Image generation method, apparatus, device, and computer storage medium
Patent Information
- Application Number
- CN202511802669.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2045-12-02
AI Technical Summary
这种图像生成方式,是基于人眼视角对图像特征进行更新调整得到新图像,应用这类新图像进行模型训练,往往难以暴露模型的逻辑漏洞,无法改进提升模型性能
[0008] Fifthly, embodiments of this application provide a computer program product, including a computer program, which, when executed, implements any of the image generation methods described in the above embodiments.
Smart Images

Figure CN121366331B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer technology, and in particular relates to an image generation method, apparatus, device and computer storage medium. Background Technology
[0002] Image recognition models, as one of the core technologies of artificial intelligence, are widely used in fields such as medicine, security, and transportation, significantly improving the efficiency and accuracy of image recognition. During the training process of image recognition models, it is necessary to add subtle perturbations to the original image to generate a new image, which is then used for model training to expose logical flaws in the model and improve its robustness. Current image generation methods typically involve randomly sampling or adding random noise to the image features of the original image to generate a new image. This method updates and adjusts image features based on the human eye's perspective, and using such new images for model training often fails to expose logical flaws in the model and cannot improve its performance. Summary of the Invention
[0003] This application provides an image generation method, apparatus, device, and computer storage medium that can combine the logical flaws of neurons in an image recognition model to generate new images more accurately. When using the new images for model training, it can fully expose the logical flaws of the model, improve the training effect of the model, and enhance the robustness and generalization ability of the model.
[0004] In a first aspect, embodiments of this application provide an image generation method, the method comprising: In the neurons of the image recognition model, several suspicious neurons are identified. These suspicious neurons are those that produce abnormal data output during the image recognition process of the image recognition model. Input a reference image into the image recognition model. The reference image is an image that has been correctly recognized by the image recognition model. During the image recognition process of the image recognition model, the average gradient between the activation values of the multiple suspicious neurons and the reference image is obtained. The average gradient is used to indicate the degree of change between the activation values and the reference image. The image data of the reference image is updated based on the average gradient to generate a new image.
[0005] Secondly, embodiments of this application provide an image generation apparatus, the apparatus comprising: The determination module is used to identify multiple suspicious neurons in the neurons of the image recognition model. The suspicious neurons are neurons that have abnormal data output during the image recognition process of the image recognition model. The input module is used to input a reference image into the image recognition model. The reference image is an image that has been correctly recognized by the image recognition model. The acquisition module is used to acquire the average gradient between the activation values of the multiple suspicious neurons and the reference image during the image recognition process of the image recognition model. The average gradient is used to indicate the degree of change between the activation values and the reference image. The generation module is used to update the image data of the reference image based on the average gradient and generate a new image.
[0006] Thirdly, embodiments of this application provide a computer device, the device including: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement any of the image generation methods in the above embodiments.
[0007] Fourthly, embodiments of this application provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement any of the image generation methods described in the above embodiments.
[0008] Fifthly, embodiments of this application provide a computer program product, including a computer program, which, when executed, implements any of the image generation methods described in the above embodiments.
[0009] This application discloses an image generation method, apparatus, device, and computer storage medium. When performing image recognition using an image recognition model, the output data of each neuron in the model is acquired, and suspicious neurons with abnormal data output are identified. A reference image that can be correctly identified is input into the image recognition model. During the recognition process of the reference image, the average gradient between the activation values of multiple suspicious neurons and the input reference image is acquired. This average gradient indicates the degree of change between the activation values and the reference image, reflecting potential logical flaws in the suspicious neurons. Based on this average gradient, the image data of the reference image is updated and adjusted to generate a new image. Therefore, this application, by addressing logical flaws in the neurons of the image recognition model, generates new images more accurately. Furthermore, a gradient ascent algorithm with added constraints is used during new image generation to control the update range and degree of image data, ensuring that the new image is substantially consistent with the reference image from a human eye's perspective. When using such new images for model training, logical flaws in the model can be fully exposed, improving the model's training effect and enhancing its robustness and generalization ability. Attached Figure Description
[0010] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a schematic diagram of the implementation environment of an image generation method provided in an embodiment of this application; Figure 2 This is a flowchart of an image recognition method provided in an embodiment of this application; Figure 3 This is a flowchart of a suspected neuron identification method provided in an embodiment of this application; Figure 4 This is a flowchart of an embodiment of the present application for obtaining the average gradient; Figure 5 This is a schematic diagram of the structure of an image generation device provided in an embodiment of this application; Figure 6 This is a schematic diagram of the hardware structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0012] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0013] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0014] To address the problems of existing technologies, embodiments of this application provide an image generation method, apparatus, device, and computer storage medium. By addressing the logical flaws in neurons within an image recognition model, new images are generated more accurately. When these new images are used for model training, the logical flaws in the model are fully exposed, improving the training effect and enhancing the model's robustness and generalization ability. The following detailed description of this solution is provided in conjunction with the accompanying drawings.
