Target detection attack method based on local attribute generative adversarial network
By generating adversarial networks based on local attributes, constructing graph structures and introducing local attribute difference losses to generate adversarial samples, the problem of insufficient concealment of target detection models in adversarial samples is solved, and the effectiveness of adversarial attacks and generalization capabilities are improved.
Patent Information
- Application Number
- CN202510832556.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-09-26
AI Technical Summary
Existing target detection models are prone to making incorrect predictions when faced with adversarial samples, and the adversarial samples are not sufficiently concealed, making it difficult to strike a balance between improving the attack success rate and concealment.
A method based on local attribute generative adversarial network is adopted to generate adversarial samples by constructing graph structure and local attribute difference loss function, and introducing target positioning attack loss to optimize the visual quality and concealment of adversarial samples and reduce the accuracy of target detection model.
The generated adversarial samples are visually imperceptible to the naked eye, significantly reducing the accuracy of the target detection model and improving the generalization ability of different target detection models.
Smart Images

Figure CN120707832A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of target detection attack technology, and in particular to a target detection attack method based on a local attribute-generating adversarial network. Background Art
[0002] In recent years, deep learning models have demonstrated superb performance in various tasks. Among them, target detection models, as the basis of many tasks in the field of computer vision, have always been a research hotspot. Target detection models based on deep learning have gradually replaced traditional target detection methods with their superior performance and have been widely used in key fields such as autonomous driving, medical image analysis, and biosafety monitoring.
[0003] However, numerous studies have shown that deep neural networks are prone to mispredictions when faced with carefully constructed adversarial examples. This poses similar security challenges to deep learning-based object detection models. The emergence of adversarial examples in the field of object detection poses a significant challenge to the robustness of these models. Mainstream adversarial attack methods for object detection include those based on gradient iteration, constrained optimization, and generative networks. These methods primarily rely on global perturbations, but these methods have significant drawbacks. Global perturbations can easily disrupt the overall structure of an image, making adversarial examples perceptible to the naked eye. Currently, striking a balance between improving the success rate of adversarial examples and their stealthiness is a key challenge facing object detection adversarial attack research.
[0004] Therefore, a target detection attack method based on local attribute generative adversarial network is provided to solve the above problems. Summary of the Invention
[0005] In order to solve the above problems, the present invention provides a target detection attack method based on local attribute generative adversarial network. By optimizing the quality and concealment of adversarial samples, the generated adversarial samples are visually imperceptible to the naked eye, and at the same time significantly reduce the accuracy of the target detection model, thereby achieving an effective attack on the target detection model.
[0006] To achieve the above objectives, the present invention provides a target detection attack method based on a local attribute generative adversarial network, which specifically includes the following steps:
[0007] S1: Preprocess the images and image annotation information in the target detection dataset to obtain preprocessed images and annotation information;
[0008] S2: Input the image preprocessed by S1 into the generative adversarial network to generate adversarial perturbations, and obtain adversarial samples based on the adversarial perturbations;
[0009] S3: Divide the image preprocessed by S1 into image blocks and construct a graph structure; divide the adversarial sample obtained by S2 into the same blocks as the image preprocessed by S1, substitute the edge weight values into the graph structure, and obtain the edge weight distribution of the adversarial sample based on the graph structure based on the edge weight values; use the Kullback-Leibler divergence function to obtain the local attribute difference loss function based on the graph structure based on the difference in edge weight distribution of the preprocessed image and the adversarial sample based on the graph structure;
[0010] S4: Generate the target error bounding box position label based on the annotation information preprocessed by S1, and input the adversarial sample into the target detection network to obtain the predicted bounding box label; use the Smooth L1 function to obtain the positioning attack loss function based on the difference between the predicted bounding box label of the adversarial sample and the target error bounding box position label;
[0011] S5: Update the parameters of the generative adversarial network by backpropagating the local attribute difference loss function based on the graph structure in S3 and the positioning attack loss function in S4 to obtain the updated generative adversarial network;
[0012] S6: Input the image preprocessed by S1 into the updated generative adversarial network to obtain the latest adversarial sample.
