Information Processing Apparatus, Information Processing Method, and Recording Medium
The information processing apparatus generates adversarial samples and evaluates authentication risks by calculating similarity and gradient information, addressing vulnerabilities to adversarial attacks and enhancing security in authentication systems.
Patent Information
- Application Number
- JP2024511141
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2025-07-23
- Estimated Expiration
- 2042-03-31
AI Technical Summary
Existing authentication technologies are vulnerable to adversarial samples that can cause misidentification, and there is a lack of effective methods to evaluate and mitigate the risk of such attacks.
An information processing apparatus and method that calculates similarity and gradient information to determine perturbation application positions, applies perturbations to generate adversarial samples, and evaluates the risk in authentication processes, using components like a similarity calculation unit, gradient information calculation unit, perturbation application unit, and risk evaluation unit.
Effectively generates adversarial samples tailored for authentication processes, enabling accurate evaluation of risks against adversarial inputs, improving security by identifying potential misidentification threats.
Smart Images

Figure 0007711842000003 
Figure 0007711842000004 
Figure 0007711842000005
Abstract
Description
Technical Field
[0001] This disclosure relates to the technical field of information processing apparatuses, information processing methods, and recording media.
Background Art
[0002] As this type of system, there is known one that evaluates an authenticator that executes authentication processing. For example, in Patent Document 1, it is disclosed that for an authentication model that performs face authentication or the like, a quantitative evaluation value of robustness against adversarial samples is calculated.
[0003] As other related technologies, for example, in Patent Document 2, it is disclosed that by obtaining candidates for adversarial samples using the feature vectors of face images, candidates for adversarial samples that are likely to cause an error in face authentication by a face authentication device can be obtained. In Patent Document 3, it is disclosed that an attacker generates adversarial inputs so as to be misrecognized in face authentication.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Patent Document 3
Summary of the Invention
Problems to be Solved by the Invention
[0005] This disclosure aims to improve the technologies disclosed in the prior art documents.
Means for Solving the Problems
[0006] One aspect of the information processing apparatus of this disclosure includes a similarity calculation means for calculating the similarity between the feature amount of the first information and the feature amount of the second information, a gradient information calculation means for calculating gradient information indicating the gradient of the similarity, a perturbation application position determination means for determining an element to be a perturbation application target in the first information based on the gradient information, a perturbation application means for applying a perturbation to the element to be the perturbation application target in the first information, and a risk evaluation means for evaluating the risk in the authentication process based on the result of the authentication process of collating the first information with the perturbation applied and the second information.
[0007] One aspect of the information processing method of this disclosure is to calculate, by at least one computer, the similarity between the feature amount of the first information and the feature amount of the second information, calculate gradient information indicating the gradient of the similarity, determine an element to be a perturbation application target in the first information based on the gradient information, apply a perturbation to the element to be the perturbation application target in the first information, and evaluate the risk in the authentication process based on the result of the authentication process of collating the first information with the perturbation applied and the second information.
[0008] One aspect of the recording medium of this disclosure has recorded thereon a computer program that causes at least one computer to calculate the similarity between the feature amount of the first information and the feature amount of the second information, calculate gradient information indicating the gradient of the similarity, determine an element to be a perturbation application target in the first information based on the gradient information, apply a perturbation to the element to be the perturbation application target in the first information, and evaluate the risk in the authentication process based on the result of the authentication process of collating the first information with the perturbation applied and the second information.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Embodiments for Carrying Out the Invention
[0010] Hereinafter, embodiments of an information processing apparatus, an information processing method, and a recording medium will be described with reference to the drawings.
[0011] <First Embodiment> The information processing apparatus according to the first embodiment will be described with reference to FIGS. 1 to 3.
[0012] (Hardware Configuration) First, with reference to FIG. 1, the hardware configuration of the information processing apparatus according to the first embodiment will be described. FIG. 1 is a block diagram showing the hardware configuration of the information processing apparatus according to the first embodiment.
[0013] As shown in FIG. 1, the information processing apparatus 10 according to the first embodiment includes a processor 11, a RAM (Random Access Memory) 12, a ROM (Read Only Memory) 13, and a storage device 14. The information processing apparatus 10 may further include an input device 15 and an output device 16. The above-described processor 11, RAM 12, ROM 13, storage device 14, input device 15, and output device 16 are connected via a data bus 17.
[0014] The processor 11 reads a computer program. For example, the processor 11 is configured to read a computer program stored in at least one of the RAM 12, ROM 13, and storage device 14. Alternatively, the processor 11 may read a computer program stored in a computer-readable recording medium using a recording medium reading device (not shown). The processor 11 may obtain (i.e., read) a computer program from a device (not shown) disposed outside the information processing apparatus 10 via a network interface. The processor 11 controls the RAM 12, storage device 14, input device 15, and output device 16 by executing the read computer program. In particular, in this embodiment, when the processor 11 executes the read computer program, a functional block for evaluating the risk of authentication processing is realized within the processor 11. That is, the processor 11 may function as a controller that executes each control in the information processing apparatus 10.
[0015] Processor 11 may be configured as, for example, a CPU (Central Processing Unit), GPU (Graphics Processing Unit), FPGA (field-programmable gate array), DSP (Demand-Side Platform), or ASIC (Application Specific Integrated Circuit). Processor 11 may be configured with one of these, or may be configured to use a plurality in parallel.
[0016] RAM 12 temporarily stores the computer programs executed by processor 11. RAM 12 temporarily stores the data that processor 11 temporarily uses when executing the computer program. RAM 12 may be, for example, D-RAM (Dynamic Random Access Memory) or SRAM (Static Random Access Memory). Also, instead of RAM 12, other types of volatile memory may be used.
[0017] ROM 13 stores the computer programs executed by processor 11. ROM 13 may also store other fixed data. ROM 13 may be, for example, P-ROM (Programmable Read Only Memory) or EPROM (Erasable Read Only Memory). Also, instead of ROM 13, other types of non-volatile memory may be used.
[0018] Storage device 14 stores the data that information processing device 10 stores long-term. Storage device 14 may operate as a temporary storage device for processor 11. Storage device 14 may include, for example, at least one of a hard disk device, a magneto-optical disk device, an SSD (Solid State Drive), and a disk array device.
