Model vulnerability test method based on input disturbance
By setting up a test set of adversarial sample data with inconsistent perturbation levels, the model is tested and trained, which solves the problem that existing technologies cannot accurately test the vulnerability of the model and improves the stability and reliability of the model.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA SOUTHERN POWER GRID ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD
- Filing Date
- 2025-12-03
- Publication Date
- 2026-04-17
AI Technical Summary
Existing technologies cannot accurately test the vulnerability of models, resulting in poor model stability and reliability.
The model is tested by setting up a test set consisting of adversarial sample data with varying degrees of perturbation. Perturbation output data is collected and detected, and the vulnerability level is marked as not meeting the threshold. The model is then trained based on the threshold.
It enables precise testing of model vulnerability, improves model stability and reliability, and provides data and information security assurance.
Smart Images

Figure CN121880171A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of testing model vulnerability, and more particularly to a model vulnerability testing method based on input perturbation. Background Technology
[0002] With the development of technology, various models are being used more and more widely. However, these models often suffer from vulnerability. When perturbation adversarial sample data is input into a model, the more vulnerable the model, the more sensitive it is to the input perturbation adversarial sample data. The frequency of the model outputting erroneous data or the probability of misjudgment tends to be higher. Even a small amount of input perturbation adversarial sample data can lead to huge errors in the model's output data. This makes the model highly susceptible to the influence of input perturbation data, resulting in high vulnerability, poor stability, and poor reliability. In existing technologies, since the perturbation level of the input perturbation adversarial sample data is basically fixed, it is often impossible to accurately test the vulnerability level of the model and find corresponding methods to reduce the vulnerability level. Therefore, it is difficult to improve the problem of poor model stability and reliability. Thus, there is an urgent need for a technical solution that can accurately test the vulnerability level of a model to improve the above problems. Summary of the Invention
[0003] This application provides a model vulnerability testing method based on input perturbation, which aims to improve the related technical problems in the prior art.
[0004] An embodiment of this application provides a model vulnerability testing method based on input perturbation, which may include the following steps: According to the test objective, a perturbation adversarial sample data test set is set up, which consists of perturbation adversarial sample data with different perturbation levels, and the perturbation adversarial sample data in the perturbation adversarial sample data test set is sequentially input into the model to be tested; Collect the perturbation output data output by the model, which corresponds to the magnitude of the perturbation in the perturbation adversarial sample data, to form a perturbation output data test set; The system detects whether there is erroneous data in the perturbation output data test set. If there is no erroneous data in the perturbation output data test set, it issues a test message indicating that the model's vulnerability meets the standard. If there is erroneous data in the perturbation output data test set, it issues a test message indicating that the model's vulnerability does not meet the standard. At the same time, the minimum value among the perturbation degree of all the perturbation adversarial sample data corresponding to the erroneous data is marked as the threshold for the model's vulnerability not meeting the standard. The model is trained based on the vulnerability threshold of the model and the test objective.
[0005] In the above technical solution, by using adversarial sample data with varying degrees of perturbation to test the model, the vulnerability of the model can be accurately tested, effectively improving the stability and reliability of the model.
[0006] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: When the vulnerability level of the model is below the threshold, which is higher than the preset threshold, the model is trained according to the vulnerability level below the threshold and the test objective.
[0007] In the above technical solution, the larger the vulnerability threshold of the model, the larger the value of the perturbation of the perturbation adversarial sample data. This means that the model is less sensitive to the perturbation adversarial sample data with a larger value of perturbation. The model has higher stability and reliability. Therefore, the model is more likely to achieve the test target after training. Selecting this model for training can effectively improve the training efficiency of the vulnerability threshold model.
[0008] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: When the vulnerability level of the model is below the preset threshold, the model fails the test and is marked as the target model to be tested next.