[0013] Preferably, S2 specifically includes the following steps:
[0014] S21: Input the image x preprocessed by S1 into the generator G of the generative adversarial network to generate a perturbation δ with the same size as the preprocessed image x;
[0015] S22: The preprocessed image x is input into the target detection network to obtain the detection target box rois. According to the location area of the target box, a mask img_mask with the same shape as the preprocessed image x is calculated;
[0016] S23: Generate adversarial sample x' based on mask img_mask and perturbation δ:
[0017] x'=x+δ·img_mask.
[0018] Preferably, S3 specifically includes the following steps:
[0019] S31: Divide the pre-processed image x into k×k image blocks, where the i-th image block is p i ,i∈[1,k 2 ], k is the number of fixed image blocks divided into each row and column of each image, the image blocks are the vertices of the graph structure, and each image block p i Corresponding to a vertex in the graph structure, the vertex set that constitutes the graph Expressed as:
[0020]
[0021] Among them, v i is the i-th vertex in the vertex set;
[0022] S32: Structural similarity SSIM is used to calculate the similarity SSIM(a, b) between each two image blocks, which is expressed as:
[0023]
[0024] Among them, a and b represent two image blocks, μ a and μ b are the average brightness of image blocks a and b, σ a and σ b are the standard deviations of image blocks a and b, σ ab is the covariance of image blocks a and b, C1 and C2 are constants;
[0025] S33: Calculate the structural similarity between every two vertices and construct the edge set ε of the graph based on the structural similarity:
[0026]
[0027] Among them, vi, vj come from the vertex set Indicates the image block corresponding to the image; SSIM(v i ,v j )=SSIM(p i ,p j ), structural similarity SSIM is used to determine whether vertices form edges;
[0028] S34: Based on the calculated structural similarity between the image blocks, the adjacency matrix A of the graph is constructed. The adjacency matrix A is a k 2 ×k 2 A matrix, where Α[i,j] represents the image block v i and v j Structural similarity between vertices: if there is an edge between vertices, the corresponding similarity value is used as the weight of the edge, otherwise the value is 0;
[0029] For each vertex v i , only retain the m most similar vertices as neighbors, and the edge set ε retains the edges with the m most similar vertices, and constructs the graph structure of the preprocessed image, which is expressed as:
[0030]
[0031] in, and ε are the vertex set and edge set constructed from the preprocessed image;
[0032] S35: In the graph structure G of the preprocessed image, each vertex Represents an image block p i , whose adjacent vertex set is By edge weight w ij Connect and normalize the vertex v i The weight distribution after the local structural information in the entire graph structure G is expressed as:
[0033]
[0034] Among them, w ij =SSIM(v i ,v j ) represents the vertex v i Its adjacent vertex v j The edge weights between is the edge weight normalization factor of all adjacent vertices, P i (j) is the probability distribution,
[0035] S36: The adversarial sample x' is divided into k×k image blocks in the same way as the preprocessed image x, and the vertex set of the adversarial sample is obtained. Substitute the graph structure G of the preprocessed image constructed by S34 and update the edge weight value to obtain the edge set of the adversarial sample and graph structure
[0036]
[0037] Graph structure in adversarial examples In each vertex Represents an image block p i ', its adjacent vertex set is By edge weight Connect and normalize vertices In the whole picture The weight distribution after the local structural information in is expressed as:
[0038]
[0039] in, Vertex Its adjacent vertices The edge weights between is the edge weight normalization factor of all adjacent vertices, Q i (j) is the probability distribution,
[0040] S37: Use Kullback-Leibler divergence to measure the difference between the adjacent edge weight distributions of the preprocessed image and the adversarial sample at the same node position:
[0041]
[0042] S38: Average the edge weight distribution of all vertices in the graph and calculate the local attribute difference loss L of the entire graph based on the graph structure graph :
[0043]
[0044] Preferably, S4 specifically includes the following steps:
[0045] S41: Based on the annotation information b pre-processed by S1 gt Randomly increase or decrease by three times to obtain the target error bounding box position label b f ;
[0046] S42: Input the adversarial sample into the target detection network to obtain the predicted bounding box label b pred , using Smooth L1 loss function to calculate b pred and b f The deviation between them is used to obtain the positioning attack loss L misloc , expressed as:
[0047]
[0048] Among them, N is the number of targets detected by the target detection network; x, y are the horizontal and vertical coordinates of the center point of the target error bounding box, respectively, and w, h are the width and height of the target error bounding box.
