An adversarial sample generation method based on frequency domain fusion and multi-scale input

CN122676280APending Publication Date: 2026-09-01YANSHAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610765315.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-09-01

AI Technical Summary

Technical Problem

[0005]针对现有技术的不足,本发明提供了一种基于频域融合与多尺度输入的对抗样本生成方法,用于解决现有技术存在的未有效利用图像频域信息与模型空间不变性、对抗样本可迁移性不足的技术问题

Benefits of technology

本发明通过频域高频分量融合与多尺度数据增强,结合动量项累积梯度更新,可有效利用图像频域信息与模型空间不变性,提升梯度更新的鲁棒性与扰动的泛化适配能力,使生成的对抗样本在不同输入场景下具备更强的干扰一致性,有助于增强其对不同分类模型的适配效果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122676280A_ABST
    Figure CN122676280A_ABST
Patent Text Reader

Abstract

This invention discloses an adversarial example generation method based on frequency domain fusion and multi-scale input, relating to the fields of computer vision and artificial intelligence. The method includes initializing a momentum term; extracting low-frequency and high-frequency components from input samples and randomly sampled samples respectively; fusing the high-frequency components of the input samples and the random samples to obtain a frequency domain fused sample; dividing the frequency domain fused sample into multiple local blocks; and scaling the frequency domain fused sample to the size of the local blocks to obtain block-level global features. This invention, through frequency domain high-frequency component fusion and multi-scale data augmentation, combined with momentum term cumulative gradient updates, can effectively utilize image frequency domain information and model space invariance to improve the robustness of gradient updates and the generalization adaptability of perturbations. This enables the generated adversarial examples to have stronger interference consistency under different input scenarios, helping to enhance their adaptability to different classification models.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of computer vision and artificial intelligence, and in particular to an adversarial example generation method based on frequency domain fusion and multi-scale input. Background Technology

[0002] Deep neural networks (DNNs), with their superior feature extraction and nonlinear modeling capabilities, have made groundbreaking progress in computer vision tasks such as image classification and object detection, and are increasingly being applied to scenarios with high system reliability requirements, such as autonomous driving and medical image analysis. During model deployment and actual operation, adversarial examples generated by adding small perturbations to normal samples can induce deep neural networks to output highly confident but erroneous predictions, thus posing a potential risk to the stable operation of related systems. This behavior of generating adversarial examples and using them to mislead the model is called an adversarial attack. Research on adversarial attacks and adversarial example generation has become an important direction in the field of artificial intelligence security, possessing high practical application demand and research value.

[0003] Existing adversarial attack methods can be categorized into white-box attacks and black-box attacks based on the attacker's access rights to the target model. Transfer attacks are a common attack strategy in black-box scenarios. This strategy generates adversarial examples from a source model with a known structure, enabling the adversarial examples to attack black-box models with unknown structures. The ability of adversarial examples to attack different models is called transferability, which is a core indicator for evaluating the actual threat level of adversarial attacks. Mainstream methods to improve the transferability of adversarial examples include gradient optimization and input transformation. Input transformation methods process the input image before calculating the gradient, using diverse image transformations to obtain richer gradient information, thereby improving the transferability of adversarial examples. Existing input transformation methods mostly rely on spatial domain operations to complete image adjustments.

[0004] Existing input transformation-based adversarial example generation methods only perform single-position transformation processing on the input image in the spatial domain, without fully incorporating the image's frequency domain information for perturbation design. Furthermore, their transformation operations do not adapt to the spatial invariance characteristics of deep neural networks, making it difficult to generate diverse perturbation forms. This limits the transferability of adversarial examples across different models and fails to consistently improve the attack success rate and cross-model transferability of adversarial examples. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides an adversarial example generation method based on frequency domain fusion and multi-scale input, which solves the technical problems of ineffective utilization of image frequency domain information and model space invariance, and insufficient transferability of adversarial examples in existing technologies.