[0015] Figure 1 This is a schematic diagram of the implementation environment of an image generation method provided in an embodiment of this application, such as... Figure 1 As shown, the implementation environment may include a terminal 101 and an image recognition platform 102, with a communication connection between the terminal 101 and the image recognition platform 102.
[0016] In one embodiment, terminal 101 may have an application that supports image recognition installed and running. For example, terminal 101 may be a smartphone, tablet, laptop, desktop computer, smartwatch, etc., and this embodiment does not limit the device type of terminal 101. In one embodiment, terminal 101 may be a user-used terminal, and terminal 101 may send instructions to image recognition platform 102 through an application. These instructions can be used to instruct image recognition platform 102 to perform image recognition tasks. The number of terminals 101 may be one or more, and this embodiment does not limit this.
[0017] In one embodiment, the image recognition platform 102 may be deployed with an image recognition model, which can be used to provide background services for the aforementioned application. For example, the image recognition platform 102 undertakes the primary image data processing work, and the terminal 101 undertakes the secondary image data processing work; or, the image recognition platform 102 undertakes the secondary image data processing work, and the terminal 101 undertakes the primary image data processing work; or, the image recognition platform 102 or the terminal 101 each undertakes image data processing work independently. For example, the image recognition platform 102 may be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, network services, cloud communication, CDN (Content Delivery Network), and big data and artificial intelligence platforms, or a cloud computing platform or virtualization center. This application embodiment does not limit the device type of the image recognition platform 102.
[0018] Figure 2 This is a flowchart of an image recognition method provided in an embodiment of this application. This method can be applied to, for example... Figure 1The terminal or image recognition platform in the implementation environment shown can be considered a computer device. In this embodiment, the image recognition method is described with the computer device as the execution subject. Figure 2 As shown, the method may include the following steps.
[0019] S201. The computer device identifies multiple suspicious neurons in the neurons of the image recognition model. These suspicious neurons are neurons that have abnormal data output during the image recognition process of the image recognition model.
[0020] S202. The computer device inputs a reference image into the image recognition model. The reference image is an image that has been correctly recognized by the image recognition model.
[0021] S203. During the image recognition process of the image recognition model on the reference image, the computer device obtains the average gradient between the activation values of the multiple suspicious neurons and the reference image. The average gradient is used to indicate the degree of change between the activation values and the reference image.
[0022] S204. The computer device updates the image data of the reference image based on the average gradient and generates a new image.
[0023] In this embodiment, multiple suspicious neurons with abnormal data output are identified within the neurons of the image recognition model. A reference image that can be correctly identified is input into the image recognition model. During the recognition process of the reference image, the average gradient between the activation values of the multiple suspicious neurons and the input reference image is obtained. This average gradient indicates the degree of change between the activation values and the reference image, revealing potential logical flaws in the suspicious neurons. The image data of the reference image is then updated based on this average gradient to generate a new image. Therefore, this embodiment, by addressing the logical flaws in the neurons of the image recognition model, generates new images more accurately. When using these new images for model training, the logical flaws in the model are fully exposed, improving the training effect and enhancing the model's robustness and generalization ability.
[0024] The specific implementation methods of each of the above steps are described below.
[0025] In step S201, the computer device identifies multiple suspicious neurons in the neurons of the image recognition model.
[0026] The suspicious neuron is the neuron whose data output is abnormal during the image recognition process of the image recognition model.