[0049] Preferably, S5 specifically includes the following steps:
[0050] S51: Calculate the total loss function L generated by adversarial samples total :
[0051] L total =L GAN (G,D)+αL L2 +βL cls +γL fea +μL graph +vL misloc ;
[0052] Among them, L GAN (G,D)=E I [logG(I)]+E I[log(1-D(G(I)))] is the loss function of the generative adversarial network, G is the generator of the generative adversarial network, D is the discriminator, I is the input image, and E I is the mathematical expectation of I; L L2 (G)=E I [‖IG(I)‖2] is used to measure the difference between the generated adversarial samples and the original samples; is the loss function for attacking the target detector to detect the category, X m is the adversarial sample after inputting the original sample X for m iterations, t n is one of the detection targets of the input original sample X, l n is the correct category of the detected target, l' n is the specified error class label; is the multi-scale attention feature loss, Y m Represents the feature subgraph extracted by the mth layer of the feature extraction network of the target detector, R m is a random predefined feature map, A m is the calculated attention weight, ° is the Hadamard product operation between the two matrices; α, β, γ, μ, v are the weight factors of each loss function;
[0053] S52: Update the parameters of the generative adversarial network based on the iterative training strategy to optimize L total .
[0054] Preferably, S52 specifically includes the following steps:
[0055] S521: The original sample is input to the generator G output perturbation to generate adversarial samples, the adversarial samples are input to the discriminator, the total discriminator loss is calculated, and the parameters of the discriminator D are updated by backpropagation;
[0056] S522: Calculate the generation adversarial loss L of the adversarial sample GAN 、L L2 Perturbation constraint loss, L cls Target category attack loss, L fea Feature attention loss, L graph Local attribute difference loss and L misloc Locate the attack loss and then calculate the total loss L total , back-propagation updates the parameters of the generator;
[0057] S523: Determine whether the total loss is less than the set threshold t or the number of iterations reaches the set threshold i. If not, repeat S522 until the conditions are met to obtain the updated generative adversarial network.
[0058] Therefore, the present invention adopts the above-mentioned target detection attack method based on local attribute generative adversarial network. By constructing a graph structure based on local attributes and introducing local attribute difference loss, the adversarial sample maintains spatial structure consistency during the generation process, optimizes its visual quality, and improves the concealment of the adversarial sample.
[0059] Furthermore, by introducing target positioning attack loss, the target detection model produces positioning bias on adversarial samples, so that the adversarial attack can not only output incorrect detection results, but also improve the generalization ability of different target detection models.
[0060] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 A flowchart of a target detection attack method based on a local attribute-generating adversarial network in the present invention;
[0062] Figure 2 Schematic diagram of the network structure in an embodiment of the present invention. DETAILED DESCRIPTION
[0063] The technical solution of the present invention is further described below with reference to the accompanying drawings and embodiments.
[0064] Unless otherwise defined, technical or scientific terms used in the present invention shall have the same meaning as commonly understood by one of ordinary skill in the art to which the present invention belongs.
[0065] The words “include” or “comprising” and similar words used in the present invention mean that the elements before the word include the elements listed after the word, and do not exclude the possibility of also including other elements. The orientation or position relationship indicated by the terms “inside”, “outside”, “upper”, “lower”, etc. is based on the orientation or position relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation of the present invention. When the absolute position of the described object changes, the relative position relationship may also change accordingly. In the present invention, unless otherwise clearly stipulated and limited, the terms such as “attachment” should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral whole; it can be directly connected or indirectly connected through an intermediate medium, and it can be the internal connection of two elements or the interaction relationship between two elements. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to the specific circumstances.
[0066] Example
[0067] A target detection attack method based on local attribute generation adversarial network, such as Figure 1-2 As shown, the specific steps include:
[0068] S1: Preprocess the images and image annotation information in the target detection dataset to obtain preprocessed images and annotation information;
[0069] S2: Input the image pre-processed by S1 into the generative adversarial network to generate adversarial perturbations, and obtain adversarial samples based on the adversarial perturbations; specifically, it includes:
[0070] S21: Input the image x preprocessed by S1 into the generator G of the generative adversarial network to generate a perturbation δ with the same size as the preprocessed image x;
[0071] S22: The preprocessed image x is input into the target detection network to obtain the detection target box rois. According to the position area of the target box, a mask img_mask with the same shape as the preprocessed image x is calculated. It indicates which areas the perturbation should be applied to. The value in img_mask is 0 or 1. A value of 1 indicates that the perturbation needs to be applied to the area, and a value of 0 indicates that the area is not affected by the perturbation.