[0009] In the above technical solution, the perturbation adversarial sample data input to the model often differs depending on the test target. Therefore, the model vulnerability test results obtained by the same model may also differ when faced with different input perturbation adversarial sample data. Thus, if the model fails the vulnerability test for the current test target, it does not mean that the model will necessarily fail the vulnerability test results for other test targets in the next test. Marking the model as the next test target model facilitates vulnerability testing of the model according to the next test target.
[0010] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: The perturbation adversarial sample data from the perturbation adversarial sample data test set are input into the model to be tested in ascending order of perturbation level at least twice, and the consistency of the test information issued by the model is checked each time. If the test information issued by the model is inconsistent each time, an inaccurate test information is issued, and the vulnerability of the model is tested again. The above technical solutions can be used to conduct further precise testing on the vulnerability of the model.
[0011] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: The adversarial sample data without perturbation is input into the model to obtain the normal output data of the model. The perturbation output data test set is then checked to see if there is a difference between the perturbation output data test set and the normal output data of the model. If there is a difference, it means that there is erroneous data in the perturbation output data test set.
[0012] The above technical solution can be used to conveniently and quickly detect erroneous data in the test set of disturbed output data.
[0013] In a preferred example, the solution of the first aspect of this application can be further configured as follows: In the step of inputting adversarial example data without perturbation into the model to obtain the model's normal output data, and detecting whether there is a difference between the perturbation output data in the perturbation output data test set and the model's normal output data, and if a difference exists, indicating that there is erroneous data in the perturbation output data test set, the method for detecting whether there is a difference between the perturbation output data in the perturbation output data test set and the model's normal output data includes the following expression: , In the formula, This represents a preset constant. Indicates the input number After the first perturbation adversarial sample data, the model outputs the first... One perturbation output data, Indicates the first Each perturbation output data weight, It is a positive integer. , This indicates the total number of perturbation output data points in the perturbation output data test set. Indicates the input number After removing the perturbation data from the adversarial sample data without adding perturbation, the model outputs the first perturbation data. Normal output data, Indicates the first Weights of normal output data This represents the sine function.
[0014] If the above formula is satisfied, it indicates that a difference exists between the perturbation output data in the perturbation output data test set and the normal output data of the model.
[0015] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: The model that meets the vulnerability standard is put into use, and the model is checked for any abnormal output data. When abnormal output data is detected, perturbation adversarial sample data with inconsistent perturbation levels is added to the perturbation adversarial sample data test set according to the test objective, forming a supplementary perturbation adversarial sample data test set. The perturbation adversarial sample data in the supplementary perturbation adversarial sample data test set is used to test the vulnerability of the model.
[0016] The above technical solutions enable more accurate testing of the vulnerability level of a model.
[0017] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: The test target and the perturbation adversarial sample data test set set according to the test target are saved. When the same test target appears again, the saved perturbation adversarial sample data test set set according to the test target is extracted to test the vulnerability of the model.
[0018] In the above technical solution, when the same test target appears again, the saved perturbation adversarial sample data test set can be directly extracted to test the vulnerability of the model, without having to repeatedly set up the perturbation adversarial sample data test set for the same test target, thus improving the testing efficiency of vulnerability testing of the model.
[0019] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: The stored perturbation and countermeasure sample data test set, configured according to the test target, is updated using the supplementary perturbation and countermeasure sample data test set of the test target.
[0020] In the above technical solution, the test set of perturbation adversarial sample data is updated, which enables a more accurate test of the vulnerability of the model.
[0021] In a preferred example, the solution of the first aspect of this application can be further configured as follows: The aforementioned model vulnerability testing method based on input perturbation may further include the following steps: The perturbation adversarial sample data in the perturbation adversarial sample data test set are input into the model to be tested in ascending order of perturbation degree. The perturbation degree value corresponding to the perturbation adversarial sample data of the data where the model's output data begins to show errors is marked as the threshold of the model's vulnerability degree.