[0019] The input device 15 is a device that receives input instructions from the user of the information processing device 10. The input device 15 may include, for example, at least one of a keyboard, a mouse, and a touch panel. The input device 15 may be configured as a portable terminal such as a smartphone or a tablet. The input device 15 may be a device capable of voice input including, for example, a microphone.
[0020] The output device 16 is a device that outputs information regarding the information processing device 10 to the outside. For example, the output device 16 may be a display device (e.g., a display) capable of displaying information regarding the information processing device 10. Also, the output device 16 may be a speaker or the like capable of outputting information regarding the information processing device 10 as voice. The output device 16 may be configured as a portable terminal such as a smartphone or a tablet. Further, the output device 16 may be a device that outputs information in a format other than an image. For example, the output device 16 may be a speaker that outputs information regarding the information processing device 10 as voice.
[0021] Note that in FIG. 1, an example of the information processing device 10 configured to include a plurality of devices is given, but all or some of these functions may be realized by one device. In that case, the information processing device may be configured to include only, for example, the above-described processor 11, RAM 12, and ROM 13, and for the other components (i.e., the storage device 14, the input device 15, and the output device 16), an external device connected to the information processing device may be provided with them. Also, the information processing device may be one in which some arithmetic functions are realized by an external device (e.g., an external server or the cloud).
[0022] (Functional configuration) Next, with reference to FIG. 2, the functional configuration of the information processing device 10 according to the first embodiment will be described. FIG. 2 is a block diagram showing the functional configuration of the information processing device according to the first embodiment.
[0023] As shown in FIG. 2, the information processing apparatus 10 according to the first embodiment includes, as components for realizing its functions, a similarity calculation unit 110, a gradient information calculation unit 120, a perturbation application position determination unit 130, a perturbation application unit 140, and a risk evaluation unit 150. Each of the similarity calculation unit 110, the gradient information calculation unit 120, the perturbation application position determination unit 130, the perturbation application unit 140, and the risk evaluation unit 150 may be a processing block realized by, for example, the above-described processor 11 (see FIG. 1). Further, each of the similarity calculation unit 110, the gradient information calculation unit 120, the perturbation application position determination unit 130, the perturbation application unit 140, and the risk evaluation unit 150 may include a neural network.
[0024] The similarity calculation unit 110 is configured such that the feature amount of the first information (hereinafter, appropriately referred to as the “first information feature amount”) and the feature amount of the second information (hereinafter, appropriately referred to as the “second information feature amount”) are input. Then, the similarity calculation unit 110 is configured to be able to calculate the similarity between the input first information feature amount and the second information feature amount. Note that the method for calculating the similarity is not particularly limited, and existing techniques may be appropriately adopted. The similarity may be a collation score obtained by collating the first information feature amount and the second information feature amount. Specific examples of the first information and the second information will be described in detail in other embodiments described later.
[0025] The gradient information calculation unit 120 is configured to be able to calculate gradient information indicating the gradient of the similarity calculated by the similarity calculation unit 110. Note that the method for calculating the gradient information is not particularly limited, and existing techniques may be appropriately adopted. The gradient information may be information including the Jacobian of the similarity. For example, when the similarity between the first information feature amount f(X a ) and the second information feature amount f(X t ) is L{f(X a ), f(X t ), the gradient information ∇L(X a , X t ) may be calculated as shown in the following formula (1).
[0026]
Equation
[0027] The perturbation application position determination unit 130 is configured to be able to determine an element to be perturbed in the first information based on the gradient information calculated by the gradient information calculation unit 120. The perturbation application position determination unit 130 determines, for example, at least one element to which perturbation is to be applied from among a plurality of elements included in the first information. Here, the "perturbation" is noise applied to increase the similarity between the first information and the second information. For example, the fact that the gradient information represented by the above-described formula (1) is positive means that by applying perturbation to the element X a the similarity between the first information and the second information increases. A more specific method for determining an element to which perturbation is to be applied will be described in detail in other embodiments described later.
[0028] The perturbation application unit 140 is configured to be able to apply perturbation to the element determined by the perturbation application position determination unit 130. That is, the perturbation application unit 140 is configured to be able to generate the first information to which perturbation has been applied (hereinafter, appropriately referred to as an "adversarial sample") by applying perturbation to some elements of the first information. When the adversarial sample generated in this way is used, for example, the similarity between the first information and the second information becomes higher than when no perturbation is applied. That is, the adversarial sample generated by the perturbation application unit 140 is information that is likely to be misrecognized as the second information in the authentication process.
[0029] The risk evaluation unit 150 is configured to be able to evaluate the risk in the authentication process (in other words, the risk latent in the authenticator or authentication model that executes the authentication process). More specifically, the risk evaluation unit 150 evaluates the risk in the authentication process based on the result of the authentication process using the adversarial sample generated by the perturbation application unit 140. For example, the risk evaluation unit 150 may evaluate the possibility that the generated adversarial sample (that is, the first information to which perturbation has been applied) will be recognized as the second information. A specific evaluation method by the risk evaluation unit 150 will be described in detail in other embodiments described later.
[0030] The above-mentioned risk evaluation unit 150 may be provided separately from the device that generates adversarial samples. For example, the adversarial sample generation device configured to include a similarity calculation unit 110, a gradient information calculation unit 120, a perturbation application position determination unit 130, and a perturbation application unit 140, and the risk evaluation device including the risk evaluation unit 150 may be configured as separate devices.
[0031] Note that the authentication process may be executed by an authentication device provided separately from the information processing device 10 according to the present embodiment. In this case, the adversarial sample generated by the perturbation application unit 140 is output to the authentication device, and the risk evaluation unit 150 may evaluate the risk using the authentication result input from the authentication device. Alternatively, the risk evaluation unit 150 may have a function of executing the authentication process. That is, the risk evaluation unit 150 itself may execute the authentication process and be configured to evaluate the risk of the authentication process based on the authentication result.
[0032] (Flow of operations) Next, with reference to FIG. 3, the overall operation flow of the information processing device 10 according to the first embodiment will be described. FIG. 3 is a flowchart showing the operation flow of the information processing device according to the first embodiment.
