational overhead, and it is difficult to cover the various attack strategies that may be encountered in real environments, such as lighting perturbations, material camouflage, and artificial fingerprints. Robust optimization methods (such as gradient smoothing and adversarial regularization) enhance the model's stability to perturbations by constraining changes in the loss function, but in practical applications they may still be limited by the instability of the acquisition equipment. For example, differences in imaging quality between different cameras, or image offsets caused by uneven surface humidity and pressure on fingerprint sensors, can cause fluctuations in model output results.
[0006] In recent years, the combination of numerical analysis methods and neural networks has provided new ideas for bioinformatics verification. Existing research shows that the forward propagation process of deep neural networks can be linked to numerical integration methods for solving ordinary differential equations (ODEs), providing a new perspective for model stability analysis and improvement. Among existing methods, explicit numerical integration methods are widely used in neural network architecture design due to their high computational efficiency. For example, the residual connection of the residual network (ResNet) can be regarded as a discrete iterative form of the Euler method, where the output of each layer can be expressed as:
[0007] x i+1 =x i +f(x i ,θ i )
[0008] This structure can be viewed as a discrete approximation of first-order differential equations, enabling the network to simulate complex nonlinear mappings through deeper stacking. Furthermore, variants such as FractalNet, PolyNet, and RevNet build upon this foundation by introducing more complex recursive or inversely reversible structures to improve the model's expressiveness and computational efficiency. While explicit methods have performed well in deep networks, stability issues remain prominent. When input perturbations are large or the data distribution undergoes drastic changes, explicit methods can lead to numerical instability, which in turn affects the model's generalization ability. For example, in face recognition, local adversarial perturbations caused by changes in expression, occlusion, or illumination can be amplified layer by layer through explicit iteration, disrupting global feature matching. In fingerprint verification tasks, texture noise introduced by low-quality images or sensor acquisition errors can make the feature update process highly sensitive to step size, leading to feature drift and causing recognition results to deviate from the true identity. Furthermore, in cross-device face verification, input distribution shifts caused by differences in camera hardware can cause inconsistent responses between training and testing of explicit networks, impacting model stability.
[0009] In order to solve these problems, implicit numerical integration methods have gradually attracted attention in recent years. A key advantage of implicit methods over explicit methods is that they can effectively alleviate the problem of numerical error accumulation caused by rapid changes in solutions in rigid systems. In rigid systems, the rate of change of certain state variables may fluctuate violently in a short period of time. Since explicit methods only rely on the information of the current time step, it is difficult to accurately capture these changes when the step size is large, which often leads to the expansion of the deviation of the numerical solution or even instability. Take the backward Euler method as an example. It depends not only on the current state x at each time step, but also on the current state x at each time step. i , also using the target state x i+1 To construct the update equation:
[0010] x i+1 =x i +hf(x i+1 ,t i+1 )
[0011] like Figure 1 As shown in Figure 2, a key advantage of this design is that it reduces error accumulation caused by rigid systems and allows for stable numerical behavior even at larger step sizes. In adversarial attack scenarios, if input perturbations cause drastic gradient changes, explicit methods may struggle to update stably. However, the Backward Euler method can more robustly adjust network parameters, allowing them to converge to the correct classification boundary and reduce the risk of misclassification caused by gradient oscillation.
[0012] In recent years, researchers have attempted to incorporate implicit methods from numerical analysis into neural network architectures to enhance model robustness and numerical stability. For example, implicit Euler skip connections (IE-Skips) draw on the backward Euler method to improve the skip connections of ResNet and its variants. However, IE-Skips is computationally expensive, and optimizing computational efficiency while maintaining robustness remains an important research direction. Summary of the Invention
[0013] The present invention aims to overcome the shortcomings of existing technologies by providing a biometric verification method based on a backward Euler residual architecture. By combining the stability principle of the implicit backward Euler method with an explicit neural network design, the robustness of the biometric data model in dynamic noisy environments and under adversarial attacks is significantly improved.
