Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

127 results about "Attack model" patented technology

In cryptanalysis, attack models or attack types are a classification of cryptographic attacks specifying the kind of access a cryptanalyst has to a system under attack when attempting to "break" an encrypted message (also known as ciphertext) generated by the system. The greater the access the cryptanalyst has to the system, the more useful information he can get to utilize for breaking the cypher.

Elastic distributed Nash equilibrium search method and device under FDI attack

PendingCN120546911AArtificial lifeInference methodsSearch problemAttack model
The invention discloses an elastic distributed Nash equilibrium search method and device under FDI attack, and relates to the technical field of non-cooperative game decision, the method comprises the following steps: constructing a multi-agent network, forming a non-cooperative game, and defining an objective function of each agent in the multi-agent network; establishing a malicious FDI attack model; the malicious FDI attack model maps false data injection attack to control input of an agent; an elastic self-adaptive distributed Nash equilibrium search algorithm is designed based on the target function, so that behaviors of other intelligent agents are estimated under the condition that the intelligent agents cannot obtain global information and attack information; the elastic self-adaptive distributed Nash equilibrium search algorithm comprises a leader-follower consistent consensus estimation-based identifier signal designed by an observer and a self-adaptive dynamic gain part. The elastic self-adaptive distributed Nash equilibrium search method solves the problem of elastic self-adaptive distributed Nash equilibrium search when the non-cooperative game is attacked by unknown FDI.
Owner:BEIHANG UNIV

Heterogeneous cluster hybrid attack defense control method and system oriented to urban confrontation environment, terminal equipment and medium

The invention discloses a hybrid attack defense control method and system for a heterogeneous cluster in an urban confrontation environment, terminal equipment and a medium, and relates to the technical field of unmanned platform cluster control, and the method comprises the steps: constructing an ideal system model of an unmanned platform cluster comprising a leader and a plurality of followers, constructing an information physical hybrid attack model based on the model; using the attack model to simulate an attack behavior of an attacker on an ideal system to obtain an attacked system model; based on an attacked system model, constructing a distributed elastic security estimator with a compensation mechanism, compensating attack influence for each follower and estimating an expected position; and based on the expected position of the follower, constructing a distributed elastic safety controller with a compensation mechanism, and controlling the follower. By designing the estimator and the controller, attack interference is counteracted, control input is generated, and safe collaboration of the heterogeneous nonlinear unmanned cluster under the cyber-physical hybrid attack is guaranteed.
Owner:BEIJING INST OF TECH

Large model security protection method and device, equipment and storage medium

The invention relates to the technical field of artificial intelligence, and discloses a large model security protection method, device and equipment and a storage medium, the method comprises the following steps: generating an attack data set through a preset attack model, the preset attack model being a model pre-trained based on a true harmful query statement, the true harmful query statements are query statements obtained by screening the query statements to be distinguished through an evaluation model, and the evaluation model is a large language model used for distinguishing whether the query statements are true harmful or not; constructing a security protection rule based on the attack data set, and performing security protection on the large model according to the security protection rule; the attack data set is generated by the preset attack model, the preset attack model is obtained by training the true harmful query statements, and the true harmful query statements are screened from the to-be-distinguished query statements through the large language model, so that the quality and the coverage range of the attack data set can be improved; and the safety protection effect of the large model can be improved.
Owner:BEIJING QIHOOD TECHNOLOGY CO LTD

Dynamic event trigger fault detection method under DoS network attack

The invention relates to the technical field of network detection, and provides a dynamic event trigger fault detection method under DoS network attack, which comprises the following steps: establishing a linear state space model of a network control system; defining a non-attack interval and an attack interval of system operation, and constraining attack frequency and duration; the observer gain is switched according to the current non-attack interval or attack interval of the system; a dynamic event triggering mechanism is constructed, and the triggering condition depends on the output state and the internal dynamic variable of the full-order switching observer and is used for dynamically adjusting the data transmission frequency; establishing a closed-loop switching system model; and analyzing system index stability according to the closed-loop switching system model, and cooperatively designing observer gain, controller gain and event triggering parameters. According to the invention, through quantification of the DoS attack model, the dynamic event triggering mechanism and collaborative optimization design, the effects of effectively detecting the system fault and improving the utilization rate of the network channel are achieved.
Owner:GUANGZHOU UNIVERSITY

Backdoor attack method and system for classification task in code model

Disclosure are a backdoor attack method and system for a classification task in a code model, the method includes: S1. collecting and preprocessing clean samples to obtain importance variable names; S2. classifying the variable names of the clean samples according to label categories to obtain a plurality of trigger sets; and selecting target labels from the clean samples; S3. performing score calculation on the variable names in the trigger sets corresponding to the target labels; replacing one importance variable name with the variable name having a maximum C score in the clean samples to obtain poisoned samples, and repeating the above process until the labels are changed into the target labels; and S4. randomly inserting the triggers in the poisoned samples into the clean samples to form negative samples; and performing an attack by using an attack model obtained based on the negative, poisoned and clean samples.
Owner:YANGZHOU UNIV