[0033] As shown in FIG. 3, when the operation of the information processing device 10 according to the first embodiment is started, first, the similarity calculation unit 110 acquires the first information feature amount and the second information feature amount (step S101). Then, the similarity calculation unit 110 calculates the similarity between the acquired first information feature amount and the second information feature amount (step S102). Information regarding the similarity calculated by the similarity calculation unit 110 is output to the gradient information calculation unit 120.
[0034] Subsequently, the gradient information calculation unit 120 calculates gradient information indicating the gradient of the similarity calculated by the similarity calculation unit 110 (step S103). The gradient information calculated by the gradient information calculation unit 120 is output to the perturbation application position determination unit 130.
[0035] Subsequently, the perturbation application position determination unit 130 determines an element to which perturbation is to be applied in the first information based on the gradient information calculated by the gradient information calculation unit 120 (step S104). Information regarding the element determined by the perturbation application position determination unit 130 is output to the perturbation application unit 140.
[0036] Subsequently, the perturbation application unit 140 applies a perturbation to the element determined by the perturbation application position determination unit 130 (step S105). That is, a perturbation is applied to the first information to generate an adversarial sample. The adversarial sample generated by the perturbation application unit 140 is used for the authentication process.
[0037] Subsequently, the risk evaluation unit 150 evaluates the risk in the authentication process based on the authentication result of the authentication process using the adversarial sample generated by the perturbation application unit 140 (step S106). The risk evaluation unit 150 may output the evaluation result of the risk.
[0038] (Technical Effect) Next, the technical effect obtained by the information processing apparatus 10 according to the first embodiment will be described.
[0039] As described with reference to FIGS. 1 to 3, in the information processing apparatus 10 according to the first embodiment, an adversarial sample is generated by applying a perturbation based on the similarity between two pieces of information. Then, based on the result of the authentication process using the generated adversarial sample, the risk of the authentication process is evaluated. In this way, the risk of the authentication process against adversarial input can be appropriately evaluated. Specifically, it becomes possible to evaluate what risks the authentication process has against an attack aimed at obtaining an intentionally incorrect authentication result.
[0040] Note that JSMA (Jacobian-base Saliency Map Attack) is known as a method for generating adversarial samples. However, since this method assumes a class classification process (i.e., a process that obtains a classification probability vector as a processing result), it cannot be directly applied when generating adversarial samples for an authentication process (i.e., a process that obtains a similarity as a processing result). However, in the information processing apparatus according to the present embodiment, adversarial samples suitable for the authentication process are generated, so the risk in the authentication process can be appropriately evaluated.
[0041] <Second Embodiment> The information processing apparatus 10 according to the second embodiment will be described with reference to FIGS. 4 and 5. Note that the second embodiment is only different from the above-described first embodiment in some configurations and operations, and the other parts may be the same as those of the first embodiment. Therefore, hereinafter, the parts different from the first embodiment already described will be described in detail, and the description of the other overlapping parts will be omitted as appropriate.
[0042] (Functional Configuration) First, with reference to FIG. 4, the functional configuration of the information processing apparatus 10 according to the second embodiment will be described. FIG. 4 is a block diagram showing the functional configuration of the information processing apparatus according to the second embodiment. In FIG. 4, the same reference numerals are given to the elements similar to those shown in FIG. 2.
[0043] As shown in FIG. 4, the information processing apparatus 10 according to the second embodiment includes, as components for realizing its functions, a similarity calculation unit 110, a gradient information calculation unit 120, a perturbation application position determination unit 130, a perturbation application unit 140, a risk evaluation unit 150, and a feature amount extraction unit 160. That is, the information processing apparatus 10 according to the second embodiment further includes a feature amount extraction unit 160 in addition to the configuration of the first embodiment (see FIG. 2). The feature amount extraction unit 160 may be, for example, a processing block realized by the above-described processor 11 (see FIG. 1).
[0044] The feature extraction unit 160 is configured such that a first image, which is a specific example of the first information, and a second image, which is a specific example of the second information, are input thereto. Note that the first image is an image including a first living body, and the second image is an image including a second living body. The first image and the second image may be, for example, a face image including a face of a living body or an iris image including an iris. Then, the feature extraction unit 160 is configured to be able to extract features from the first image and the second image. That is, the feature extraction unit 160 is configured to be able to extract a feature amount related to the first living body included in the first image and a feature amount related to the second living body included in the second image. Each feature amount extracted by the feature extraction unit 160 is input to the similarity calculation unit 110 as a first information feature amount and a second information feature amount.
[0045] (Flow of operations) Next, with reference to FIG. 5, the overall operation flow of the information processing apparatus 10 according to the second embodiment will be described. FIG. 5 is a flowchart showing the operation flow of the information processing apparatus according to the second embodiment. In FIG. 5, the same reference numerals are given to the same processes as those shown in FIG. 3.
[0046] As shown in FIG. 5, when the operation of the information processing apparatus 10 according to the second embodiment is started, first, the feature extraction unit 160 acquires the first image and the second image (step S201). Then, the feature extraction unit 160 extracts a first information feature amount from the first image and extracts a second information feature amount from the second image (step S202). Information regarding the feature amount extracted by the feature extraction unit 160 is output to the similarity calculation unit 110.
[0047] Subsequently, the similarity calculation unit 110 calculates the similarity between the first information feature amount and the second information feature amount extracted by the feature extraction unit 160 (step S102). Information regarding the similarity calculated by the similarity calculation unit 110 is output to the gradient information calculation unit 120.
[0048] Subsequently, the gradient information calculation unit 120 calculates gradient information indicating the gradient of the similarity calculated by the similarity calculation unit 110 (step S103). The gradient information calculated by the gradient information calculation unit 120 is output to the perturbation application position determination unit 130.
[0049] Subsequently, the perturbation application position determination unit 130 determines an element to which perturbation is to be applied in the first information based on the gradient information calculated by the gradient information calculation unit 120 (step S104). Here, the element may be a pixel in the first image. The perturbation application position determination unit 130 may perform a process of determining the position of a pixel to which perturbation is to be applied, for example, among a plurality of pixels included in the first image. Information regarding the element determined by the perturbation application position determination unit 130 is output to the perturbation application unit 140.