[0014] The object of the present invention is achieved through the following technical solution: a bioinformatics verification method based on a backward Euler residual architecture, comprising the following steps:
[0015] Step 1. Prepare the dataset: Select public face recognition and fingerprint recognition related datasets as clean sample sets, and divide the clean sample sets into training clean sample sets and test clean sample sets;
[0016] Step 2: Data preprocessing: Normalize the images in the training clean sample set, randomly crop the images and add edge padding, and randomly flip the images horizontally;
[0017] Perform tensor transformation and normalization on the images in the test clean sample set;
[0018] Step 3: Design a WideResNet model based on the backward Euler residual network architecture and initialize the model parameters; the WideResNet model based on the backward Euler residual network architecture also includes an input layer, an intermediate layer, and an output layer;
[0019] The input layer uses a convolutional layer for initial feature extraction, and then connects a BN layer and a ReLU activation function;
[0020] The middle layer constructs a deep network by stacking multiple backward Euler residual modules. Each backward Euler residual module consists of four backward Euler network layers, and each backward Euler network layer includes two convolutional layers. Except for the first backward Euler residual module, the remaining backward Euler residual modules use convolution with a stride of 2 in the first backward Euler network layer to achieve feature map downsampling, and the convolution stride of the remaining backward Euler network layers is 1. In the first backward Euler residual module, the stride of the convolution layer in all backward Euler network layers is 1.
[0021] At the same time, each backward Euler residual module performs channel expansion in the first backward Euler network layer, and the widen_factor parameter controls the expansion ratio of the number of channels; in each backward Euler residual module, a residual connection is established with the output of each backward Euler network layer through the input features;
[0022] In each backward Euler residual module, the input features of the backward Euler residual module are respectively connected with the output of each backward Euler network layer, and all residual connections are accumulated as the output of the backward Euler residual module;
[0023] The output layer uses global average pooling to compress the features to 1x1 size, and then the fully connected layer completes the classification task;
[0024] Step 4. Generate adversarial samples: Process clean samples using the PGD attack method to generate adversarial samples; process samples in the training clean sample set and the test clean sample set using the PGD attack method to generate training adversarial samples and test adversarial samples; then combine the training clean samples and training adversarial samples into the training sample set, and combine the test clean samples and test adversarial samples into the test sample set;
[0025] Step 5: Model training and evaluation: Use the training sample set to train the WideResNet model. After each training cycle, perform model evaluation: Use the test sample set to calculate the accuracy of the model on clean samples and adversarial samples respectively. If better accuracy is achieved on clean samples, save the parameters of the current model and use this model as an alternative model.
[0026] Step 6: Perform adversarial detection and select the optimal model; including the following steps:
[0027] Step 6-1, conduct adversarial attack: use multiple attack methods to process the test clean samples, generate multiple adversarial samples, and combine the test clean samples and the generated adversarial samples into a test sample set;
[0028] Step 6-2: Input the test sample sets generated in step 6-1 into the candidate models for classification;
[0029] Step 6-3. Evaluation Metrics Analysis: Calculate the model's adversarial attack success rate (ASR), the model's perturbation robustness (PR), and the average confidence difference (ACD). When selecting the optimal model, prioritize the model with balanced and high accuracy on both clean and adversarial samples. Next, select the model with the lowest ASR and highest PR. Furthermore, select the model with the smallest ACD. Finally, based on the above conditions, select the model with the highest computational efficiency and use it for bioinformatics verification.
[0030] The present invention provides a biometric verification method based on a backward Euler residual architecture. By combining the stability principle of the implicit backward Euler method with an explicit neural network design, the method significantly improves the robustness of the model in dynamic noisy environments and under adversarial attacks. This method leverages the stability advantage of the backward Euler method to maintain good performance under adversarial examples. Furthermore, through the explicit network architecture design, the method avoids the high computational overhead of traditional implicit methods, significantly shortening training time and improving the security and real-time performance of biometric verification systems in practical applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 This is a comparison diagram of the backward Euler method and the Euler method.
[0032] Figure 2 It is the overall flow chart of the present invention.
[0033] Figure 3 It is a structural diagram of the WideResNet model based on the backward Euler residual network architecture designed by the present invention.
[0034] Figure 4 It is a structural diagram of the backward Euler residual module of the present invention. DETAILED DESCRIPTION
[0035] This paper provides a biometric verification method based on a backward Euler residual architecture. By combining the stability principle of the implicit backward Euler method with an explicit neural network design, the method significantly improves the robustness of the model in dynamic noisy environments and under adversarial attacks. This method leverages the stability advantage of the backward Euler method to maintain good performance under adversarial examples. Through the explicit network architecture design, the method avoids the high computational overhead of traditional implicit methods, significantly shortens training time, and improves the security and real-time performance of biometric verification systems in practical applications.