[0072] S23: Generate adversarial sample x' based on mask img_mask and perturbation δ:
[0073] x'=x+δ·img_mask.
[0074] S3: Divide the image preprocessed by S1 into image blocks and construct a graph structure; divide the adversarial sample obtained by S2 into the same blocks as the image preprocessed by S1, substitute the edge weight values into the graph structure, and obtain the edge weight distribution of the adversarial sample based on the graph structure based on the edge weight values; use the Kullback-Leibler divergence function to obtain the local attribute difference loss function based on the graph structure based on the difference in edge weight distribution of the preprocessed image and the adversarial sample based on the graph structure; specifically, it includes:
[0075] S31: Divide the preprocessed image x into k×k image blocks, where the i-th image block is p i ,i∈[1,k 2 ], k is the number of fixed image blocks divided into each row and column of each image, and these image blocks will serve as the vertices of the graph constructed later, forming the vertex set of the graph Right now:
[0076]
[0077] Among them, v i is the i-th vertex in the vertex set; each patchp iEach corresponds to a vertex in the graph.
[0078] S32: For every two patches a and b, the structural similarity SSIM is used to calculate the similarity SSIM(a, b) between each two image blocks, which is expressed as:
[0079]
[0080] Among them, a and b represent two image blocks, μ a and μ b are the average brightness of image blocks a and b, σ a and σ b are the standard deviations of image blocks a and b, σ ab is the covariance of image blocks a and b, C1 and C2 are constants;
[0081] S33: Calculate the structural similarity between every two vertices and construct the edge set ε of the graph based on the structural similarity:
[0082]
[0083] Among them, v i 、v j From the vertex set Indicates the image block corresponding to the image; SSIM(v i ,v j )=SSIM(p i ,p j ), structural similarity SSIM is used to determine whether vertices form edges;
[0084] S34: Based on the calculated structural similarity between the image blocks, the adjacency matrix A of the graph is constructed. The adjacency matrix A is a k 2 ×k 2 A matrix, where Α[i,j] represents the image block v i and v j Structural similarity between vertices: if there is an edge between vertices, the corresponding similarity value is used as the weight of the edge, otherwise the value is 0;
[0085] For each vertex v i , only retain the m most similar vertices as neighbors, and only retain the edges with the m most similar vertices in the edge set ε, and construct the graph structure of the preprocessed image, which is expressed as:
[0086]
[0087] in, and ε are the vertex set and edge set constructed from the preprocessed image;
[0088] S35: In the graph structure G of the preprocessed image, each vertex Represents an image block p i , whose adjacent vertex set is By edge weight w ij Connect and normalize the vertex v i The weight distribution after the local structural information in the entire graph structure G is expressed as:
[0089]
[0090] Among them, w ij =SSIM(v i ,v j ) represents the vertex v i Its adjacent vertex v j The edge weights between is the edge weight normalization factor of all adjacent vertices, so that P i (j) forming a probability distribution,
[0091] S36: The adversarial sample x' is divided into k×k image blocks in the same way as the preprocessed image x, and the vertex set of the adversarial sample is obtained. Substitute the graph structure G of the preprocessed image constructed by S34 and update the edge weight value to obtain the edge set of the adversarial sample and graph structure
[0092]
[0093] Graph structure in adversarial examples In each vertex Represents an image block p i ', its adjacent vertex set is By edge weight Connect and normalize vertices In the whole picture The weight distribution after the local structural information in is expressed as:
[0094]
[0095] in, Vertex Its adjacent vertices The edge weights between is the edge weight normalization factor of all adjacent vertices, so that Q i (j) forming a probability distribution,
[0096] S37: Use Kullback-Leibler divergence to measure the difference between the adjacent edge weight distributions of the preprocessed image and the adversarial sample at the same node position:
[0097]
[0098] S38: Average the edge weight distribution of all vertices in the graph and calculate the local attribute difference loss L of the entire graph based on the graph structure graph :
[0099]
[0100] S4: Generate the target error bounding box position label based on the annotation information pre-processed by S1, and input the adversarial sample into the target detection network to obtain the predicted bounding box label. Use the Smooth L1 function to obtain the positioning attack loss function based on the difference between the predicted bounding box label of the adversarial sample and the target error bounding box position label. Specifically, it includes:
[0101] S41: The true label b of the original sample target bounding box gt Randomly increase or decrease by three times to obtain the target error bounding box position label b f ;
[0102] S42: Input the adversarial sample into the target detection network to obtain the predicted bounding box label b pred , using Smooth L1 loss function to calculate b pred and b f The deviation between them, that is, the positioning attack loss L misloc , expressed as:
[0103]
[0104] Among them, N is the number of targets detected by the target detection network; x, y are the horizontal and vertical coordinates of the center point of the target error bounding box, respectively, and w, h are the width and height of the target error bounding box.