[0027] In this embodiment, the image recognition model can be an artificial intelligence model built based on DNN (Deep Neural Networks). This model includes multiple operational layers, such as an input layer, multiple hidden layers, and an output layer. Each operational layer can include multiple neurons. Each neuron receives input data through weighted connections, performs data processing operations such as weighted summation and activation functions on the input data, and then generates output data. In this embodiment, the image recognition model can be a trained model. For example, a training dataset can be used to train the image recognition model. This training dataset can include multiple training images, each carrying annotation information, such as bounding boxes of detected targets in the image and category labels for image classification. A computer device can perform multiple rounds of iterative training on the image recognition model based on this training dataset, adjusting the neuron parameters of each operational layer until the error of the image recognition model's output is less than an error threshold. This error threshold can be set by the developer. The trained image recognition model can process, analyze and understand the input image, and identify the objects, scenes or features in the image. The specific training method of the image recognition model is not limited in the embodiments of this application.
[0028] Figure 3 This is a flowchart of a suspected neuron identification method provided in an embodiment of this application, such as... Figure 3 As shown, in one embodiment, the process by which the computer device identifies a suspicious neuron may include the following steps S301 to S304.
[0029] S301. The computer device inputs multiple test images into the image recognition model.
[0030] In one embodiment, the computer device, in response to a model testing instruction, acquires a test dataset, which may include multiple test images. For example, the test images may be images stored in the computer device, images captured from a video, or images obtained from any application or webpage; this embodiment does not limit the scope of the invention.
[0031] S302. During the image recognition process of the image recognition model on the multiple test images, the computer device acquires the state distribution data of each neuron.
[0032] The state distribution data can be used to indicate the number of times a neuron enters an active or inactive state when the image recognition result is correct or incorrect. This active and inactive state can be determined based on the neuron's data, specifically the activation value φ(t,n), where t represents the input image data of the image recognition model during the current image recognition process, and n represents the neuron's weights and biases. For example, if the activation value of any neuron is greater than or equal to the activation threshold, then that neuron is determined to be in an active state; if the activation value of any neuron is less than the activation threshold, then that neuron is determined to be in an inactive state. The activation threshold can be set by the developer.
[0033] In one embodiment, during the image recognition process of the image recognition model on any test image, the computer device acquires the state of each neuron and the current image recognition result. The state includes an active state and an inactive state. For example, the computer device can record the activation value of each neuron during the image recognition process and determine the state of each neuron based on the comparison between the activation value and an activation threshold. For any neuron, in response to the occurrence of an active state and the current image recognition result being correct, the neuron is determined to be in a first state; in response to the occurrence of an active state and the current image recognition result being incorrect, the neuron is determined to be in a second state; in response to the occurrence of an inactive state and the current image recognition result being correct, the neuron is determined to be in a third state; in response to the occurrence of an inactive state and the current image recognition result being incorrect, the neuron is determined to be in a fourth state. The computer device can calculate the number of times each neuron occurs in the first state, the second state, the third state, and the fourth state, and determine the distribution of the number of times each neuron occurs in the first, second, third, and fourth states as the state distribution data of any neuron.
[0034] S303. The computer device determines the suspicious score of each neuron based on the state distribution data of each neuron.
[0035] The suspicious score is used to indicate the degree of abnormality in the neuron's data output. In one embodiment, the suspicious score can be determined by the following formula (1). SN_score= (1) Wherein, SN_score represents the questionable score of neuron n. This represents the number of times neuron n enters its first state. This represents the number of times neuron n enters its second state. This represents the number of times neuron n enters the third state. This represents the number of times neuron n enters the fourth state. It should be noted that the above description of the method for calculating the suspicious score is only an exemplary description of one possible implementation. Other calculation formulas can be constructed to determine the suspicious score based on the principle that "the higher the frequency of neuron activation when the image recognition model makes a mistake, and the lower the frequency of neuron activation when the image recognition model makes a correct mistake, the more suspicious the neuron is." This application does not limit this aspect.
[0036] S304. The computer device identifies the neuron whose suspicious score meets the preset conditions as the suspicious neuron.
[0037] The preset conditions can be set by the developer. For example, the preset conditions may include the top K neurons with the highest suspicious scores. For example, the computer device can sort the suspicious scores of each neuron in descending order, and determine the top K neurons with the highest suspicious scores as suspicious neurons. Here, K is a positive integer, greater than 1, and less than the total number of neurons in the image recognition model. It should be noted that the above description of the preset conditions is only an example; the preset conditions can also be set to neurons with suspicious scores greater than a score threshold. This application embodiment does not limit the specific content of the preset conditions.