[0050] Subsequently, the perturbation application unit 140 applies a perturbation to the element determined by the perturbation application position determination unit 130 (step S105). That is, the perturbation application unit 140 applies a perturbation to the pixel of the first image determined by the perturbation application position determination unit 130 to generate an adversarial sample. The adversarial sample generated by the perturbation application unit 140 is used for the authentication process.
[0051] Subsequently, the risk evaluation unit 150 evaluates the risk in the authentication process based on the authentication result of the authentication process using the adversarial sample generated by the perturbation application unit 140 (step S106). The risk evaluation unit 150 may output the evaluation result of the risk.
[0052] (Technical effect) Next, the technical effect obtained by the information processing apparatus 10 according to the second embodiment will be described.
[0053] As described with reference to FIGS. 4 and 5, in the information processing apparatus 10 according to the second embodiment, feature amounts are extracted from each of the first image and the second image, and adversarial samples are generated by adding perturbations based on their similarity. In this way, the risk of the authentication process using images can be appropriately evaluated. For example, for face authentication using a face image or iris authentication using an iris image, it becomes possible to appropriately evaluate the risk against adversarial inputs.
[0054] <Third Embodiment> The information processing apparatus 10 according to the third embodiment will be described with reference to FIG. 6. Note that the third embodiment describes a specific example of the operation for determining the perturbation application position in the first and second embodiments described above (that is, the operation corresponding to step S104 in FIG. 3), and other parts may be the same as those in the first and second embodiments. For this reason, in the following, parts different from the embodiments already described will be described in detail, and description of other overlapping parts will be omitted as appropriate.
[0055] (Perturbation Application Position Determination Operation) First, with reference to FIG. 6, the flow of the perturbation application position determination operation (that is, the operation for determining the element to which the perturbation is applied) by the information processing apparatus 10 according to the third embodiment will be described. FIG. 6 is a flowchart showing the flow of the perturbation application position determination operation by the information processing apparatus according to the third embodiment.
[0056] As shown in FIG. 6, in the perturbation application position determination operation by the information processing apparatus 10 according to the third embodiment, first, the perturbation application position determination unit 130 acquires the gradient information calculated by the gradient information calculation unit 120 (that is, the gradient information of the similarity between the first information feature amount and the second information feature amount) (step S301). Then, the perturbation application position determination unit 130 searches for one element with the maximum gradient information based on the gradient information calculated by the gradient information calculation unit 120 (step S302).
[0057] Subsequently, the perturbation application position determination unit 130 determines one element with the maximum gradient information obtained as the search result as the element to which perturbation is applied (i.e., the perturbation application position) (step S303). When there are a plurality of elements with the maximum gradient information, the perturbation application position determination unit 130 may select one element from these plurality of elements and determine all of them as the element to which perturbation is applied. Thereafter, the perturbation application position determination unit 130 outputs information regarding the element to which perturbation is applied to the perturbation application unit 140 (step S304).
[0058] (Technical effect) Next, the technical effect obtained by the information processing apparatus 10 according to the third embodiment will be described.
[0059] As described with reference to FIG. 6, in the information processing apparatus 10 according to the third embodiment, one element with the maximum gradient information is determined as the perturbation application target. In this way, the perturbation application position can be easily and appropriately determined based on the gradient information. Therefore, adversarial samples can be appropriately generated and the risk of the authentication process can be evaluated.
[0060] <Fourth Embodiment> The information processing apparatus 10 according to the fourth embodiment will be described with reference to FIG. 7. Note that the fourth embodiment, like the third embodiment described above, describes a specific example of the perturbation application position determination operation, and other parts may be the same as those of the first and second embodiments. Therefore, hereinafter, parts different from the embodiments already described will be described in detail, and description of other overlapping parts will be omitted as appropriate.
[0061] (Perturbation application position determination operation) First, with reference to FIG. 7, the flow of the perturbation application position operation by the information processing apparatus 10 according to the fourth embodiment will be described. FIG. 7 is a flowchart showing the flow of the perturbation application position determination operation by the information processing apparatus according to the fourth embodiment.
[0062] As shown in FIG. 7, in the perturbation application position determination operation by the information processing apparatus 10 according to the fourth embodiment, first, the perturbation application position determination unit 130 acquires the gradient information calculated by the gradient information calculation unit 120 (that is, the gradient information of the similarity between the first information feature amount and the second information feature amount) (step S401). Then, the perturbation application position determination unit 130 sorts each element in descending order of the gradient information calculated by the gradient information calculation unit 120 (step S402).
[0063] Subsequently, the perturbation application position determination unit 130 determines a predetermined number of elements in descending order of the gradient information as the elements to which perturbation is to be applied (that is, the perturbation application positions) (step S403). Here, the "predetermined number" is the number of elements selected as the perturbation application positions, and may be, for example, a value that can be arbitrarily set by a user or the like. For example, when the predetermined number is set to "3", the perturbation application position determination unit 130 may determine the element with the highest gradient information, the second highest element, and the third highest element as the perturbation application positions. Thereafter, the perturbation application position determination unit 130 outputs information regarding the elements to which perturbation is to be applied to the perturbation application unit 140 (step S404).
[0064] (Technical Effect) Next, the technical effect obtained by the information processing apparatus 10 according to the fourth embodiment will be described.
[0065] As described with reference to FIG. 7, in the information processing apparatus 10 according to the fourth embodiment, a predetermined number of elements are determined as the perturbation application targets in descending order of the gradient information. In this way, the perturbation application positions can be easily and appropriately determined based on the gradient information. Therefore, adversarial samples can be appropriately generated and the risk of the authentication process can be evaluated.
[0066] <Fifth Embodiment> The information processing apparatus 10 according to the fifth embodiment will be described with reference to FIG. 8. Note that, similar to the above-described third and fourth embodiments, the fifth embodiment describes a specific example of the perturbation application positioning operation, and other parts may be the same as those in the first and second embodiments. For this reason, in the following, parts different from the above-described embodiments will be described in detail, and description of other overlapping parts will be omitted as appropriate.