[0036] The technical solution of the present invention is further described below with reference to the accompanying drawings.
[0037] like Figure 2 As shown, a bioinformatics verification method based on a backward Euler residual architecture of the present invention comprises the following steps:
[0038] Step 1. Prepare the data set: First, collect and organize diverse biometric information data sets to ensure the balance of data quality and distribution, and support the needs of subsequent training and evaluation. The present invention uses public face recognition and fingerprint recognition related data sets as clean sample sets, such as face images in the LFW (Labeled Faces in the Wild) data set and fingerprint images in the FVC (Fingerprint Verification Competition) series. These data sets cover a variety of identity features and collection environments, have good representativeness and complexity, can effectively simulate real biometric application scenarios, and support the robustness verification requirements of the present invention in identity verification tasks. The clean sample set is divided into a training clean sample set and a test clean sample set.
[0039] Step 2: Data preprocessing: A series of dynamic enhancement strategies are implemented in the training phase using multimodal means, while a more streamlined processing flow is adopted in the testing phase to enhance the generalization performance of the model in adversarial environments.
[0040] The images in the clean training set are normalized to account for the statistical characteristics of the three RGB channels. During the training phase, a dynamic augmentation strategy is used to randomly crop images and add edge padding to simulate perturbations in the target position. Random horizontal flipping operations are also introduced to enhance the model's robustness to rotational transformations.
[0041] For the images in the test clean sample set, tensor conversion (converting the image pixels into a tensor) and normalization are performed to avoid the influence of random operations on the evaluation results;
[0042] Through these data preprocessing methods, the model can improve data diversity while maintaining the consistency of the feature space, thereby enhancing the generalization ability under adversarial attacks.
[0043] Step 3: Design a WideResNet model based on the backward Euler residual network architecture and initialize the model parameters;
[0044] WideResNet uses deep residual learning to improve model performance and enhances feature representation and training stability by increasing network width instead of simply deepening the network. Its overall architecture consists of three main components: the input layer uses 3×3 convolutions for initial feature extraction, followed by batch normalization and ReLU activation functions; the intermediate layers are stacked with multiple stages, each consisting of multiple residual blocks (ResidualBlocks). Except for the first stage, all other stages use convolutions with a stride of 2 in the first ResidualBlock to downsample the feature maps, while the convolutions in the remaining ResidualBlocks have a stride of 1. Furthermore, each stage performs channel expansion in the first ResidualBlock, with the widen_factor parameter controlling the channel expansion ratio. Within each ResidualBlock, features are extracted step by step through two 3x3 convolutions (conv1 and conv2), each preceded by a normalization combination of batch normalization and ReLU activation functions. Furthermore, residual connections are established between the input features and the output after the two convolutions. The output layer uses global average pooling to compress the features to 1x1 size, and after flattening, the fully connected layer completes the classification task.
[0045] The WideResNet model based on the backward Euler residual network architecture proposed in this paper has the most critical change compared to the basic structure of WideResNet, which is to improve the middle layer into a backward Euler residual module.
[0046] The WideResNet model also includes input layer, intermediate layer and output layer, such as Figure 3 shown.
[0047] The input layer uses a convolutional layer for initial feature extraction, followed by a batch normalization (BN) layer and a ReLU activation function. The appropriate convolution kernel size is dynamically selected based on the input image resolution for initial feature extraction. For higher-resolution input images, a 7×7 convolution kernel is used with a stride of 2 and padding of 3 to reduce computational overhead while maintaining an effective receptive field. For lower-resolution input images, a 3×3 convolution kernel is used with a stride of 1 and padding of 1 to maintain the fine-grained and spatial resolution of feature extraction. BN is then added to accelerate convergence and stabilize training, and the ReLU activation function introduces nonlinearity to improve feature representation.