[0038] In this embodiment, by identifying the degree of abnormality of neurons during image recognition, suspicious neurons that may lead to defects in the decision logic of the image recognition model can be determined. This allows for more accurate localization of vulnerabilities in the image recognition model, enabling more targeted generation of new images in subsequent image generation processes.
[0039] In step S202, the computer device inputs a reference image into the image recognition model, which is an image that has been correctly recognized by the image recognition model.
[0040] In one embodiment, during the image recognition model's image recognition of multiple test images, the computer device can determine the test image correctly recognized by the image recognition model as the reference image. For example, during the image recognition model's recognition of the test images, the computer device can record the image recognition results corresponding to each test image, and in response to an image input command, obtain the test image with the correct image recognition result from the multiple test images as the reference image, and input the reference image into the image recognition model. In one embodiment, the reference image can also be an image in the aforementioned training dataset that can be correctly recognized by the image recognition model; this application embodiment does not limit this.
[0041] In step S203, during the image recognition process performed by the image recognition model on the reference image, the computer device obtains the average gradient between the activation values of the plurality of suspicious neurons and the reference image.
[0042] Wherein, the average gradient can be used to indicate the degree of change between the activation values and the reference image. Figure 4 is a flow chart of obtaining average gradient provided by the embodiment of the present application, as Figure 4 shown, in one embodiment, the process of obtaining the average gradient by the computer device may include the following steps S401 to S403.
[0043] S401: During the image recognition process performed by the image recognition model on any one of the reference images, the computer device obtains the activation value of each suspicious neuron.
[0044] In one embodiment, the computer device can obtain M reference images, where M is a positive integer and M≥1. The computer device can sequentially input the M reference images into the image recognition model. During the recognition process of the j-th reference image by the image recognition model, the computer device can traverse each suspicious neuron and obtain the activation value of each neuron. Wherein, j is a positive integer and 0<j≤M.
[0045] S402: The computer device obtains the gradient between the activation value of each suspicious neuron and the reference image.
[0046] In one embodiment, the calculation method of the gradient can be expressed as the following formula (2).
[0047] g i = φ(t,n) / t (2) Wherein, g i represents the gradient corresponding to the i-th suspicious neuron, i is a positive integer, 0<i≤N, and N is the total number of suspicious neurons; φ(t,n) represents the activation value of the i-th suspicious neuron, and t represents the input image data of the image recognition model in the current image recognition process.
[0048] S403: The computer device obtains the average value of the gradients corresponding to the plurality of suspicious neurons, and uses the average value as the average gradient.
[0049] In one embodiment, the calculation method of the average gradient can be expressed as the following formula (3).
[0050] g mean =( ) / N (3) Wherein, g mean represents the average gradient, g iLet represent the gradient corresponding to the i-th suspicious neuron, and N represent the total number of suspicious neurons.
[0051] In this embodiment, the gradients corresponding to each suspicious neuron are obtained, and the gradients are combined to generate new images. This allows for the generation of images based on potential defects and vulnerabilities in the decision-making logic of the image recognition model, ensuring that the newly generated images can expose the defects in the model's decision-making logic.
[0052] In step S204, the computer device updates the image data of the reference image based on the average gradient to generate a new image.
[0053] In one embodiment, the process by which the computer device generates a new image based on the average gradient and the reference image may include the following steps one and two.
[0054] Step 1: The computer equipment can perform gradient ascent processing on the average gradient based on the reference constraints.
[0055] The reference constraint is used to limit the range of variation of the average gradient, and the reference constraint can be implemented as a constraint function.
[0056] Step 2: The computer device can update the image data of the reference image based on the average gradient after gradient ascent processing, and generate the new image.
[0057] In this embodiment of the application, the computer device may use a gradient ascent algorithm with added constraint functions to generate a new image in combination with the input reference image. For example, the method of generating a new image can be expressed as the following formula (4).
[0058] t'=t+domain_constrain(g mean *step)(4) Where t' represents the new image; t represents the reference image; g mean The value represents the average gradient; step represents the step size, which can be used to control the magnitude of parameter updates; domain_constrain represents the constraint function.
[0059] In this embodiment, the gradient ascent algorithm is used to amplify the gradient of the suspicious neurons, which means amplifying the possible defects and vulnerabilities of the model. Furthermore, by adding constraints, i.e., constraint functions, the update range and degree of the generated new image can be limited, so that when the new image is viewed from the human eye, it can be basically consistent with the reference image and will not be recognized as a different image by the human eye. This ensures the rationality of the generated new image and improves the quality of image generation.