[0067] (Perturbation application positioning operation) First, with reference to FIG. 8, the flow of the perturbation application position operation by the information processing apparatus 10 according to the fifth embodiment will be described. FIG. 8 is a flowchart showing the flow of the perturbation application positioning operation by the information processing apparatus according to the fifth embodiment.
[0068] As shown in FIG. 8, in the perturbation application positioning operation by the information processing apparatus 10 according to the fifth embodiment, first, the perturbation application position determination unit 130 acquires the gradient information (that is, the gradient information of the similarity between the first information feature amount and the second information feature amount) calculated by the gradient information calculation unit 120 (step S501). Then, the perturbation application position determination unit 130 compares the gradient information calculated by the gradient information calculation unit 120 with a predetermined threshold (step S502). Here, the "predetermined threshold" is a threshold set in advance for determining the perturbation application position.
[0069] Subsequently, the perturbation application position determination unit 130 determines an element with gradient information higher than the predetermined threshold as an element to which perturbation is applied (that is, the perturbation application position) (step S503). For this reason, for example, when it is desired to determine a relatively small number of elements as the perturbation application position, the predetermined threshold may be set to a higher value. Conversely, when it is desired to determine a relatively large number of elements as the perturbation application position, the predetermined threshold may be set to a lower value. Thereafter, the perturbation application position determination unit 130 outputs information regarding the element to which perturbation is applied to the perturbation application unit 140 (step S404).
[0070] In the process of step S503, when there is no gradient information greater than a predetermined threshold (that is, when all gradient information is lower than the predetermined threshold), after the predetermined threshold is reset to a lower value, the processes of steps S502 and S503 may be performed again. Alternatively, when there is no gradient information greater than the predetermined threshold, the perturbation application position may be determined by the method already described in the third and fourth embodiments.
[0071] (Technical effect) Next, the technical effect obtained by the information processing apparatus 10 according to the fifth embodiment will be described.
[0072] As described with reference to FIG. 8, in the information processing apparatus 10 according to the fifth embodiment, an element with gradient information greater than a predetermined threshold is determined as a perturbation application target. In this way, the perturbation application position can be easily and appropriately determined based on the gradient information. Therefore, adversarial samples can be appropriately generated and the risk of the authentication process can be evaluated.
[0073] <Sixth Embodiment> The information processing apparatus 10 according to the sixth embodiment will be described with reference to FIG. 9. Note that the sixth embodiment is only different from the first to fifth embodiments described above in some structural operations, and the other parts may be the same as those of the first to fifth embodiments. For this reason, in the following, the parts different from the embodiments already described will be described in detail, and the description of the other overlapping parts will be omitted as appropriate.
[0074] (Risk evaluation operation) First, with reference to FIG. 9, the flow of the risk evaluation operation (that is, the operation when evaluating the risk using the generated adversarial sample) by the information processing apparatus 10 according to the sixth embodiment will be described. FIG. 9 is a flowchart showing the flow of the risk evaluation operation by the information processing apparatus according to the sixth embodiment.
[0075] As shown in FIG. 9, in the risk assessment operation by the information processing apparatus 10 according to the sixth embodiment, first, the risk assessment unit 150 acquires the result of the authentication process using adversarial samples (that is, the first information with perturbations added) (step S601). Then, the risk assessment unit 150 calculates the false authentication probability based on the acquired authentication result (step S602). The false authentication probability is the probability that an incorrect authentication result will be obtained. For example, it can be calculated by dividing the number of times false authentication has occurred by the total number of authentication times.
[0076] Subsequently, the risk assessment unit 150 evaluates the risk of the authentication process based on the calculated false authentication probability (step S603). For example, the risk assessment unit 150 may determine that the higher the false authentication probability, the higher the risk. Thereafter, the risk assessment unit 150 outputs the evaluation result (step S604). The risk assessment unit 150 may output the false authentication probability together with the evaluation result.
[0077] (Technical Effect) Next, the technical effect obtained by the information processing apparatus 10 according to the sixth embodiment will be described.
[0078] As described with reference to FIG. 9, in the information processing apparatus 10 according to the sixth embodiment, the risk is evaluated based on the false authentication probability calculated from the authentication result. In this way, it is possible to appropriately evaluate the risk that the authentication result will output an incorrect authentication result for adversarial input.
[0079] <Seventh Embodiment> The information processing apparatus 10 according to the seventh embodiment will be described with reference to FIGS. 10 to 12. Note that the seventh embodiment is only different from the first to sixth embodiments described above in some configurations and operations, and the other parts may be the same as those of the first to sixth embodiments. Therefore, hereinafter, the parts different from the embodiments already described will be described in detail, and the description of the other overlapping parts will be omitted as appropriate.
[0080] (Functional Configuration) First, with reference to FIG. 10, the functional configuration of the information processing apparatus 10 according to the seventh embodiment will be described. FIG. 10 is a block diagram showing the functional configuration of the information processing apparatus according to the seventh embodiment. In FIG. 10, the same reference numerals are given to the same elements as those shown in FIG. 2.
[0081] As shown in FIG. 10, the information processing apparatus 10 according to the seventh embodiment includes, as components for realizing its functions, a similarity calculation unit 110, a gradient information calculation unit 120, a perturbation application position determination unit 130, a perturbation application unit 140, and a risk evaluation unit 150. In particular, the similarity calculation unit 110 according to the seventh embodiment is configured such that, in addition to the first information feature amount and the second information feature amount, a third information feature amount is input.
[0082] The similarity calculation unit 110 according to the seventh embodiment is configured such that, in addition to the feature amount of the first information and the feature amount of the second information, a feature amount of the third information (hereinafter, appropriately referred to as "third information feature amount") is input. And the similarity calculation unit 110 is configured to be able to calculate the similarity between the first information feature amount and the third information feature amount (hereinafter, appropriately referred to as "second similarity") in addition to the similarity between the first information feature amount and the second information feature amount (hereinafter, appropriately referred to as "first similarity") which has already been described.