[0022] In the above technical solution, the vulnerability level of the model that does not meet the threshold can be directly marked, thereby speeding up the process of obtaining the vulnerability level threshold of the model.
[0023] Based on the above method embodiments, this application provides a corresponding terminal embodiment; This application provides a terminal, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a model vulnerability testing method based on input perturbation as described in any embodiment of this application.
[0024] Based on the above method embodiments, this application provides a corresponding storage medium embodiment; This application provides a storage medium including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a model vulnerability testing method based on input perturbation as described in any embodiment of this application.
[0025] This application has at least the following beneficial effects: This application provides a model vulnerability testing method based on input perturbation. By using perturbation adversarial sample data with varying degrees of input perturbation, the vulnerability of the model is tested. This method can accurately test the vulnerability level of the model and find corresponding methods to reduce the vulnerability level. It also helps to take corresponding defensive measures based on the vulnerability level of the model, thereby effectively improving the stability and reliability of the model and providing strong protection for the data and information security of users. Attached Figure Description
[0026] Figure 1 This is a flowchart of a model vulnerability testing method based on input perturbation according to an embodiment of this application.
[0027] Figure 2 This is a block diagram of a model vulnerability testing system based on input perturbation, according to an embodiment of this application. Detailed Implementation
[0028] The technical solutions of this application will now be clearly, completely, and comprehensively described with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0029] like Figure 1 As shown in the figure, an embodiment of this application provides a model vulnerability testing method based on input perturbation, which may specifically include the following steps: Step S1: According to the test objective, set up a perturbation adversarial sample data test set consisting of perturbation adversarial sample data with inconsistent perturbation levels, and input the perturbation adversarial sample data in the perturbation adversarial sample data test set into the model to be tested in sequence; Step S2: Collect the perturbation output data output by the model that corresponds to the perturbation level of the perturbation adversarial sample data, and form a perturbation output data test set; Step S3: Detect whether there is erroneous data in the perturbation output data test set. If there is no erroneous data in the perturbation output data test set, issue test information indicating that the vulnerability of the model meets the standard. If there is erroneous data in the perturbation output data test set, issue test information indicating that the vulnerability of the model does not meet the standard. At the same time, mark the minimum value of the perturbation degree of all the perturbation adversarial sample data corresponding to the erroneous data as the threshold value for the vulnerability degree of the model not meeting the standard. Step S4: Train the model according to the vulnerability threshold of the model and the test target.
[0030] In the above embodiments, by using adversarial sample data with varying degrees of perturbation to test the model, the vulnerability of the model can be accurately tested, effectively improving the stability and reliability of the model.
[0031] In a preferred embodiment, the larger the vulnerability threshold of the model and the larger the perturbation magnitude of the adversarial sample data, the less sensitive the model is to the perturbation magnitude of the input adversarial sample data. This indicates higher stability and reliability of the model, making it easier for the model to achieve the testing objective after training. Selecting this model for training can effectively improve the training efficiency of models with vulnerability thresholds. Specifically, the aforementioned model vulnerability testing method based on input perturbation may further include the following steps: When the vulnerability level of the model is below the threshold, which is higher than the preset threshold, the model is trained according to the vulnerability level below the threshold and the test objective.
[0032] In a preferred embodiment, the perturbation adversarial sample data input to the model often differs depending on the test target. Therefore, the model vulnerability test results obtained by the same model may also differ when facing different perturbation adversarial sample data. Thus, the model failing the vulnerability test for the current test target does not necessarily mean that the model will fail the vulnerability test for other test targets in the future. Marking the model as the next test target model facilitates vulnerability testing of the model according to the next test target. Specifically, the model vulnerability testing method based on input perturbation may further include the following steps: When the vulnerability level of the model is below the preset threshold, the model fails the test and is marked as the target model to be tested next.