[0060] In one embodiment, after generating a new image, the computer device can also verify the validity of the new image. For example, the computer device can input the new image into the image recognition model. If the image recognition model correctly identifies the new image, the new image is determined to be invalid; if the image recognition model incorrectly identifies the new image, the new image is determined to be valid. For example, the computer device can input a new image generated based on the j-th reference image into the image recognition model. If the recognition result output by the image recognition model is the same as the recognition result of the j-th reference image, that is, the image recognition model can still correctly identify the new image, then the data update made on the j-th reference image based on the average gradient of the suspicious neuron is determined to be invalid, and the generated new image is invalid. If the recognition result output by the image recognition model is different from the recognition result of the j-th reference image, that is, the image recognition model cannot correctly identify the new image, then the data update made on the j-th reference image based on the average gradient of the suspicious neuron is determined to be valid, and the generated new image is valid. The recognition result of the j-th reference image can be determined based on the recognition of the reference image in step S202 above, or each reference image can be re-input into the image recognition model for recognition. This embodiment does not limit this approach. In this embodiment, by verifying new images and eliminating new images with invalid image data updates, the image generation quality can be improved.
[0061] In one embodiment, the computer device can repeatedly execute steps S202 to S204, that is, after generating a new image based on the j-th reference image, the (j+1)-th reference image is then obtained and input into the image recognition model, and steps S202 to S204 are executed until all reference images are traversed. The computer device can generate multiple new images. The image generation method of this application embodiment can generate new images in batches quickly and at low cost. Furthermore, the new images can reveal logical vulnerabilities in the model and can be used as adversarial examples for subsequent model training. The exposed model defects and vulnerabilities can then be targeted for repair, improving the model's recognition accuracy.
[0062] In this embodiment, during image recognition, the output data of each neuron in the image recognition model is acquired to identify suspicious neurons with abnormal data output. A reference image that can be correctly identified is input into the image recognition model. During the recognition process of the reference image, the average gradient between the activation values of multiple suspicious neurons and the input reference image is obtained. This average gradient indicates the degree of change between the activation value and the reference image, reflecting potential logical flaws in the suspicious neurons. Based on this average gradient, the image data of the reference image is updated and adjusted to generate a new image. Thus, this embodiment, by combining the logical flaws of neurons in the image recognition model, generates new images more accurately. Furthermore, a gradient ascent algorithm with added constraints is used during new image generation to control the update range and degree of image data, ensuring that the new image is essentially consistent with the reference image from a human perspective. When using such new images for model training, logical flaws in the model can be fully exposed, improving the training effect and enhancing the robustness and generalization ability of the model.
[0063] This application's embodiments start from the decision-making logic flaws of the model and generate adversarial examples that can expose these flaws. The technical solutions provided in this application's embodiments are not limited to the aforementioned image recognition models and image data. The adversarial example generation approach of this solution can also be applied to other types of artificial intelligence models. For example, generating speech data that can expose the flaws and vulnerabilities of speech recognition models, or text data that can expose the flaws and vulnerabilities of text recognition models. This application's embodiments do not limit the specific application scenarios.
[0064] Figure 5 This is a schematic diagram of an image generation device provided in an embodiment of this application. Figure 5 As shown, the device may include a determining module 510, an input module 520, an acquisition module 530, and a generating module 540.
[0065] The determination module 510 is used to determine multiple suspicious neurons in the neurons of the image recognition model. The suspicious neurons are neurons that have abnormal data output during the image recognition process of the image recognition model. Input module 520 is used to input a reference image into the image recognition model, wherein the reference image is an image that has been correctly recognized by the image recognition model; The acquisition module 530 is used to acquire the average gradient between the activation values of the plurality of suspicious neurons and the reference image during the image recognition process of the image recognition model performing image recognition on the reference image. The average gradient is used to indicate the degree of change between the activation values and the reference image. The generation module 540 is used to update the image data of the reference image based on the average gradient and generate a new image.