[0105] S5: Update the parameters of the generative adversarial network by backpropagating the local attribute difference loss function based on the graph structure in S3 and the positioning attack loss function in S4 to obtain the updated generative adversarial network;
[0106] S51: Calculate the total loss function L generated by adversarial samples total :
[0107] L total =L GAN (G,D)+αL L2 +βL cls +γL fea +μL graph +vLmisloc ;
[0108] Among them, L GAN (G,D)=E I [logD(I)]+E I [log(1-D(G(I)))] is the loss function of the generative adversarial network, G is the generator of the generative adversarial network, D is the discriminator, I is the input image, E I is the mathematical expectation of I; L L2 (G)=E I [‖IG(I)‖2] is the l2 loss function introduced to measure the difference between the generated adversarial sample and the original sample; is the loss function for attacking the target detector to detect the category, X m is the adversarial sample after inputting the original sample X for m iterations, t n is one of the detection targets of the input original sample X, l n is the correct category of the detected target, l' n is the specified error class label; is the multi-scale attention feature loss, Y m Represents the feature subgraph extracted by the mth layer of the feature extraction network of the target detector, R m is a random predefined feature map, A m is the calculated attention weight, ° is the Hadamard product operation between the two matrices; α, β, γ, μ, ν are the weight factors of each loss function;
[0109] S52: Update the parameters of the generative adversarial network based on the iterative training strategy to optimize L total . Specifically including:
[0110] S521: The original sample is input to the generator G output perturbation to generate adversarial samples, the adversarial samples are input to the discriminator, the total discriminator loss is calculated, and the parameters of the discriminator D are updated by backpropagation;
[0111] S522: Calculate the generation adversarial loss L of the adversarial sample GAN 、L L2 Perturbation constraint loss, L cls Target category attack loss, L fea Feature attention loss, L graph Local attribute difference loss and L misloc Locate the attack loss and then calculate the total loss L total , back-propagation updates the parameters of the generator;
[0112] S523: Determine whether the total loss is less than the set threshold t or the number of iterations reaches the set threshold i. If not, repeat S522 until the conditions are met to obtain the updated generative adversarial network.
[0113] S6: Input the image preprocessed by S1 into the updated generative adversarial network to obtain the latest adversarial sample.
[0114] Example 1
[0115] This example uses two public blood cell datasets, BCCD and LISC, to verify the effectiveness of a target detection attack method based on a local attribute generative adversarial network. The details are as follows:
[0116] The experiments used two publicly available blood cell datasets, BCCD and LISC, for training and testing. The BCCD dataset contains 364 white blood cell images, and the LISC dataset contains 250 white blood cell images. Both datasets are derived from peripheral blood and are suitable for medical object detection tasks. The datasets are divided into training and test sets to ensure effective training and evaluation.
[0117] As shown in Table 1 below, the comparative experimental results of different attack methods on the FasterR-CNN model are given:
[0118] Table 1 Comparative experimental results of different attack methods on FasterR-CNN model
[0119]
[0120]
[0121] As can be seen from Table 1, in terms of attack success rate, the method provided in this embodiment achieved an attack success rate of 90.14% on the BCCD dataset and 97.29% on the LISC dataset. SSIM is mainly used to measure the structural similarity of images before and after the attack, thereby judging the impact of the attack on image quality. In terms of structural similarity, the method provided in this embodiment achieved a structural similarity of 0.94 on the BCCD dataset and 0.99 on the LISC dataset, which is 0.09 higher than the second highest structural similarity of the UEA method. Overall, the method proposed in this embodiment is superior to these existing methods and can effectively target target detection attack tasks. The target detection attack method based on the local attribute generative adversarial network optimizes the quality and concealment of adversarial samples. The generated adversarial samples are visually imperceptible to the naked eye, while significantly reducing the accuracy of the target detection model, thereby achieving an effective attack on the target detection model.