[0048] The middle layer constructs a deep network by stacking multiple backward Euler residual modules (BE_Block), each backward Euler residual module consists of four backward Euler network layers (BE_Layer), such as Figure 4As shown; each backward Euler network layer includes two convolutional layers. Except for the first backward Euler residual module, the other backward Euler residual modules use convolution with a stride of 2 in the first backward Euler network layer to achieve feature map downsampling, and the convolution stride of the remaining backward Euler network layers is 1; in the first backward Euler residual module, the stride of the convolution layer in all backward Euler network layers is 1. At the same time, each backward Euler residual module performs channel expansion in the first backward Euler network layer, and the widen_factor parameter is used to control the expansion ratio of the number of channels; the difference from the traditional WideResNet is that each backward Euler network layer does not contain residual connections, but in the backward Euler residual module, residual connections are established with the output of each backward Euler network layer through the input features;
[0049] In each backward Euler residual module, the input features of the backward Euler residual module are respectively connected with the output of each backward Euler network layer. All residual connections are accumulated as the output of the backward Euler residual module. The core formula of the backward Euler residual module is:
[0050]
[0051] x i+1 、x i are the output and input data of the backward Euler residual module respectively; f k represents the kth backward Euler network layer;
[0052] The specific design principle of the above backward Euler residual module is:
[0053] (1) Constructing the backward Euler network layer: In the neural network, the hierarchical structure is analogous to the time discretization process, and the step size h is set to 1. The explicit Euler method recursive formula is:
[0054] x i+1 =x i +hf(x i ,t i ) (1)
[0055] The mathematical expression corresponding to the traditional residual architecture is:
[0056] x i+1 =x i +f(x i ,θ i ) (2)
[0057] On this basis, f(x i ,θ i ) and f(x i ,t i) are similar, both used to calculate the increments at each iteration or time step, thereby driving system or network updates. Based on this, the Euler method recursive formula is mapped to the neural network hierarchical structure, paving the way for the subsequent conversion of implicit formulas into explicit network architectures.
[0058] (2) Design of the neural network architecture formula of the backward Euler method: Since the backward Euler method performs better in numerical stability, especially when dealing with rigid systems, it can cope with strong nonlinearity and complex dynamic changes, which helps to improve the robustness of the neural network. The backward Euler method recursive formula is:
[0059] x i+1 =x i +hf(x i+1 ,t i+1 ) (3)
[0060] Mapping to the neural network architecture yields:
[0061] x i+1 =x i +f(x i+1 ,θ i+1 ) (4)
[0062] Because each layer of the neural network is updated only based on the current layer input, removing the i+1 The explicit dependency of simplifies the formula to:
[0063] x i+1 =x i +f(x i+1 ) (5)
[0064] Thus, an implicit residual network layer structure derived based on the backward Euler method is constructed.
[0065] (3) Construct the backward Euler residual module; the core formula design method of the backward Euler residual module is: convert formula (5) into matrix form:
[0066] (If)x i+1 =x i (6)
[0067] Among them, I is the unit matrix, f is the function matrix, which represents the dynamic change of the system, x i is the feature tensor of the current layer. By multiplying its inverse matrix (If) on both sides of the equation -1 ,get:
[0068] x i+1 =(If) -1 x i (7)
[0069] By using the property that the spectral radius ρ(f) is the maximum modulus of the eigenvalues of the matrix f, when ρ(f)<1, we can ensure that (If) is reversible. And at this time, the Neumann series Absolutely convergent, and its sum is equal to (If) -1 ,Right now:
[0070] (If) -1 =I+f+f 2 +f 3 +… (8)
[0071] Substituting it into the backward Euler method recursive formula, we get the core formula of the network architecture:
[0072]
[0073] f k Refers to the kth backward Euler network layer.
[0074] like Figure 3 As shown in Figure 1, the backward Euler residual module implements the backward Euler method recursive formula through the design of (9). Each backward Euler residual module is composed of multiple backward Euler network layers stacked together. When k = 1, f corresponds to the basic transformation of the input features by a single backward Euler network layer; when k ≥ 2, f k Instead of independently stacking k new backward Euler network layers, a layer sharing mechanism is used to reuse the parameters and computation paths of the previous k-1 backward Euler network layers and superimpose the latest backward Euler network layer to complete the composite transformation. This recursive parameter reuse strategy makes the high-order term f k The construction of (k ≥ 2) maintains the integrity of the mathematical expression while significantly reducing model complexity through parameter sharing. To avoid excessive computational overhead, this example truncates the series to use only the first five terms, ensuring high computational efficiency while maintaining sufficient model accuracy in practical applications.