[0066] In one embodiment, the determining module 510 includes: An input unit is used to input multiple test images into the image recognition model; The acquisition unit is used to acquire state distribution data of each neuron during the image recognition process of the image recognition model on the multiple test images. The state distribution data is used to indicate the number of times the neuron is in an active state and an inactive state when the image recognition result is correct and incorrect. The first determining unit is configured to determine a suspicious score for each neuron based on the state distribution data of each neuron, wherein the suspicious score is used to indicate the degree of abnormality in the neuron's data output; The second determining unit is used to determine neurons whose suspicious scores meet preset conditions as suspicious neurons.
[0067] In one embodiment, the acquisition unit is configured to acquire the state of each neuron and the current image recognition result during the image recognition process of the image recognition model performing image recognition on any of the test images. The state includes the active state and the inactive state. For any neuron, in response to the occurrence of the active state and the current image recognition result being correct, the neuron is determined to be in a first state. In response to the occurrence of the active state and the current image recognition result being incorrect, the neuron is determined to be in a second state. In response to the occurrence of the inactive state and the current image recognition result being correct, the neuron is determined to be in a third state. In response to the occurrence of the inactive state and the current image recognition result being incorrect, the neuron is determined to be in a fourth state. The distribution of the number of times any neuron occurs in the first state, the second state, the third state, and the fourth state is determined as the state distribution data of any neuron.
[0068] In one embodiment, the preset conditions include the top K neurons with the highest suspected scores, where K is a positive integer and K>1.
[0069] In one embodiment, the device further includes an image determination module, used to determine the test image that is correctly recognized by the image recognition model as the reference image during the image recognition process of the image recognition model performing image recognition on the plurality of test images.
[0070] In one embodiment, the acquisition module 530 is configured to acquire the activation values of each of the suspicious neurons during the image recognition process of the image recognition model performing image recognition on the reference image; acquire the gradient between the activation values of each of the suspicious neurons and the reference image; and acquire the average value of the gradients corresponding to the plurality of suspicious neurons as the average gradient.
[0071] In one embodiment, the generation module 540 is configured to perform gradient ascent processing on the average gradient based on reference constraints, wherein the reference constraints are used to limit the range of variation of the average gradient; and update the image data of the reference image based on the average gradient after gradient ascent processing to generate the new image.
[0072] In one embodiment, the device further includes a recognition module for inputting the new image into the image recognition model; determining that the new image is invalid in response to the image recognition model correctly recognizing the new image; and determining that the new image is valid in response to the image recognition model incorrectly recognizing the new image.
[0073] The image generation apparatus provided in this application acquires the output data of each neuron in the image recognition model during image recognition, identifies suspicious neurons with abnormal data output, inputs a correctly identifiable reference image into the image recognition model, and acquires the average gradient between the activation values of multiple suspicious neurons and the input reference image during the recognition process of the reference image. This average gradient indicates the degree of change between the activation values and the reference image, and can reflect possible logical flaws in the suspicious neurons. Based on this average gradient, the image data of the reference image is updated and adjusted to generate a new image. Therefore, this application embodiment, by combining the logical flaws of neurons in the image recognition model, generates new images more accurately. Furthermore, by employing a gradient ascent algorithm with added constraints during new image generation, the update range and degree of image data are controlled to ensure that the new image is substantially consistent with the reference image from a human eye's perspective. When using such new images for model training, the logical flaws of the model can be fully exposed, improving the model's training effect and enhancing its robustness and generalization ability.
[0074] Figure 6 This is a schematic diagram of the hardware structure of a computer device provided in an embodiment of this application. For example... Figure 6 As shown, the computer device may include a processor 601 and a memory 602 storing computer program instructions.
[0075] Specifically, the processor 601 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0076] Memory 602 may include mass storage for data or instructions. For example, and not limitingly, memory 602 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. In one instance, memory 602 may include removable or non-removable (or fixed) media, or memory 602 may be non-volatile solid-state memory. Memory 602 may be internal or external to the integrated gateway disaster recovery device.
[0077] In one instance, memory 602 may be read-only memory (ROM). In one instance, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.
[0078] Memory 602 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Therefore, generally, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this disclosure.
[0079] The processor 601 reads and executes computer program instructions stored in the memory 602 to achieve... Figure 2 The image generation method in the illustrated embodiment.
[0080] In one example, the computer device may also include a communication interface 603 and a bus 606. Wherein, as... Figure 6 As shown, the processor 601, memory 602, and communication interface 603 are connected through bus 604 and complete communication with each other.
[0081] The communication interface 603 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0082] Bus 604 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 604 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.