[0122] Therefore, the present invention adopts the above-mentioned target detection attack method based on local attribute generative adversarial network. By constructing a graph structure based on local attributes and introducing local attribute difference loss, the adversarial sample maintains spatial structure consistency during the generation process, optimizes its visual quality, and improves the concealment of the adversarial sample; by introducing target positioning attack loss, the target detection model produces positioning deviation on the adversarial sample, so that the adversarial attack can not only output incorrect detection results, but also improve the generalization ability of different target detection models.
[0123] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit the same. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that they can still modify or replace the technical solutions of the present invention with equivalents, and these modifications or equivalent replacements cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A target detection attack method based on local attribute generative adversarial network, characterized by: The specific steps include: S1: Preprocess the images and image annotation information in the target detection dataset to obtain preprocessed images and annotation information; S2: Input the image preprocessed by S1 into the generative adversarial network to generate adversarial perturbations, and obtain adversarial samples based on the adversarial perturbations; S3: Divide the image preprocessed by S1 into image blocks and construct a graph structure; divide the adversarial sample obtained by S2 into the same blocks as the image preprocessed by S1, substitute the edge weight values into the graph structure, and obtain the edge weight distribution of the adversarial sample based on the graph structure based on the edge weight values; use the Kullback-Leibler divergence function to obtain the local attribute difference loss function based on the graph structure based on the difference in edge weight distribution of the preprocessed image and the adversarial sample based on the graph structure; S4: Generate the target error bounding box position label based on the annotation information preprocessed by S1, and input the adversarial sample into the target detection network to obtain the predicted bounding box label; use the Smooth L1 function to obtain the positioning attack loss function based on the difference between the predicted bounding box label of the adversarial sample and the target error bounding box position label; S5: Update the parameters of the generative adversarial network by backpropagating the local attribute difference loss function based on the graph structure in S3 and the positioning attack loss function in S4 to obtain the updated generative adversarial network; S6: Input the image preprocessed by S1 into the updated generative adversarial network to obtain the latest adversarial sample.
2. The target detection attack method based on local attribute generative adversarial network according to claim 1, characterized in that: S2 specifically includes the following steps: S21: Input the image x preprocessed by S1 into the generator G of the generative adversarial network to generate a perturbation δ with the same size as the preprocessed image x; S22: The preprocessed image x is input into the target detection network to obtain the detection target box rois. According to the location area of the target box, a mask img_mask with the same shape as the preprocessed image x is calculated; S23: Generate adversarial sample x' based on mask img_mask and perturbation δ: x′=x+δ·img_mask.
3. The target detection attack method based on local attribute generative adversarial network according to claim 2, characterized in that: S3 specifically includes the following steps: S31: Divide the pre-processed image x into k×k image blocks, where the i-th image block is p i ,i∈[1,k 2 ], k is the number of fixed image blocks divided into each row and column of each image, the image blocks are the vertices of the graph structure, and each image block p i Corresponding to a vertex in the graph structure, the vertex set that constitutes the graph Expressed as: Among them, v i is the i-th vertex in the vertex set; S32: Structural similarity SSIM is used to calculate the similarity SSIM(a, b) between each two image blocks, which is expressed as: Among them, a and b represent two image blocks, μ a and μ b are the average brightness of image blocks a and b, σ a and σ b are the standard deviations of image blocks a and b, σ ab is the covariance of image blocks a and b, C1 and C2 are constants; S33: Calculate the structural similarity between every two vertices and construct the edge set ε of the graph based on the structural similarity: Among them, v i ,v j From the vertex set , represents the image block corresponding to the image; SSIM(v i ,v j )=SSIM(p i ,p j ), structural similarity SSIM is used to determine whether vertices form edges; S34: Based on the calculated structural similarity between the image blocks, the adjacency matrix A of the graph is constructed. The adjacency matrix A is a k 2 ×k 2 A matrix, where Α[i,j] represents the image block v i and v j Structural similarity between vertices: if there is an edge between vertices, the corresponding similarity value is used as the weight of the edge, otherwise the value is 0; For each vertex v i , only retain the m most similar vertices as neighbors, and