[0083] The gradient information calculation unit 120 according to the seventh embodiment is configured to be able to calculate the gradient information of the second similarity (hereinafter, appropriately referred to as "second gradient information") in addition to the gradient information of the first similarity (hereinafter, appropriately referred to as "first gradient information") which has already been described. For example, when the similarity between the first information feature amount f(X a ) and the third information feature amount f(X s ) is denoted as L{f(X a ), f(X s ), the gradient information ∇L(X a , X s ) may be calculated as in the following formula (2).
[0084]
Equation
[0085] The perturbation application position determination unit 130 according to the seventh embodiment is configured to be able to determine an element to which perturbation is to be applied in the first information based on the first gradient information and the second gradient information calculated by the gradient information calculation unit 120. That is, the perturbation application position determination unit 130 determines an element to which perturbation is to be applied based on the two gradient informations. Note that the method for determining an element to which perturbation is to be applied using the two gradient informations will be described in detail in other embodiments described later.
[0086] Note that the information processing apparatus 10 according to the seventh embodiment may include the feature amount extraction unit 160 described in the second embodiment in addition to the above-described configuration. In this case, the feature amount extraction unit 160 may receive a third image (that is, an image including a third living body) in addition to the first image and the second image. Then, the feature amount extraction unit 160 may be configured to extract a first information feature amount from the first image, extract a second information amount from the second image, and extract a third information feature amount from the third image.
[0087] (Assumed attack example) Next, with reference to FIG. 11, an attack example assumed in the information processing apparatus 10 according to the seventh embodiment will be described. FIG. 11 is a conceptual diagram showing an attack example on a face authentication gate at an airport.
[0088] As shown in FIG. 11, the information processing apparatus 10 according to the seventh embodiment may evaluate the risk in the face authentication system at the airport. For example, assume that there are a person A who is a collaborator and a person B who is a terrorist. In this case, first, person A submits a photo to apply for a passport. The photo submitted at this time looks like person A to the human eye, but is a photo that is similar to both person A and person B when viewed from the authenticator.
[0089] After that, Person A transfers the passport to Person B. Then, Person B attempts to pass through the unmanned gate at the airport (a gate that permits passage through facial recognition) by presenting the passport transferred from Person A. At this time, authentication processing is performed at the gate using the photo (registered image) submitted during passport application. This registered image also resembles Person B as described above. Therefore, at the unmanned gate, the authentication processing for Person B is successful (i.e., misidentified as Person A), and as a result, an illegal breakthrough by Person B occurs.
[0090] As described above, in authentication processing, photos that are similar among multiple users can pose a greater threat. Therefore, when evaluating the risk of authentication processing, it is preferable to use the similarity with multiple users. In contrast, for the information processing apparatus 10 according to the seventh embodiment, the similarities between two pieces of information (i.e., the similarity between the first information and the second information, and the similarity between the first information and the third information) are considered. For this reason, it is possible to evaluate the risk assuming an attack example by multiple users as described above.
[0091] (Flow of operations) Next, with reference to FIG. 12, the overall flow of operations by the information processing apparatus 10 according to the seventh embodiment will be described. FIG. 12 is a flowchart showing the flow of operations of the information processing apparatus according to the seventh embodiment. In FIG. 12, the same reference numerals are given to the same processes as those shown in FIG. 3.
[0092] As shown in FIG. 12, when the operation of the information processing apparatus 10 according to the seventh embodiment is started, first, the similarity calculation unit 110 acquires the first information feature amount, the second information feature amount, and the third information feature amount (step S701). Then, the similarity calculation unit 110 calculates a first similarity, which is the similarity between the first information feature amount and the second information feature amount, and a second similarity, which is the similarity between the first information feature amount and the third information feature amount (step S702). Information regarding the first and second similarities calculated by the similarity calculation unit 110 is output to the gradient information calculation unit 120.
[0093] Subsequently, the gradient information calculation unit 120 calculates first gradient information indicating the gradient of the first similarity calculated by the similarity calculation unit 110 and second gradient information indicating the gradient of the second similarity (step S703). The first and second gradient information calculated by the gradient information calculation unit 120 is output to the perturbation application position determination unit 130.
[0094] Subsequently, the perturbation application position determination unit 130 determines an element to which perturbation is to be applied in the first information based on the first gradient information and the second gradient information calculated by the gradient information calculation unit 120 (step S704). Information regarding the element determined by the perturbation application position determination unit 130 is output to the perturbation application unit 140.
[0095] Subsequently, the perturbation application unit 140 applies a perturbation to the element determined by the perturbation application position determination unit 130 (step S105). That is, a perturbation is applied to the first information to generate an adversarial sample. The adversarial sample generated by the perturbation application unit 140 is used for the authentication process.
[0096] Subsequently, the risk evaluation unit 150 evaluates the risk in the authentication process based on the authentication result of the authentication process using the adversarial sample generated by the perturbation application unit 140 (step S106). The risk evaluation unit 150 may output the evaluation result of the risk.
[0097] (Technical Effect) Next, the technical effect obtained by the information processing apparatus 10 according to the seventh embodiment will be described.
[0098] As described with reference to FIGS. 10 to 12, in the information processing apparatus 10 according to the seventh embodiment, an adversarial sample is generated in consideration of third information in addition to the first information and the second information. Therefore, compared with the case where only the first information and the second information are considered, an adversarial sample can be generated more appropriately. For example, an adversarial sample considering both the source image and the target image described above can be generated. Thus, it becomes possible to more appropriately evaluate the risk of the authentication process.
[0099] <Eighth Embodiment> The information processing apparatus 10 according to the eighth embodiment will be described with reference to FIG. 13. Note that the eighth embodiment describes a specific example of the perturbation application positioning operation in the above-described seventh embodiment, and other parts may be the same as those in the first to seventh embodiments. For this reason, hereinafter, parts different from the already described embodiments will be described in detail, and redundant parts will be omitted as appropriate.
[0100] (Perturbation application positioning operation) First, with reference to FIG. 13, the flow of the perturbation application position operation by the information processing apparatus 10 according to the eighth embodiment will be described. FIG. 13 is a flowchart showing the flow of the perturbation application positioning operation by the information processing apparatus according to the eighth embodiment.