[0006] The technical means employed in this invention are as follows: In a first aspect, embodiments of the present invention provide a method for generating adversarial examples based on frequency domain fusion and multi-scale input, including: Initialize the momentum term; The low-frequency and high-frequency components of the input sample and the random sample are extracted respectively. The high-frequency components of the input sample and the high-frequency components of the random sample are fused to obtain the frequency domain fused sample. The frequency domain fusion sample is divided into multiple local blocks, and the frequency domain fusion sample is scaled to the size of the local block to obtain block-level global features. For each local block, the local block and the block-level global features are linearly fused at a random ratio with a preset probability to obtain a linearly fused sample. The linearly fused sample is then randomly scaled and restored to the size of the frequency domain fusion sample through reflection filling to obtain a data augmentation sample. The process of obtaining data augmentation samples is performed multiple times on the adversarial sample of the current iteration to construct a set of data augmentation samples. Based on the loss gradient of each data augmentation sample in the set of data augmentation samples and the current adversarial sample, the comprehensive gradient direction is obtained. The momentum term is updated based on the comprehensive gradient direction, and the adversarial sample is updated through the sign function to obtain the updated adversarial sample. The perturbation amplitude of the updated adversarial sample is limited through the pruning function to obtain the target adversarial sample.

[0007] Further, the step of extracting the low-frequency and high-frequency components of the input sample and the random sample respectively, and fusing the high-frequency components of the input sample and the random sample to obtain a frequency domain fused sample includes: Perform a two-dimensional discrete Fourier transform on the input sample and the randomly sampled sample to obtain the frequency domain features of the input sample and the frequency domain features of the randomly sampled sample; A circular mask filter is used to separate the low-frequency and high-frequency components of the frequency domain features of the input samples and the frequency domain features of the randomly sampled samples; The high-frequency components of the frequency domain features of the input sample are weighted and fused with the high-frequency components of the frequency domain features of the randomly sampled sample to obtain the fused frequency domain features. The fused frequency domain features are converted into the spatial domain by inverse two-dimensional discrete Fourier transform to obtain frequency domain fused samples.

[0008] Furthermore, the circular mask filter is defined as follows:

[0009] in, The center coordinates of the spectrum The radius is the mask radius.

[0010] Furthermore, the calculation formula for weighted fusion of the high-frequency components of the input sample frequency domain features and the high-frequency components of the random sample frequency domain features is as follows:

[0011] in, To fuse frequency domain features, The low-frequency components of the frequency domain features of the input sample. For the high-frequency components of the frequency domain features of the input sample, For high-frequency fusion weighting coefficients, It represents the high-frequency components of the frequency domain characteristics of randomly sampled samples.

[0012] Further, the step of dividing the frequency domain fusion sample into multiple local blocks, scaling the frequency domain fusion sample to the size of the local block to obtain block-level global features, and for each local block, linearly fusing the local block and the block-level global features at a random ratio with a preset probability to obtain a linearly fused sample, performing random scaling on the linearly fused sample, and restoring it to the size of the frequency domain fusion sample through reflection filling to obtain a data augmentation sample, includes: The frequency domain fusion sample is divided into multiple local blocks; By scaling the frequency domain fused samples to the local block size using bilinear interpolation, block-level global features are obtained. For each local block, the replacement probability is compared with a random number. If the random number is less than the replacement probability, the local block is linearly fused with the block-level global feature based on the linear fusion weight. If the random number is not less than the replacement probability, the content of the local block is retained to obtain a linearly fused sample. Scaling factors are sampled from a uniform distribution, and the linear fusion sample is randomly scaled to obtain a scaled linear fusion sample. The scaled linear fusion sample is then embedded into a random position in the original space, and the size of the frequency domain fusion sample is restored by reflection filling to obtain a data augmentation sample.

[0013] Furthermore, the calculation formula for linearly fusing the local block with the block-level global feature is as follows:

[0014] in, For the fused local block features, For linear fusion weighting coefficients, For block-level global features, These are the original local block features.

[0015] Furthermore, the step of performing multiple data augmentation sample operations on the adversarial sample of the current iteration to construct a data augmentation sample set, and obtaining the comprehensive gradient direction based on the loss gradient of each data augmentation sample in the data augmentation sample set and the current adversarial sample, includes: The process of obtaining data augmentation samples is performed multiple times on the adversarial sample of the current iteration, resulting in multiple data augmentation samples. The multiple data augmentation samples are then combined into a data augmentation sample set. For the target data augmentation sample in the data augmentation sample set, the cross-entropy loss function is calculated with the real label as the supervision information. The cross-entropy loss function is differentiated with the current adversarial sample as the variable to obtain the loss gradient corresponding to the target data augmentation sample. The average loss gradient corresponding to multiple data augmentation samples in the data augmentation sample set is calculated to obtain the comprehensive gradient direction.