[0033] In a preferred embodiment, to further refine the testing of the model's vulnerability level, the model vulnerability testing method based on input perturbation may further include the following steps: The perturbation adversarial sample data from the perturbation adversarial sample data test set are input into the model to be tested in ascending order of perturbation level at least twice, and the consistency of the test information issued by the model is checked each time. If the test information issued by the model is inconsistent each time, an inaccurate test information is issued, and the vulnerability of the model is tested again.
[0034] In a preferred embodiment, in order to conveniently and quickly detect erroneous data in the perturbation output data test set, the model vulnerability testing method based on input perturbation may further include the following steps: The adversarial sample data without perturbation is input into the model to obtain the normal output data of the model. The perturbation output data test set is then checked to see if there is a difference between the perturbation output data test set and the normal output data of the model. If there is a difference, it means that there is erroneous data in the perturbation output data test set.
[0035] In a preferred embodiment, if the following formula is satisfied, it indicates that a difference exists between the perturbation output data in the perturbation output data test set and the normal output data of the model. Specifically, in the step of inputting adversarial sample data without added perturbation data into the model to obtain the normal output data of the model, detecting whether there is a difference between the perturbation output data in the perturbation output data test set and the normal output data of the model, and if a difference exists, indicating that there is erroneous data in the perturbation output data test set, the method for detecting whether there is a difference between the perturbation output data in the perturbation output data test set and the normal output data of the model includes the following expression: , In the formula, This represents a preset constant. Indicates the input number After the first perturbation adversarial sample data, the model outputs the first... One perturbation output data, Indicates the first Each perturbation output data weight, It is a positive integer. , This indicates the total number of perturbation output data points in the perturbation output data test set. Indicates the input number After removing the perturbation data from the adversarial sample data without adding perturbation, the model outputs the first perturbation data. Normal output data, Indicates the first Weights of normal output data This represents the sine function.
[0036] In a preferred embodiment, in order to more accurately test the magnitude of model vulnerability, the model vulnerability testing method based on input perturbation may further include the following steps: The model that meets the vulnerability standard is put into use, and the model is checked for any abnormal output data. When abnormal output data is detected, perturbation adversarial sample data with inconsistent perturbation levels is added to the perturbation adversarial sample data test set according to the test objective, forming a supplementary perturbation adversarial sample data test set. The perturbation adversarial sample data in the supplementary perturbation adversarial sample data test set is used to test the vulnerability of the model.
[0037] In a preferred embodiment, in order to directly extract the saved perturbation adversarial sample data test set to test the vulnerability of the model when the same test target appears again, without having to repeatedly set up the perturbation adversarial sample data test set for the same test target, thus improving the testing efficiency of the model vulnerability test, the aforementioned model vulnerability testing method based on input perturbation may further include the following steps: The test target and the perturbation adversarial sample data test set set according to the test target are saved. When the same test target appears again, the saved perturbation adversarial sample data test set set according to the test target is extracted to test the vulnerability of the model.
[0038] In a preferred embodiment, in order to update the perturbation adversarial sample data test set and achieve further accurate testing of the model's vulnerability, the model vulnerability testing method based on input perturbation may further include the following steps: The stored perturbation and countermeasure sample data test set, configured according to the test target, is updated using the supplementary perturbation and countermeasure sample data test set of the test target.
[0039] In a preferred embodiment, in order to directly identify the vulnerability level of the model that does not meet the threshold, thereby accelerating the process of obtaining the vulnerability level threshold, the model vulnerability testing method based on input perturbation may further include the following steps: The perturbation adversarial sample data in the perturbation adversarial sample data test set are input into the model to be tested in ascending order of perturbation degree. The perturbation degree value corresponding to the perturbation adversarial sample data of the data where the model's output data begins to show errors is marked as the threshold of the model's vulnerability degree.