[0101] As shown in FIG. 13, in the perturbation application positioning operation by the information processing apparatus 10 according to the eighth embodiment, first, the perturbation application position determination unit 130 acquires the first gradient information (i.e., the gradient information of the similarity between the first information feature amount and the second information feature amount) calculated by the gradient information calculation unit 120 and the second gradient information (i.e., the gradient information of the similarity between the first information feature amount and the third information feature amount) (step S801).
[0102] Subsequently, the perturbation application position determination unit 120 calculates an index value from the first gradient information and the second gradient information calculated by the gradient information calculation unit 120 (step S802). The "index value" here is a value used as an index for determining the perturbation application position. The index value may be, for example, a value calculated as the product of the first gradient information and the second gradient information. Alternatively, the index value may be a weighted sum of the first gradient information and the second gradient information. Alternatively, the index value may be the sum of the absolute value of the first gradient information and the absolute value of the second gradient information.
[0103] Subsequently, the perturbation application position determination unit 130 determines the position to which perturbation is to be applied in the first information based on the calculated index value (step S803). For example, the perturbation application position determination unit 130 may determine one element with the maximum index value as the perturbation application position (see the third embodiment). Alternatively, the perturbation application position determination unit 130 may determine a predetermined number of elements in descending order of the index value as the perturbation application positions (see the fourth embodiment). Alternatively, the perturbation application position determination unit 130 may determine an element whose index value is greater than a predetermined threshold value as the perturbation application position (see the fifth embodiment). Then, the perturbation application position determination unit 130 outputs information regarding the element to which perturbation is to be applied to the perturbation application unit 140 (step S804).
[0104] (Technical effect) Next, the technical effect obtained by the information processing apparatus 10 according to the eighth embodiment will be described.
[0105] As described with reference to FIG. 13, in the information processing apparatus 10 according to the eighth embodiment, an element to which perturbation is to be applied is determined based on the index value calculated from the first gradient information and the second gradient information. In this way, the perturbation application position can be determined in consideration of the similarity between the first information and the second information, and the similarity between the first information and the third information. Therefore, adversarial samples can be appropriately generated and the risk of the authentication process can be evaluated.
[0106] A program that operates the configuration of the embodiment so as to realize the functions of the above-described embodiments is recorded on a recording medium, the program recorded on the recording medium is read as code, and a processing method executed by a computer is also included in the scope of each embodiment. That is, a computer-readable recording medium is also included in the scope of each embodiment. In addition, not only the recording medium on which the above program is recorded but also the program itself is included in each embodiment.
[0107] As the recording medium, for example, a floppy (registered trademark) disk, a hard disk, an optical disk, a magneto-optical disk, a CD-ROM, a magnetic tape, a non-volatile memory card, or a ROM can be used. Moreover, the present embodiments include not only those that execute processing with a program alone recorded on the recording medium, but also those that operate on an OS and execute processing in cooperation with the functions of other software and expansion boards. Further, the program itself may be stored in a server, and part or all of the program may be downloadable from the server to a user terminal.
[0108] <Supplementary Note> Regarding the embodiments described above, they can be further described as in the following supplementary notes, but are not limited thereto.
[0109] (Supplementary Note 1) The information processing apparatus described in Supplementary Note 1 includes a similarity calculation means for calculating the similarity between the feature amount of the first information and the feature amount of the second information, a gradient information calculation means for calculating gradient information indicating the gradient of the similarity, a perturbation application position determination means for determining an element to be a perturbation application target in the first information based on the gradient information, a perturbation application means for applying a perturbation to the element to be the perturbation application target in the first information, and a risk evaluation means for evaluating the risk in the authentication process based on the result of the authentication process of comparing the first information with the perturbation applied and the second information.
[0110] (Supplementary Note 2) In the information processing apparatus described in Supplementary Note 2, the first information is a first image including a first living body, the second information is a second image including a second living body, and the similarity calculation means calculates the similarity between the feature amount related to the first living body extracted from the first image and the feature amount related to the second living body extracted from the second image. It is the information processing apparatus described in Supplementary Note 1.
[0111] (Supplementary Note 3) The information processing apparatus described in Supplementary Note 3 is the information processing apparatus according to Supplementary Note 1 or 2, wherein the perturbation application position determination means determines one element with the maximum gradient information as the element to which perturbation is to be applied.
[0112] (Supplementary Note 4) The information processing apparatus described in Supplementary Note 4 is the information processing apparatus according to Supplementary Note 1 or 2, wherein the perturbation application position determination means determines a predetermined number of elements in descending order of the gradient information as the elements to which perturbation is to be applied.
[0113] (Supplementary Note 5) The information processing apparatus described in Supplementary Note 5 is the information processing apparatus according to Supplementary Note 1 or 2, wherein the perturbation application position determination means determines an element with gradient information greater than a predetermined threshold value as the element to which perturbation is to be applied.
[0114] (Supplementary Note 6) The information processing apparatus described in Supplementary Note 6 is the information processing apparatus according to any one of Supplementary Notes 1 to 5, wherein the risk evaluation means calculates a false authentication probability in the authentication process and evaluates the risk in the authentication process based on the false authentication probability.
[0115] (Supplementary Note 7) The information processing apparatus described in Supplementary Note 7 is the information processing apparatus according to any one of Supplementary Notes 1 to 6, wherein the similarity calculation means calculates the similarity between the feature amount of the first information and the feature amount of the third information in addition to the similarity between the feature amount of the first information and the feature amount of the second information, the gradient information calculation means calculates the gradient information of the similarity between the feature amount of the first information and the feature amount of the third information in addition to the gradient information of the similarity between the feature amount of the first information and the feature amount of the second information, and the perturbation application position determination means determines the element to which perturbation is to be applied based on the gradient information of the similarity between the feature amount of the first information and the feature amount of the third information and the gradient information of the similarity between the feature amount of the first information and the feature amount of the third information.
[0116] (Supplementary Note 8) The information processing apparatus according to Supplementary Note 8, wherein the perturbation application position determination means determines an element to which perturbation is to be applied by using at least one of a product, a weighted sum, and a sum of absolute values of gradient information of the similarity between the feature amount of the first information and the feature amount of the third information and gradient information of the similarity between the feature amount of the first information and the feature amount of the third information, is the information processing apparatus according to Supplementary Note 7.