[0016] Furthermore, the formula for calculating the loss gradient is:

[0017] in, The loss gradient calculated in step i is... For gradient operators, This is the current adversarial sample after the (t-1)th iteration. Let cross-entropy be the loss function. The source model for generating adversarial examples, Augment the target data sample for step i. The true labels for the input samples.

[0018] Furthermore, the formula for calculating the comprehensive gradient direction is:

[0019] in, The gradient direction is defined by N, which represents the total number of data augmentation samples in the data augmentation sample set. The loss gradient is calculated in step i.

[0020] Secondly, embodiments of the present invention also provide an adversarial example generation device based on frequency domain fusion and multi-scale input, comprising: The initialization module is used to initialize the momentum term; The frequency domain fusion module is used to extract the low-frequency and high-frequency components of the input sample and the random sample, respectively, and to fuse the high-frequency components of the input sample and the high-frequency components of the random sample to obtain the frequency domain fused sample. A multi-scale data augmentation module is used to divide the frequency domain fusion sample into multiple local blocks, scale the frequency domain fusion sample to the size of the local block to obtain block-level global features, linearly fuse the local block and the block-level global features at a random ratio with a preset probability to obtain a linearly fused sample, randomly scale the linearly fused sample, and restore it to the size of the frequency domain fusion sample through reflection filling to obtain a data augmented sample. The integrated gradient calculation module is used to perform multiple steps to obtain data augmentation samples on the adversarial sample of the current iteration to construct a set of data augmentation samples. Based on the loss gradient of each data augmentation sample in the set of data augmentation samples and the current adversarial sample, the integrated gradient direction is obtained. The adversarial example update module is used to update the momentum term based on the comprehensive gradient direction, update the adversarial example through a sign function to obtain the updated adversarial example, and limit the perturbation amplitude of the updated adversarial example through a pruning function to obtain the target adversarial example.

[0021] Compared with the prior art, the present invention has the following advantages: This invention utilizes frequency domain high-frequency component fusion and multi-scale data enhancement, combined with momentum term cumulative gradient updates, to effectively leverage image frequency domain information and model space invariance. This enhances the robustness of gradient updates and the generalization and adaptation capabilities of perturbations, enabling the generated adversarial examples to exhibit stronger interference consistency under different input scenarios. This helps to improve their adaptation to different classification models.

[0022] Based on the above reasons, this invention can be widely applied in fields such as computer vision and artificial intelligence. Attached Figure Description

[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1 This is a flowchart illustrating an adversarial example generation method based on frequency domain fusion and multi-scale input according to the present invention. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0026] It should be noted that the terms "comprising" and "having" and any variations thereof in this invention are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or device.

[0027] The embodiments of the present invention will now be described with reference to the accompanying drawings.

[0028] Please see Figure 1 , Figure 1 This is a flowchart illustrating an adversarial example generation method based on frequency domain fusion and multi-scale input according to the present invention.

[0029] This invention provides a method for generating adversarial examples based on frequency domain fusion and multi-scale input, comprising the following steps: Step 101: Initialize the momentum term.

[0030] Given an input sample x, its corresponding true label y, and a randomly selected sample x' from the same dataset; set up a classification model. Configure the disturbance constraint range. Number of iterations T, step size of a single iteration The number of transformations N is input to control the magnitude of a single perturbation update within a preset range, preventing the step size from exceeding the perturbation constraint range; the momentum term is initialized. This ensures that the initial state of gradient updates is not disturbed by historical gradients, guaranteeing the controllability of the iteration process; and allows the initial adversarial examples to be... By setting the initial adversarial sample as the input sample itself, a unified starting point can be provided for gradient iteration, allowing the perturbation update process to proceed step by step along a preset path, thereby generating adversarial samples that conform to perturbation constraints.

[0031] Step 102: Extract the low-frequency and high-frequency components of the input sample and the randomly sampled sample respectively. Then, fuse the high-frequency components of the input sample and the randomly sampled sample to obtain a frequency-domain fused sample. By extracting the low-frequency and high-frequency components of the input sample and the randomly sampled sample respectively, and fusing the high-frequency components of both, the main features carried by the low-frequency components of the input sample can be preserved while introducing perturbation information from the high-frequency components of other samples. This enriches the frequency-domain feature distribution of the input sample, improves the adversarial performance of the generated frequency-domain fused sample in the classification model, and helps to enhance the concealment and attack effectiveness of adversarial perturbations.