[0040] One embodiment of this application provides a model vulnerability testing system based on input perturbation, such as... Figure 2 As shown, it can specifically include: The perturbation adversarial sample data test set setting module is used to set up a perturbation adversarial sample data test set consisting of perturbation adversarial sample data with inconsistent perturbation levels according to the test target, and to input the perturbation adversarial sample data in the perturbation adversarial sample data test set into the model to be tested in sequence; The perturbation output data test set formation module is used to collect the perturbation output data output by the model that corresponds to the perturbation degree of the perturbation adversarial sample data, and form a perturbation output data test set; The detection module is used to detect whether there is erroneous data in the perturbation output data test set. If there is no erroneous data in the perturbation output data test set, it issues test information indicating that the vulnerability of the model meets the standard. If there is erroneous data in the perturbation output data test set, it issues test information indicating that the vulnerability of the model does not meet the standard. At the same time, the minimum value of the perturbation degree of all the perturbation adversarial sample data corresponding to the erroneous data is marked as the threshold value for the vulnerability degree of the model not meeting the standard. The training module is used to train the model based on the vulnerability level of the model failing to meet the threshold and the test objective.
[0041] It should be noted that the system embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the system embodiment drawings provided in this application, the connection relationships between modules indicate that they have communication connections, which can be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without creative effort. The above schematic diagrams are merely examples of a model vulnerability testing system based on input perturbation and do not constitute a limitation on a model vulnerability testing system based on input perturbation. It may include more or fewer components than illustrated, or combine certain components, or use different components.
[0042] Based on the above method embodiments, this application provides corresponding terminal embodiments.
[0043] Another embodiment of this application provides a terminal, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a model vulnerability testing method based on input perturbation as described in any embodiment of this application.
[0044] For example, in this embodiment, the computer program can be divided into one or more modules, which are stored in the memory and executed by the processor to complete the present application. The one or more modules may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the device. The aforementioned terminals can be computing devices such as desktop computers, laptops, handheld computers, and cloud servers. These devices may include, but are not limited to, processors and memory.
[0045] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. This processor is the control center of the device, connecting various parts of the device via various interfaces and lines.
[0046] The aforementioned memory can be used to store the aforementioned computer programs and / or modules. The aforementioned processor implements various functions of the aforementioned device by running or executing the computer programs and / or modules stored in the aforementioned memory, and by calling data stored in the memory. The aforementioned memory may mainly include a program storage area and a data storage area, wherein the program storage area may store the operating system, at least one application program required for a function, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0047] Based on the above method embodiments, this application provides corresponding storage medium embodiments.
[0048] Another embodiment of this application provides a storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the storage medium is located to execute a model vulnerability testing method based on input perturbation as described in any embodiment of this application.
[0049] In this embodiment, the storage medium is a computer-readable storage medium, and the computer program includes computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0050] In the embodiments described above in this application, the enterprise's internal and external networks are integrated, enabling internal staff participating in the enterprise's internal network project to access external network information related to the project simply by logging into the enterprise's internal network. This allows for very convenient access to relevant information about the enterprise's internal network project. By setting up external network access accounts for internal staff participating in the project to access the project-related external network information, and by setting different external network access permissions for different external network access accounts, internal staff participating in the enterprise's internal network project can conveniently and accurately obtain relevant external network information about the project they are participating in.
[0051] The above are preferred embodiments of this application. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principles of this application, and these improvements and modifications are also considered to be within the scope of protection of this application.
Claims
1. A model vulnerability testing method based on input perturbation, characterized in that, Includes the following steps: According to the test objective, a perturbation adversarial sample data test set is set up, which consists of perturbation adversarial sample data with different perturbation levels, and the perturbation adversarial sample data in the perturbation adversarial sample data test set is sequentially input into the model to be tested; Collect the perturbation output data output by the model, which corresponds to the magnitude of the perturbation in the perturbation adversarial sample data, to form a perturbation output data test set; The system detects whether there is erroneous data in the perturbation output data test set. If there is no erroneous data in the perturbation output data test set, it issues a test message indicating that the model's vulnerability meets the standard. If there is erroneous data in the perturbation output data test set, it issues a test message indicating that the model's vulnerability does not meet the standard. At the same time, the minimum value among the perturbation degree of all the perturbation adversarial sample data corresponding to the erroneous data is marked as the threshold for the model's vulnerability not meeting the standard. The model is trained based on the vulnerability threshold of the model and the test objective.