[0117] (Supplementary Note 9) The information processing method according to Supplementary Note 9 is an information processing method in which at least one computer calculates a similarity between a feature amount of first information and a feature amount of second information, calculates gradient information indicating a gradient of the similarity, determines an element to which perturbation is to be applied in the first information based on the gradient information, applies perturbation to the element to which perturbation is to be applied in the first information, and evaluates a risk in the authentication process based on a result of an authentication process of comparing the first information to which the perturbation has been applied with the second information.
[0118] (Supplementary Note 10) The recording medium according to Supplementary Note 10 is a recording medium on which a computer program for causing at least one computer to execute an information processing method in which a similarity between a feature amount of first information and a feature amount of second information is calculated, gradient information indicating a gradient of the similarity is calculated, an element to which perturbation is to be applied in the first information is determined based on the gradient information, perturbation is applied to the element to which perturbation is to be applied in the first information, and a risk in the authentication process is evaluated based on a result of an authentication process of comparing the first information to which the perturbation has been applied with the second information is recorded.
[0119] (Supplementary Note 11) The computer program described in Supplementary Note 11 causes at least one computer to calculate the similarity between the feature amounts of first information and the feature amounts of second information, calculate gradient information indicating the gradient of the similarity, determine an element to which perturbation is to be applied in the first information based on the gradient information, apply perturbation to the element to which perturbation is to be applied in the first information, and evaluate the risk in the authentication process based on the result of the authentication process of comparing the first information to which the perturbation has been applied and the second information.
[0120] (Supplementary Note 12) The information processing system described in Supplementary Note 12 includes a similarity calculation means for calculating the similarity between the feature amounts of first information and the feature amounts of second information, a gradient information calculation means for calculating gradient information indicating the gradient of the similarity, a perturbation application position determination means for determining an element to which perturbation is to be applied in the first information based on the gradient information, a perturbation application means for applying perturbation to the element to which perturbation is to be applied in the first information, and a risk evaluation means for evaluating the risk in the authentication process based on the result of the authentication process of comparing the first information to which the perturbation has been applied and the second information.
[0121] This disclosure can be appropriately modified within a range not contrary to the gist or idea of the invention that can be read from the claims and the entire specification, and an information processing apparatus, an information processing method, and a recording medium involving such modifications are also included in the technical idea of this disclosure.
Explanation of Reference Numerals
[0122] 10 Information processing apparatus 11 Processor 110 Similarity calculation unit 120 Gradient information calculation unit 130 Perturbation application position determination unit 140 Perturbation application unit 150 Risk evaluation unit 160 Feature amount extraction unit
Claims
1. A similarity calculation means for calculating a similarity between a feature amount of first information and a feature amount of second information; A gradient information calculation means for calculating gradient information indicating a gradient of the similarity; A perturbation application position determination means for determining an element to which perturbation is to be applied in the first information based on the gradient information; A perturbation application means for applying perturbation to the element to which the perturbation is to be applied in the first information; A risk evaluation means for evaluating a risk in the authentication process based on a result of an authentication process of collating the first information to which the perturbation is applied and the second information; An information processing apparatus comprising the above.
2. The first information is a first image including a first living body, The second information is a second image including a second living body, The similarity calculation means calculates a similarity between a feature amount related to the first living body extracted from the first image and a feature amount related to the second living body extracted from the second image. The information processing apparatus according to claim 1.
3. The application position determination means determines one element with the maximum gradient information as the element to which the perturbation is to be applied. The information processing apparatus according to claim 1 or 2.
4. The application position determination means determines a predetermined number of elements in descending order of the gradient information as the elements to which the perturbation is to be applied. The information processing apparatus according to claim 1 or 2.
5. The application position determination means determines an element with the gradient information greater than a predetermined threshold value as the element to which the perturbation is to be applied. The information processing apparatus according to claim 1 or 2.
6. The risk evaluation means calculates a false authentication probability in the authentication process and evaluates the risk in the authentication process based on the false authentication probability. The information processing apparatus according to any one of claims 1 to 5.
7. The similarity calculation means calculates, in addition to the similarity between the feature amount of the first information and the feature amount of the second information, a similarity between the feature amount of the first information and the feature amount of third information. The gradient information calculation means calculates, in addition to the gradient information of the similarity between the feature amount of the first information and the feature amount of the second information, gradient information of the similarity between the feature amount of the first information and the feature amount of third information. The perturbation application position determination means determines the element to which the perturbation is to be applied based on the gradient information of the similarity between the feature amount of the first information and the feature amount of the second information and the gradient information of the similarity between the feature amount of the first information and the feature amount of third information. The information processing apparatus according to any one of claims 1 to 6.
8. The perturbation application position determination means determines an element to which perturbation is to be applied using at least one of a product, a weighted sum, and a sum of absolute values of gradient information of a similarity between a feature amount of the first information and a feature amount of the second information and gradient information of a similarity between the feature amount of the first information and a feature amount of the third information. The information processing apparatus according to claim 7.
9. By at least one computer, calculate a similarity between a feature amount of first information and a feature amount of second information; calculate gradient information indicating a gradient of the similarity; determine an element to which perturbation is to be applied in the first information based on the gradient information; apply perturbation to the element to which perturbation is to be applied in the first information; evaluate a risk in the authentication process based on a result of an authentication process of collating the first information to which the perturbation has been applied and the second information. An information processing method.
10. To at least one computer, calculate a similarity between a feature amount of first information and a feature amount of second information; calculate gradient information indicating a gradient of the similarity; determine an element to which perturbation is to be applied in the first information based on the gradient information; apply perturbation to the element to which perturbation is to be applied in the first information; evaluate a risk in the authentication process based on a result of an authentication process of collating the first information to which the perturbation has been applied and the second information. A computer program for causing a computer to execute the information processing method.
Citation Information
Patent Citations
Network model training method, information pushing method and related devices
CN112434213A
Pedestrian re-recognition attack method based on heat map attention mechanism and frequency domain analysis
CN113792729A
Anti-face recognition method and system based on adversarial attack
CN113869152A
Convolutional neural network-based adversarial sample defense method
CN114049537A
Protecting cognitive systems from gradient-based attacks via the use of deceptive gradients
JP2021501414A