[0032] In some embodiments, the low-frequency components and high-frequency components of the input sample and the random sample are extracted respectively, and the high-frequency components of the input sample and the random sample are fused to obtain a frequency domain fused sample, including the following steps: Step 1021: Perform a two-dimensional discrete Fourier transform on the input sample and the random sample to obtain the frequency domain features of the input sample and the frequency domain features of the random sample.

[0033] Specifically, the frequency domain features F(x) of the input sample are obtained by performing a two-dimensional discrete Fourier transform on the input sample x and the randomly sampled sample x'. This completes the mapping from the spatial domain to the frequency domain. By performing a two-dimensional discrete Fourier transform on the input samples and random samples, the sample data in the spatial domain can be mapped to the frequency domain to obtain the corresponding frequency domain features. This enables the separation of low-frequency and high-frequency components in the samples, facilitating targeted processing of different frequency components and providing a basic data format for perturbation design at the frequency domain level.

[0034] Step 1022: Use a circular mask filter to separate the low-frequency and high-frequency components of the frequency domain features of the input samples and the random sampled samples.

[0035] In some embodiments, a circular mask filter is defined as:

[0036] in, It is a circular mask filter. The center coordinates of the spectrum The radius is the mask radius.

[0037] Based on a circular mask filter, the low-frequency and high-frequency components of the frequency domain features of the input sample and the random sample sample are separated by the Hadamard product. The calculation formula is as follows:

[0038]

[0039] in, For low-frequency component extraction operator, For high-frequency component extraction operators, Here, I is the Hadamard product operator, where I is a matrix of all ones with the same size as the spectrum. For the frequency domain features of the input samples, This represents the frequency domain characteristics of randomly sampled samples.

[0040] By using a circular mask filter and a Hadamard product, low-frequency and high-frequency components in the frequency domain features of input samples and random samples can be separated. This preserves the main feature information of low-frequency components while providing a clear processing target for the fusion and perturbation generation of high-frequency components, which helps to improve the controllability and targeting of counter-perturbations.

[0041] Step 1023: Weightedly fuse the high-frequency components of the frequency domain features of the input sample with the high-frequency components of the frequency domain features of the random sample to obtain the fused frequency domain features.

[0042] In some embodiments, the formula for weighted fusion of the high-frequency components of the frequency domain features of the input samples and the high-frequency components of the frequency domain features of the randomly sampled samples is as follows:

[0043] in, To fuse frequency domain features, The low-frequency components of the frequency domain features of the input sample. For the high-frequency components of the frequency domain features of the input sample, For high-frequency fusion weighting coefficients, It represents the high-frequency components of the frequency domain characteristics of randomly sampled samples.

[0044] By weighting and fusing only the high-frequency components of the input sample and the randomly sampled sample, the high-frequency perturbation information of the randomly sampled sample can be introduced into the frequency domain features of the input sample while fully preserving the overall semantic information carried by the low-frequency components of the input sample. At the same time, the fusion ratio of the two high-frequency components can be adjusted by the high-frequency fusion weight coefficient, which can enhance the diversity of feature distribution while maintaining the recognizability of the main content, and improve the ability of the generated adversarial examples to interfere with the classification model.

[0045] Step 1024: Convert the fused frequency domain features into the spatial domain using the inverse two-dimensional discrete Fourier transform to obtain frequency domain fused samples. By converting the fused frequency domain features back to the spatial domain using the inverse two-dimensional discrete Fourier transform, the fused frequency domain features can be restored to spatial domain data consistent with the original sample format, resulting in frequency domain fused samples. This facilitates gradient calculation and perturbation updates of the samples in the spatial domain, allowing the perturbation information based on frequency domain fusion to directly affect the spatial domain samples, enhancing the actual effectiveness against perturbation attacks.

[0046] Step 103: Divide the frequency domain fusion sample into multiple local blocks, scale the frequency domain fusion sample to the size of the local block to obtain block-level global features, and for each local block, perform linear fusion processing on the local block and the block-level global features at a random ratio with a preset probability to obtain a linear fusion sample. Perform random scaling on the linear fusion sample and restore it to the size of the frequency domain fusion sample through reflection filling to obtain a data augmentation sample.

[0047] By dividing the frequency domain fusion samples into multiple local blocks and combining block-level global features with random proportional linear fusion, random scale scaling, and reflection filling operations of local blocks, it is possible to introduce diverse combinations of local and global features and scale variations while preserving the main features of the samples. This enriches the data, enhances the diversity of sample feature distribution, improves the robustness of generated samples to different scales and local features, and helps to enhance the generalization attack capability of subsequent adversarial perturbations in classification models.