[0075] In the backward Euler network layer, features are extracted step by step through two convolution operations (conv1 and conv2). A standardized combination of batch normalization (BN) and rectified linear unit (ReLU) activation functions is used before each convolution. The convolution kernel size is set to 3x3 by default to achieve fine feature capture. During model training, a dynamic dropout mechanism is introduced in the convolution layer to reduce the risk of overfitting by probabilistically discarding neurons, and gradient checkpoint technology can be optionally used to optimize training memory usage. The backward Euler residual module is composed of multiple cascaded backward Euler network layers. After all layers complete the feature transformation, the original input features are fused with the deep features through the residual connection mechanism. Specifically, the residual connection is the element-by-element addition of the input of the backward Euler residual module and the output features of each layer of the backward Euler network layer to achieve cross-layer feature integration.
[0076] The shortcut path is set during the initialization of the backward Euler residual module and is located at the end of the entire backward Euler residual module. Its function is to adjust the input after the backward Euler network layer is calculated. When the number of channels of the input of the backward Euler residual module and the output of the backward Euler network layer does not match, a shortcut consisting of 1x1 convolution is used to align the channels to ensure smooth addition, ultimately achieving effective transmission and fusion of deep features. This design preserves shallow semantic information while enhancing the stability of gradient backpropagation.
[0077] The output layer uses global average pooling to compress the features to 1x1 size, and after flattening, the fully connected layer completes the classification task.
[0078] In this invention, spectral normalization is used in all convolutional layers.
[0079] torch.nn.utils.spectral_norm wrapper, which imposes constraints on the weight parameters of the convolutional layer so that it undergoes a normalization process of the maximum singular value at each forward step, ensuring that the spectral radius ρ(f) < 1. Spectral normalization is expressed as:
[0080] ScaledSpectralNormConv2d
[0081] self.conv=spectral_norm(nn.Conv2d(in_channels,out_channels,kernel_size,stride,padding))
[0082] The entire WideResNet model's forward propagation process uses progressive feature processing via multiple levels of Backward Euler Residual modules, ultimately forming a classification network architecture that combines feature width expansion with deep mining capabilities. To improve the model's stability and robustness in adversarial attack environments, the present invention converts the implicit Backward Euler method into an explicit form, making it more suitable for implementation in neural networks. Based on this, a specialized Backward Euler Residual module is designed and constructed.
[0083] Parameter initialization utilizes an adversarial optimization strategy: convolutional layer weights are automatically adjusted to a normal distribution based on the number of input channels and kernel size to prevent gradient anomalies. Batch normalization layers uniformly set weights to 1 and biases to 0 to stabilize initial features. The number of network channels is expanded in three stages (16, 160, 320, and 640) using the widen_factor = 10 parameter. In each stage, the first layer uses stride 2 convolutions to compress the feature map size. Training employs a dual defense mechanism with a 15% probability of random feature dropout and a weight decay coefficient of 0.0002. These design strategies establish a complete robust learning framework, from data input and feature extraction to adversarial defense.
[0084] Step 4. Generate adversarial samples: Process the clean samples through the PGD attack method to generate adversarial samples; divide the clean samples into a training clean sample set and a test clean sample set, and process the samples in the training clean sample set and the test clean sample set respectively through the PGD attack method to generate training adversarial samples and test adversarial samples; then combine the training clean samples and training adversarial samples into a training sample set, and combine the test clean samples and test adversarial samples into a test sample set.
[0085] When applying the PGD attack to the clean training set, adversarial examples are generated 80% of the time starting with random perturbations (e.g., adding a small amount of noise) based on the clean samples, and 20% of the time starting directly from the clean samples. The perturbations are gradually adjusted along the gradient of the cross-entropy loss over 10 iterations, with each update step size of 2 / 225 (approximately 0.0089 pixel intensity), while the total perturbation amplitude is strictly limited to a visually imperceptible 8 / 255 (approximately 0.031 pixel intensity). When applying the PGD attack to the clean test set, the perturbations are always applied starting from the clean samples, with a step size of 2 / 255. This ultimately generates adversarial examples that can deceive model predictions while being minimally different from the original images. (In the testing phase, the perturbations are 2 / 255 and do not have a random starting point, starting from the original image, resulting in more stable and detailed perturbations.) This dual-mode design—diversified perturbations during training to enhance generalization and deterministic attacks during testing to verify performance at the extremes—systematically improves the model's robustness in adversarial environments.