the edge set ε retains the edges with the m most similar vertices, and constructs the graph structure of the preprocessed image, which is expressed as: in, and ε are the vertex set and edge set constructed from the preprocessed image; S35: In the graph structure G of the preprocessed image, each vertex Represents an image block p i , whose adjacent vertex set is By edge weight w ij Connect and normalize the vertex v i The weight distribution after the local structural information in the entire graph structure G is expressed as: Among them, w ij =SSIM(v i ,v j ) represents the vertex v i Its adjacent vertex v j The edge weights between is the edge weight normalization factor of all adjacent vertices, P i (j) is the probability distribution, S36: The adversarial sample x' is divided into k×k image blocks in the same way as the preprocessed image x, and the vertex set of the adversarial sample is obtained. Substitute the graph structure G of the preprocessed image constructed by S34 and update the edge weight value to obtain the edge set of the adversarial sample and graph structure Graph structure in adversarial examples In each vertex Represents an image block p i ', its adjacent vertex set is By edge weight Connect and normalize vertices In the whole picture The weight distribution after the local structural information in is expressed as: in, Vertex Its adjacent vertices The edge weights between is the edge weight normalization factor of all adjacent vertices, Q i (j) is the probability distribution, S37: Use Kullback-Leibler divergence to measure the difference between the adjacent edge weight distributions of the preprocessed image and the adversarial sample at the same node position: S38: Average the edge weight distribution of all vertices in the graph and calculate the local attribute difference loss L of the entire graph based on the graph structure graph :
4. The target detection attack method based on local attribute generative adversarial network according to claim 3, characterized in that: S4 specifically includes the following steps: S41: Based on the annotation information b pre-processed by S1 gt Randomly increase or decrease by three times to obtain the target error bounding box position label b f ; S42: Input the adversarial sample into the target detection network to obtain the predicted bounding box label b pred , using SmoothL1 loss function to calculate b pred and b f The deviation between them is used to obtain the positioning attack loss L misloc , expressed as: Among them, N is the number of targets detected by the target detection network; x, y are the horizontal and vertical coordinates of the center point of the target error bounding box, respectively, and w, h are the width and height of the target error bounding box.
5. The target detection attack method based on local attribute generative adversarial network according to claim 4, characterized in that: S5 specifically includes the following steps: S51: Calculate the total loss function L generated by adversarial samples total : L total =L GAN (G,D)+αL L2 +βL cls +γL fea +μL graph +νL misloc ; Among them, L GAN (G,D)=E I [logD(I)]+E I [log(1-D(G(I)))] is the loss function of the generative adversarial network, G is the generator of the generative adversarial network, D is the discriminator, I is the input image, E I is the mathematical expectation of I; L L2 (G)=E I [||IG(I)||2] is used to measure the difference between the generated adversarial samples and the original samples; is the loss function for attacking the target detector to detect the category, X m is the adversarial sample after inputting the original sample X for m iterations, y n is one of the detection targets of the input original sample X, l n is the correct category of the detected target, l' n is the specified error class label; is the multi-scale attention feature loss, Y m Represents the feature subgraph extracted by the mth layer of the feature extraction network of the target detector, R m is a random predefined feature map, A m is the calculated attention weight, ° is the Hadamard product operation between the two matrices; α, β, γ, μ, v are the weight factors of each loss function; S52: Update the parameters of the generative adversarial network based on the iterative training strategy to optimize L total .
6. The target detection attack method based on local attribute generative adversarial network according to claim 5, characterized in that: S52 specifically includes the following steps: S521: The original sample is input to the generator G output perturbation to generate adversarial samples, the adversarial samples are input to the discriminator, the total discriminator loss is calculated, and the parameters of the discriminator D are updated by backpropagation; S522: Calculate the generation adversarial loss L of the adversarial sample GAN , L L2 Perturbation constraint loss, L cls Target category attack loss, L fea Feature attention loss, L graph Local attribute difference loss and L misloc Locate the attack loss and then calculate the total loss L total , back-propagation updates the parameters of the generator; S523: Determine whether the total loss is less than the set threshold t or the number of iterations reaches the set threshold i. If not, repeat S522 until the conditions are met to obtain the updated generative adversarial network.
Citation Information
Cited By
Image classification model robustness enhancement method and system based on improved generative adversarial network
CN121010835A