[0048] In some embodiments, the frequency domain fusion sample is divided into multiple local blocks, and the frequency domain fusion sample is scaled to the size of the local block to obtain block-level global features. For each local block, the local block and the block-level global features are linearly fused at a random ratio with a preset probability to obtain a linearly fused sample. The linearly fused sample is then randomly scaled and restored to the size of the frequency domain fusion sample through reflection padding to obtain a data augmented sample. This includes the following steps: Step 1031: Divide the frequency domain fusion sample into multiple local blocks.

[0049] Specifically, frequency domain fusion sample x f Divide evenly into k There are k local blocks of equal size that do not overlap, and the size of each local block is... H and W represent the height and width of the sample, respectively, and k is a preset block number parameter. By uniformly dividing the frequency domain fusion sample into multiple equal-sized and non-overlapping local blocks, the overall features of the sample can be decomposed into multiple local unit features. This allows subsequent processing of the sample to focus on different local regions, facilitating the introduction of diverse transformations of local features, enhancing the local diversity of sample feature distribution, and helping to improve the perturbation effectiveness of the generated adversarial sample in different local regions.

[0050] Step 1032: Scale the frequency domain fusion samples to the local block size using bilinear interpolation to obtain block-level global features.

[0051] Specifically, a bilinear interpolation scaling operation is used to scale the complete frequency domain fused sample x. f Scale to the size of a single local block to generate block-level global features. ,in This indicates a bilinear interpolation scaling operation to ensure that the block-level global features match the size of the local blocks.

[0052] By using bilinear interpolation scaling, the frequency domain fusion samples are scaled to the local block size to generate block-level global features. This can maintain the overall semantic information of the frequency domain fusion samples while keeping the block-level global features and local blocks the same size, which facilitates the linear fusion operation between the block-level global features and local blocks. It can also introduce global semantic information into local units, enhance the global correlation of local features, and improve the diversity of sample features.

[0053] Step 1033: For each local block, compare the replacement probability with the random number. If the random number is less than the replacement probability, perform linear fusion of the local block and the block-level global features based on the linear fusion weight. If the random number is not less than the replacement probability, retain the content of the local block and obtain the linear fusion sample.

[0054] Specifically, traverse each local block B i,j If random number ,satisfy If the random number t is less than the replacement probability p, then the linear fusion weights are used. The local block and the block-level global features are linearly fused. If the random number is not less than the replacement probability, the content of the local block is retained. After traversal, the linearly fused sample is obtained.

[0055] By judging each local block with a replacement probability, the local block can be selectively linearly fused with block-level global features or the local block content can be retained. This allows for the introduction of global semantic information while preserving some original local features. The degree of fusion can be controlled by the replacement probability and the linear fusion weight, so that the generated linearly fused samples have both local details and global features, improving the diversity of sample feature distribution and enhancing the attack generalization ability of the generated adversarial samples in the classification model.

[0056] In some embodiments, the calculation formula for linearly fusing local block and block-level global features is as follows:

[0057] in, For the fused local block features, For linear fusion weighting coefficients, For block-level global features, These are the original local block features.

[0058] Step 1034: Sample the scaling factor from the uniform distribution, randomly scale the linear fusion sample to obtain the scaled linear fusion sample, embed the scaled linear fusion sample into a random position in the original space, and restore it to the size of the frequency domain fusion sample through reflection filling to obtain the data augmentation sample.

[0059] Specifically, a scaling factor s is sampled from a uniform distribution, and the linearly fused sample x is... b Perform random scaling to obtain scaled linearly fused sample x s Scale the linearly fused sample x s The data is embedded at random locations in the original space, and the edge regions are filled using a reflection-filling operation to restore the size of the frequency domain fused sample, ultimately resulting in the data-enhanced sample x. aug This is to reduce the spatial offset effect caused by fixed positions.

[0060] By introducing random scale scaling and random location embedding into linear fusion samples, the fixed scale and spatial location constraints of the samples can be broken. Combined with reflection filling operations to maintain sample size consistency, the generated data augmentation samples can have richer scale and spatial feature variations, reduce the model's dependence on fixed scale and location features, and enable adversarial perturbations generated based on the samples to better adapt to inputs of different scales and spatial locations, thereby improving the attack performance of adversarial samples in different scenarios.