[0086] Assume x i+1is a clean sample, which becomes a perturbed sample after adding ∈ perturbation The goal of a robust network architecture is to ensure that the difference between clean samples and perturbed samples does not gradually increase during the forward propagation process, thereby avoiding misclassification. Let the difference caused by the perturbation be δ, then:
[0087]
[0088] because Therefore, we can get During the forward propagation process, the number of network layers that the feature map goes through gradually increases, which means that the k value gradually increases. The perturbation is convergent, and the perturbation is gradually suppressed during the propagation process instead of being gradually amplified. In this way, the network architecture effectively suppresses the impact of the perturbation and improves the robustness of the network.
[0089] Step 5: Model Training and Evaluation: The designed WideResNet model is trained using the training sample set. An adversarial training strategy is employed, using both adversarial and clean samples during training. The performance of both clean and adversarial samples is evaluated during the testing phase, enhancing the adaptability of the neural network in complex environments. An adaptive optimization strategy and dynamic learning rate adjustment ensure an efficient training process, and the best model is evaluated and saved at each stage to cope with different attack environments.
[0090] In the adversarial training process of the present invention, the network architecture is first initialized and the optimization algorithm is configured. In each training cycle, the PGD attack is first applied to the input sample to generate adversarial samples. This process enhances the robustness of the network to adversarial attacks, while ensuring that some samples remain clean, so as to improve the model's generalization ability to naturally distributed data. Next, by calculating the loss of the model on the adversarial sample, the model parameters are optimized using the cross-entropy loss function. The Stochastic Gradient Descent (SGD) algorithm is used in the optimization process, combined with momentum to accelerate convergence, and weight decay is introduced to avoid overfitting. After each training cycle, the model is evaluated: the accuracy of the model on clean samples and adversarial samples is calculated using the test sample set; if better accuracy is achieved on the clean sample, the parameters of the current model are saved; the model is used as an alternative model; and in each training iteration, the learning rate is dynamically adjusted to optimize the convergence speed. The learning rate lr0 = 0.1 adopts a periodic (75 / 90 / 100) decay strategy. Finally, the best model is saved regularly during the training process to ensure that it maintains excellent robustness under different attack environments.
[0091] Step 6: Conduct adversarial testing and select the optimal model. The model is thoroughly tested using a variety of adversarial attack methods. Combined with clean samples from the test set, the model's generalization and robustness are systematically evaluated. By comparing the model's performance on clean and adversarial samples, its stability and adaptability in complex environments are comprehensively analyzed. Ultimately, the optimal model is selected based on the evaluation results to ensure its reliability and effectiveness in practical applications. This includes the following steps:
[0092] Step 6-1, conduct adversarial attack: Use multiple attack methods to process the test clean samples to generate multiple adversarial samples, and respectively combine the test clean samples and the generated adversarial samples into a test sample set; the adversarial attack methods used in this invention include standard white-box attack methods (such as FGSM and PGD), as well as other more challenging attack methods (such as MIM attack and adaptive attack), to generate adversarial samples under four types of attacks;
[0093] Step 6-2: After completing the adversarial attack, conduct a detailed comparative test on the performance of the model on the adversarial samples and clean samples; input the test sample sets generated in step 6-1 into the alternative models for classification; record the classification accuracy, misclassification rate and confidence distribution of the model on clean samples and adversarial samples, and analyze the performance difference of the model on clean samples and adversarial samples. If it is found that the model has significant weaknesses under a certain type of attack, the training strategy can be locally adjusted for this type of attack, such as enhancing adversarial training, optimizing the loss function or adjusting the regularization method to further improve the robustness of the model. The comparative test results show that when the test accuracy on clean samples and adversarial samples is similar, the model training time of the method of the present invention is only one-third of that of the IE-Skips method, which significantly improves the computational efficiency.
[0094] Step 6-3, Evaluation Metrics Analysis: Based on the classification performance comparison, this paper further evaluates the model from a robustness perspective. The model's attack success rate (ASR), perturbation robustness (PR), and average confidence difference (ACD) are calculated to comprehensively measure the model's performance in adversarial environments. ASR measures the effectiveness of the attack method on the model, PR reflects the model's stability in the face of input perturbations, and ACD characterizes the difference in the model's decision confidence on clean and adversarial samples, thereby assessing its adversarial uncertainty.