[0083] The computer device can execute the process of generating new images in the embodiments of this application based on potential defects and vulnerabilities in the image recognition model, thereby achieving... Figure 2 Describes the image generation method.
[0084] Furthermore, in conjunction with the image generation methods described in the above embodiments, this application embodiment can provide a computer storage medium for implementation. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the image generation methods described in the above embodiments.
[0085] This application also provides a computer program product, including a computer program, which, when executed, implements any of the image generation methods described in the above embodiments.
[0086] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0087] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memory (ROM), flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0088] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0089] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0090] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. An image generation method characterized by, The method includes: Input multiple test images into the image recognition model; During the image recognition process of the image recognition model for any of the test images, the state of each neuron and the current image recognition result are obtained, and the state includes an active state and an inactive state. For any of the neurons, in response to the occurrence of the activation state and the current image recognition result being correct, it is determined that any of the neurons is in a first state; in response to the occurrence of the activation state and the current image recognition result being incorrect, it is determined that any of the neurons is in a second state; in response to the occurrence of the deactivation state and the current image recognition result being correct, it is determined that any of the neurons is in a third state; in response to the occurrence of the deactivation state and the current image recognition result being incorrect, it is determined that any of the neurons is in a fourth state. The distribution of the number of times any neuron appears in the first state, the second state, the third state, and the fourth state is determined as the state distribution data of any neuron. The state distribution data is used to indicate the number of times the neuron appears in the active state and the inactive state when the image recognition result is correct and incorrect. Based on the state distribution data of each neuron, a suspicious score is determined for each neuron, and the suspicious score is used to indicate the degree of abnormality in the neuron's data output; Neurons whose suspicious scores meet preset conditions are identified as suspicious neurons. Suspicious neurons are neurons that output abnormal data during the image recognition process of the image recognition model. A reference image is input into the image recognition model, wherein the reference image is an image that has been correctly recognized by the image recognition model. During the image recognition process of the image recognition model on the reference image, the activation values of each of the suspicious neurons are obtained; Obtain the gradient between the activation value of each of the suspected neurons and the reference image; The average gradient of the gradients corresponding to the plurality of suspicious neurons is obtained as the average gradient, which is used to indicate the degree of change between the activation value and the reference image; The image data of the reference image is updated based on the average gradient to generate a new image.
2. The method of claim 1, wherein, The preset conditions include the top K neurons with the highest suspicious scores, where K is a positive integer and K>1.
3. The method of claim 1, wherein, After inputting multiple test images into the image recognition model, the method further includes: During the image recognition process of the image recognition model on the multiple test images, the test image that is correctly recognized by the image recognition model is determined as the reference image.
4. The method of claim 1, wherein, The step of updating the image data of the reference image based on the average gradient to generate a new image includes: Based on reference constraints, the average gradient is subjected to gradient ascent processing, whereby the reference constraints are used to limit the range of variation of the average gradient. Based on the average gradient after gradient ascent processing, the image data of the reference image is updated to generate the new image.
5. The method of claim 1, wherein, After updating the image data of the reference image based on the average gradient to generate a new image, the method further includes: The new image is input into the image recognition model; In response to the image recognition model correctly recognizing the new image, the new image is determined to be invalid; In response to the image recognition model's error in recognizing the new image, the new image is determined to be valid.
6. An image generation apparatus characterized by comprising: The apparatus for performing the method as claimed in claim 1 includes: The determination module is used to identify multiple suspicious neurons in the neurons of the image recognition model. The suspicious neurons are neurons that have abnormal data output during the image recognition process of the image recognition model. The input module is used to input a reference image into the image recognition model, wherein the reference image is an image that has been correctly recognized by the image recognition model; The acquisition module is used to acquire the average gradient between the activation values of the plurality of suspicious neurons and the reference image during the image recognition process of the image recognition model performing image recognition on the reference image. The average gradient is used to indicate the degree of change between the activation values and the reference image. The generation module is used to update the image data of the reference image based on the average gradient and generate a new image.
7. A computer device, comprising: The device includes: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the image generation method as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the image generation method as described in any one of claims 1-5.
9. A computer program product, characterised in that, Includes a computer program, which, when executed, implements the image generation method as described in any one of claims 1-5.
Citation Information
Patent Citations
Method and system for predicting generalization error of image recognition model based on non-check set
CN112598082A