[0061] Step 104: Perform the data augmentation sample generation process multiple times on the adversarial sample of the current iteration to construct a data augmentation sample set. Based on the loss gradients of each data augmentation sample in the data augmentation sample set and the current adversarial sample, obtain the comprehensive gradient direction. By executing the data augmentation step multiple times to construct the data augmentation sample set and obtaining the comprehensive gradient direction based on the loss gradients of each sample in the set and the current adversarial sample, gradient information from different data augmentation samples can be integrated, reducing the bias caused by a single gradient direction, making the gradient update direction more robust, improving the attack consistency of adversarial perturbations in different data augmentation scenarios, and enhancing the overall interference effect of the generated adversarial samples on the classification model.

[0062] In some embodiments, the step of obtaining data augmentation samples is performed multiple times on the adversarial sample of the current iteration to construct a data augmentation sample set. Based on the loss gradient of each data augmentation sample in the data augmentation sample set and the current adversarial sample, the comprehensive gradient direction is obtained, including the following steps: Step 1041: Perform the steps to obtain data augmentation samples multiple times on the adversarial sample of the current iteration to obtain multiple data augmentation samples, and combine the multiple data augmentation samples into a data augmentation sample set.

[0063] Specifically, for the adversarial examples in the current iteration The process of independently and without repetition is repeated N times to obtain data augmentation samples, generating N mutually independent data augmentation samples with different feature distributions. Combine them into a data augmentation sample set .

[0064] By performing data augmentation operations multiple times on the adversarial examples of the current iteration, multiple data augmentation samples with different feature distributions are generated and a set is constructed. This allows for the introduction of diverse sample forms with different scales, locations, and frequency domain features, enabling gradient calculation to be comprehensively judged based on feedback from multiple independent samples. This reduces the feature bias caused by a single data augmentation operation, allowing the gradient update direction to adapt to more diverse input feature changes and enhancing the attack stability of adversarial perturbations in different scenarios.

[0065] Step 1042: For the target data augmentation sample in the data augmentation sample set, calculate the cross-entropy loss function with the real label as the supervision information, and take the derivative of the cross-entropy loss function with the current adversarial sample as the variable to obtain the loss gradient corresponding to the target data augmentation sample.

[0066] Specifically, for the input sample set The i-th data augmentation sample Using the true label y as the supervision information, the cross-entropy loss function is calculated, and the cross-entropy loss function is applied to the current adversarial example. By taking the derivative, we obtain the loss gradient corresponding to the i-th data augmentation sample.

[0067] Using real labels as supervision information, the cross-entropy loss function is calculated for the target data augmentation samples in the data augmentation sample set. The derivative of the loss function with the current adversarial sample as the variable is calculated, which can obtain the corresponding loss gradient for each data augmentation sample. This can reflect the direction of interference of adversarial samples on the classification model under different data augmentation forms, and provide multi-dimensional gradient information for the generation of comprehensive gradient direction, which helps to improve the adaptability of gradient update to diverse data augmentation scenarios.

[0068] In some embodiments, the formula for calculating the loss gradient is:

[0069] in, The loss gradient calculated in step i is... For gradient operators, This is the current adversarial sample after the (t-1)th iteration. Let cross-entropy be the loss function. The source model for generating adversarial examples, Augment the target data sample for step i. The true labels for the input samples.

[0070] Step 1043: Calculate the average of the loss gradients corresponding to multiple data augmentation samples in the data augmentation sample set to obtain the comprehensive gradient direction.

[0071] Specifically, the loss gradient corresponding to N data augmentation samples in the data augmentation sample set. Arithmetic averaging is performed to eliminate gradient noise and bias caused by single transformation, resulting in a stable and generalizable comprehensive gradient direction, which provides a reliable gradient for subsequent adversarial example updates.

[0072] In some embodiments, the formula for calculating the comprehensive gradient direction is:

[0073] in, The gradient direction is defined by N, which represents the total number of data augmentation samples in the data augmentation sample set. The loss gradient is calculated in step i.

[0074] Step 105: Update the momentum term based on the comprehensive gradient direction, update the adversarial sample through the sign function to obtain the updated adversarial sample, and limit the perturbation amplitude of the updated adversarial sample through the clipping function to obtain the target adversarial sample.