[0095] By comprehensively analyzing these evaluation metrics, the present invention can more accurately optimize training strategies or adjust adversarial training schemes, ensuring the reliability and stability of the model under different attack environments. When selecting the optimal model, comprehensive considerations are taken into account. Prioritizing models with balanced and high accuracy on both clean and adversarial samples; secondly, selecting models with the lowest ASR and highest PR; and thirdly, selecting models with the lowest ACD for greater stability. Finally, based on the above conditions, selecting models with higher computational efficiency to improve the feasibility of actual deployment and use in bioinformatics verification.
[0096] Those skilled in the art will appreciate that the embodiments described herein are intended to help readers understand the principles of the present invention, and it should be understood that the scope of protection of the present invention is not limited to such specific descriptions and embodiments. Those skilled in the art can make various other specific variations and combinations based on the technical teachings disclosed in the present invention without departing from the essence of the present invention, and such variations and combinations are still within the scope of protection of the present invention.
Claims
1. A bioinformatics verification method based on a backward Euler residual architecture, characterized in that: The following steps are involved: Step 1. Prepare the dataset: Select public face recognition and fingerprint recognition related datasets as clean sample sets, and divide the clean sample sets into training clean sample sets and test clean sample sets; Step 2: Data preprocessing: Normalize the images in the training clean sample set, randomly crop the images and add edge padding, and randomly flip the images horizontally; Perform tensor transformation and normalization on the images in the test clean sample set; Step 3: Design a WideResNet model based on the backward Euler residual network architecture and initialize the model parameters; the WideResNet model based on the backward Euler residual network architecture includes an input layer, an intermediate layer, and an output layer; The input layer uses a convolutional layer for initial feature extraction, and then connects a BN layer and a ReLU activation function; The middle layer constructs a deep network by stacking multiple backward Euler residual modules. Each backward Euler residual module consists of four backward Euler network layers, and each backward Euler network layer includes two convolutional layers. Except for the first backward Euler residual module, the rest of the backward Euler residual modules use convolution with a stride of 2 in the first backward Euler network layer to achieve feature map downsampling, and the convolution stride of the remaining backward Euler network layers is 1; in the first backward Euler residual module, the stride of the convolution layer in all backward Euler network layers is 1; At the same time, each backward Euler residual module performs channel expansion in the first backward Euler network layer, and the widen_factor parameter controls the expansion ratio of the number of channels; in each backward Euler residual module, a residual connection is established with the output of each backward Euler network layer through the input features; In each backward Euler residual module, the input features of the backward Euler residual module are respectively connected with the output of each backward Euler network layer, and all residual connections are accumulated as the output of the backward Euler residual module; The output layer uses global average pooling to compress the features to 1x1 size, and then the fully connected layer completes the classification task; Step 4. Generate adversarial samples: Process clean samples using the PGD attack method to generate adversarial samples; process samples in the training clean sample set and the test clean sample set using the PGD attack method to generate training adversarial samples and test adversarial samples; then combine the training clean samples and training adversarial samples into the training sample set, and combine the test clean samples and test adversarial samples into the test sample set; Step 5: Model training and evaluation: Use the training sample set to train the WideResNet model. After each training cycle, perform model evaluation: Use the test sample set to calculate the accuracy of the model on clean samples and adversarial samples respectively. If better accuracy is achieved on clean samples, the parameters of the current model are saved and the model is used as an alternative model; Step 6: Perform adversarial detection and select the optimal model; including the following steps: Step 6-1, conduct adversarial attack: use multiple attack methods to process the test clean samples, generate multiple adversarial samples, and combine the test clean samples and the generated adversarial samples into a test sample set; Step 6-2: Input the test sample sets generated in step 6-1 into the candidate models for classification; Step 6-3. Evaluation Metrics Analysis: Calculate the model's adversarial attack success rate (ASR), the model's perturbation robustness (PR), and the average confidence difference (ACD). When selecting the optimal model, prioritize the model with balanced and high accuracy on both clean and adversarial samples. Next, select the model with the lowest ASR and highest PR. Furthermore, select the model with the smallest ACD. Finally, based on the above conditions, select the model with the highest computational efficiency and use it for bioinformatics verification.