2. The model vulnerability testing method based on input perturbation according to claim 1, characterized in that, It also includes the following steps: When the vulnerability level of the model is below the threshold, which is higher than the preset threshold, the model is trained according to the vulnerability level below the threshold and the test objective.
3. The model vulnerability testing method based on input perturbation according to claim 1, characterized in that, It also includes the following steps: When the vulnerability level of the model is below the preset threshold, the model fails the test and is marked as the target model to be tested next.
4. The model vulnerability testing method based on input perturbation according to claim 1, characterized in that, It also includes the following steps: The perturbation adversarial sample data from the perturbation adversarial sample data test set are input into the model to be tested in ascending order of perturbation level at least twice, and the consistency of the test information issued by the model is checked each time. If the test information issued by the model is inconsistent each time, an inaccurate test information is issued, and the vulnerability of the model is tested again.
5. The model vulnerability testing method based on input perturbation according to claim 1, characterized in that, It also includes the following steps: The adversarial sample data without perturbation is input into the model to obtain the normal output data of the model. The perturbation output data test set is then checked to see if there is a difference between the perturbation output data test set and the normal output data of the model. If there is a difference, it means that there is erroneous data in the perturbation output data test set.
6. The model vulnerability testing method based on input perturbation according to claim 5, characterized in that, In the step of inputting adversarial example data without perturbation into the model to obtain the model's normal output data, and detecting whether there is a difference between the perturbation output data in the perturbation output data test set and the model's normal output data, and if a difference exists, indicating that there is erroneous data in the perturbation output data test set, the method for detecting whether there is a difference between the perturbation output data in the perturbation output data test set and the model's normal output data includes the following expression: , In the formula, This represents a preset constant. Indicates the input number After the first perturbation adversarial sample data, the model outputs the first... One perturbation output data, Indicates the first Each perturbation output data weight, It is a positive integer. , This indicates the total number of perturbation output data points in the perturbation output data test set. Indicates the input number After removing the perturbation data from the adversarial sample data without adding perturbation, the model outputs the first perturbation data. Normal output data, Indicates the first Weights of normal output data.
7. The model vulnerability testing method based on input perturbation according to claim 1, characterized in that, It also includes the following steps: The model that meets the vulnerability standard is put into use, and the model is checked for any abnormal output data. When abnormal output data is detected, perturbation adversarial sample data with inconsistent perturbation levels is added to the perturbation adversarial sample data test set according to the test objective, forming a supplementary perturbation adversarial sample data test set. The perturbation adversarial sample data in the supplementary perturbation adversarial sample data test set is used to test the vulnerability of the model.
8. The model vulnerability testing method based on input perturbation according to claim 7, characterized in that, It also includes the following steps: The test target and the perturbation adversarial sample data test set set according to the test target are saved. When the same test target appears again, the saved perturbation adversarial sample data test set set according to the test target is extracted to test the vulnerability of the model.
9. The model vulnerability testing method based on input perturbation according to claim 8, characterized in that, It also includes the following steps: The stored perturbation and countermeasure sample data test set, configured according to the test target, is updated using the supplementary perturbation and countermeasure sample data test set of the test target.
10. The model vulnerability testing method based on input perturbation according to claim 1, characterized in that, It also includes the following steps: The perturbation adversarial sample data in the perturbation adversarial sample data test set are input into the model to be tested in ascending order of perturbation degree. The perturbation degree value corresponding to the perturbation adversarial sample data at which the model's output data begins to show errors is marked as the threshold of the model's vulnerability degree.