[0075] Accumulating gradient information through momentum terms can smooth the gradient update direction during the iteration process, reduce the interference of gradient noise, and make the perturbation update more stable. Applying perturbation directly along the gradient direction using the sign function can efficiently amplify the interference effect on the classification model. By constraining the perturbation amplitude through the pruning function, the perturbation can be prevented from exceeding the preset range. While ensuring the effectiveness of adversarial examples in attacking the classification model, visual consistency with the original samples is maintained, thus improving the concealment of adversarial examples.

[0076] This invention also provides an adversarial example generation device based on frequency domain fusion and multi-scale input, comprising: an initialization module for initializing momentum terms; a frequency domain fusion module for extracting low-frequency and high-frequency components from input samples and randomly sampled samples respectively, fusing the high-frequency components of the input samples and the high-frequency components of the randomly sampled samples to obtain frequency domain fused samples; and a multi-scale data augmentation module for dividing the frequency domain fused samples into multiple local blocks, scaling the frequency domain fused samples to the size of the local blocks to obtain block-level global features, and linearly fusing the local blocks and block-level global features at a random ratio with a preset probability for each local block to obtain linear... The data augmentation sample is obtained by randomly scaling the linearly fused sample and restoring it to the size of the frequency domain fused sample through reflection padding. The comprehensive gradient calculation module is used to perform the data augmentation sample calculation multiple times on the adversarial sample of the current iteration to construct a data augmentation sample set. Based on the loss gradient of each data augmentation sample in the data augmentation sample set and the current adversarial sample, the comprehensive gradient direction is obtained. The adversarial sample update module is used to update the momentum term based on the comprehensive gradient direction, update the adversarial sample through the sign function to obtain the updated adversarial sample, and limit the perturbation amplitude of the updated adversarial sample through the pruning function to obtain the target adversarial sample.

[0077] The same or similar parts among the various embodiments in this specification can be referred to mutually, and will not be repeated here.

[0078] This invention utilizes frequency domain high-frequency component fusion and multi-scale data enhancement, combined with momentum term cumulative gradient updates, to effectively leverage image frequency domain information and model space invariance. This enhances the robustness of gradient updates and the generalization and adaptation capabilities of perturbations, enabling the generated adversarial examples to exhibit stronger interference consistency under different input scenarios. This helps to improve their adaptation to different classification models.

[0079] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for generating adversarial examples based on frequency domain fusion and multi-scale input, characterized in that, include: Initialize the momentum term; The low-frequency and high-frequency components of the input sample and the random sample are extracted respectively. The high-frequency components of the input sample and the high-frequency components of the random sample are fused to obtain the frequency domain fused sample. The frequency domain fusion sample is divided into multiple local blocks, and the frequency domain fusion sample is scaled to the size of the local block to obtain block-level global features. For each local block, the local block and the block-level global features are linearly fused at a random ratio with a preset probability to obtain a linearly fused sample. The linearly fused sample is then randomly scaled and restored to the size of the frequency domain fusion sample through reflection filling to obtain a data augmentation sample. The process of obtaining data augmentation samples is performed multiple times on the adversarial sample of the current iteration to construct a set of data augmentation samples. Based on the loss gradient of each data augmentation sample in the set of data augmentation samples and the current adversarial sample, the comprehensive gradient direction is obtained. The momentum term is updated based on the comprehensive gradient direction, and the adversarial sample is updated through the sign function to obtain the updated adversarial sample. The perturbation amplitude of the updated adversarial sample is limited through the pruning function to obtain the target adversarial sample.

2. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 1, characterized in that, The step of extracting low-frequency and high-frequency components from the input sample and the random sample, respectively, and fusing the high-frequency components of the input sample and the random sample to obtain a frequency domain fused sample includes: Perform a two-dimensional discrete Fourier transform on the input sample and the randomly sampled sample to obtain the frequency domain features of the input sample and the frequency domain features of the randomly sampled sample; A circular mask filter is used to separate the low-frequency and high-frequency components of the frequency domain features of the input samples and the frequency domain features of the randomly sampled samples; The high-frequency components of the frequency domain features of the input sample are weighted and fused with the high-frequency components of the frequency domain features of the randomly sampled sample to obtain the fused frequency domain features. The fused frequency domain features are converted into the spatial domain by inverse two-dimensional discrete Fourier transform to obtain frequency domain fused samples.

3. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 2, characterized in that, The circular mask filter is defined as follows: in, The center coordinates of the spectrum The radius is the mask radius.

4. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 2, characterized in that, The calculation formula for weighted fusion of the high-frequency components of the input sample frequency domain features and the high-frequency components of the random sample frequency domain features is as follows: in, To fuse frequency domain features, The low-frequency components of the frequency domain features of the input sample. For the high-frequency components of the frequency domain features of the input sample, For high-frequency fusion weighting coefficients, It represents the high-frequency components of the frequency domain characteristics of randomly sampled samples.

5. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 1, characterized in that, The process involves dividing the frequency domain fusion sample into multiple local blocks, scaling the frequency domain fusion sample to the size of each local block to obtain block-level global features, linearly fusing the local block and the block-level global features at a random ratio with a preset probability to obtain a linearly fused sample, randomly scaling the linearly fused sample, and restoring it to the size of the frequency domain fusion sample through reflection filling to obtain a data augmentation sample, including: The frequency domain fusion sample is divided into multiple local blocks; By scaling the frequency domain fused samples to the local block size using bilinear interpolation, block-level global features are obtained. For each local block, the replacement probability is compared with a random number. If the random number is less than the replacement probability, the local block is linearly fused with the block-level global feature based on the linear fusion weight. If the random number is not less than the replacement probability, the content of the local block is retained to obtain a linearly fused sample. Scaling factors are sampled from a uniform distribution, and the linear fusion sample is randomly scaled to obtain a scaled linear fusion sample. The scaled linear fusion sample is then embedded into a random position in the original space, and the size of the frequency domain fusion sample is restored by reflection filling to obtain a data augmentation sample.

6. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 5, characterized in that, The calculation formula for linearly fusing the local block with the block-level global feature is as follows: in, For the fused local block features, For linear fusion weighting coefficients, For block-level global features, These are the original local block features.

7. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 1, characterized in that, The step of performing multiple data augmentation samples on the adversarial sample of the current iteration to construct a data augmentation sample set, and obtaining the comprehensive gradient direction based on the loss gradient of each data augmentation sample in the data augmentation sample set and the current adversarial sample, includes: The process of obtaining data augmentation samples is performed multiple times on the adversarial sample of the current iteration, resulting in multiple data augmentation samples. The multiple data augmentation samples are then combined into a data augmentation sample set. For the target data augmentation sample in the data augmentation sample set, the cross-entropy loss function is calculated with the real label as the supervision information. The cross-entropy loss function is differentiated with the current adversarial sample as the variable to obtain the loss gradient corresponding to the target data augmentation sample. The average loss gradient corresponding to multiple data augmentation samples in the data augmentation sample set is calculated to obtain the comprehensive gradient direction.

8. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 7, characterized in that, The formula for calculating the loss gradient is: in, The loss gradient calculated in step i is... For gradient operators, This is the current adversarial sample after the (t-1)th iteration. Let cross-entropy be the loss function. The source model for generating adversarial examples, Augment the target data sample for step i. The true labels for the input samples.

9. The adversarial example generation method based on frequency domain fusion and multi-scale input according to claim 7, characterized in that, The formula for calculating the comprehensive gradient direction is: in, The gradient direction is defined by N, which represents the total number of data augmentation samples in the data augmentation sample set. The loss gradient is calculated in step i.

10. An adversarial example generation device based on frequency domain fusion and multi-scale input, characterized in that, include: The initialization module is used to initialize the momentum term; The frequency domain fusion module is used to extract the low-frequency and high-frequency components of the input sample and the random sample, respectively, and to fuse the high-frequency components of the input sample and the high-frequency components of the random sample to obtain the frequency domain fused sample. A multi-scale data augmentation module is used to divide the frequency domain fusion sample into multiple local blocks, scale the frequency domain fusion sample to the size of the local block to obtain block-level global features, linearly fuse the local block and the block-level global features at a random ratio with a preset probability to obtain a linearly fused sample, randomly scale the linearly fused sample, and restore it to the size of the frequency domain fusion sample through reflection filling to obtain a data augmented sample. The integrated gradient calculation module is used to perform multiple steps to obtain data augmentation samples on the adversarial sample of the current iteration to construct a set of data augmentation samples. Based on the loss gradient of each data augmentation sample in the set of data augmentation samples and the current adversarial sample, the integrated gradient direction is obtained. The adversarial example update module is used to update the momentum term based on the comprehensive gradient direction, update the adversarial example through a sign function to obtain the updated adversarial example, and limit the perturbation amplitude of the updated adversarial example through a pruning function to obtain the target adversarial example.