Privacy training data leakage risk black box detection method and device for classification model

The invention discloses a classification model privacy disclosure risk black box detection method and device, and relates to the technical field of machine learning security, and the method comprises the steps: constructing an auxiliary data set; generating an auxiliary model covering different privacy risk levels; training a shadow model and a black box member reasoning attack model corresponding to the shadow model; evaluating the privacy risk score of each auxiliary model by using the attack model, and labeling a high-risk / low-risk label; calculating a correction prediction entropy difference, and screening the first k samples with the maximum difference to form a query data set; extracting a prediction result of each auxiliary model on the query set, calculating and correcting a prediction entropy and a mean value, a variance, a kurtosis and a skewness thereof, and splicing into a k + 4-dimensional risk feature vector; training a risk detection classifier; similar features of the model to be detected are extracted and input into the classifier, and the classifier performs five-level privacy disclosure risk level mapping according to the final risk probability prediction value and outputs the five-level privacy disclosure risk level mapping. The method is mainly applied to risk assessment of classification models in high-privacy sensitive fields such as financial credit investigation and medical diagnosis.
Owner:BEIHANG UNIV

Multi-agent system safety convergence control method based on dual-channel adaptive event triggering

The invention discloses a multi-agent system safety convergence control method based on dual-channel adaptive event triggering, and the method comprises the steps: firstly building a multi-agent system mathematical model, and designing a controller of each agent in a multi-agent system based on the multi-agent system mathematical model; secondly, establishing a sequence scaling attack model, and combining the sequence scaling attack model to a controller of an intelligent agent; and then designing an event trigger controller based on the controller of the intelligent agent containing the sequence scaling attack. And then, based on the event triggering controller, safety convergence control is carried out, and multi-agent control in the multi-agent system is completed. According to the method, malicious network attacks can be effectively resisted, the problem of limited bandwidth resources can be solved, and the applicability and the application range are improved and expanded.
Owner:HANGZHOU DIANZI UNIV

Power grid continuous information attack defense method, system and device based on node coupling degree and medium

The invention relates to the technical field of intelligent power distribution networks, and discloses a node coupling degree-based power grid continuous information attack defense method, system and device and a medium, and the method comprises the steps: through the representation and analysis of the coupling degree, the damage degree of various fault conditions to a power distribution network can be evaluated more accurately. In the aspect of attack defense, a continuous information attack model is constructed, the model not only considers division of a security area and configuration of electronic security perimeter equipment, but also combines related factors such as defense equipment types and the number of operation and maintenance personnel, and comprehensively depicts the process and strength of information attack. Therefore, formulation of a defense strategy is more targeted and effective, and proper defense measures can be taken according to different attack scenes and node coupling conditions. Meanwhile, by testing the defense strategy, the defense scheme can be continuously optimized and perfected, and the toughness of the power grid CPS to malicious information attacks is improved.
Owner:GUIZHOU POWER GRID CO LTD

Large model output data security detection method and system based on adversarial attack

The invention discloses a large model output data security detection method and system based on adversarial attacks. The method comprises the following steps: constructing and optimizing a strategy space containing a plurality of attack strategies, and grading and sorting the strategies to improve the attack efficiency; generating a single-strategy antagonism prompt by the attack model according to the optimized strategy space, and performing effectiveness evaluation and feedback correction on the prompt by the judgment model; inputting a prompt passing the evaluation into the target large model to obtain a response, and performing malicious degree scoring on the response by the judgment model; and if the single-strategy attack is not successful, introducing an optimization mechanism based on a genetic algorithm, generating a more complex multi-strategy antagonism prompt through strategy variation and crossover, and carrying out iterative attack until the target large model is successfully broken into the prison. According to the method, the security defects of the large model can be efficiently and comprehensively detected in a self-adaptive and multi-strategy attack mode.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Method and device for determining initial fault line combination of power system considering cascading failure propagation, electronic equipment and storage medium

The invention discloses a method and device for determining an initial fault line combination of a power system considering cascading failure propagation, electronic equipment and a storage medium, and belongs to the technical field of power system fault recognition. The method comprises the following steps: constructing an attack and defense double-layer optimization model comprising an upper-layer attack model and a lower-layer defense model, wherein the upper-layer attack model aims at maximizing the load loss value, and the lower-layer defense model aims at minimizing the load loss value; the method comprises the following steps of: randomly generating a plurality of candidate fault line combinations containing a preset number of fault lines, respectively simulating a cascading fault propagation process caused by the candidate fault line combinations, obtaining a power grid working condition after a fault is ended, and calculating a load loss value of each candidate combination by utilizing a lower-layer defense model; and selecting the candidate fault line combination with the maximum load loss value as an initial fault line combination of the power system. By implementing the method, the problem that the initial fault line combination of the power system is not accurately determined in the prior art can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGDONG POWER GRID CO LTD

Gateway test method, system and equipment based on artificial intelligence

The invention discloses a gateway test method, system and equipment based on artificial intelligence, and the method comprises the steps: building and training a reinforcement learning attack model according to a test demand, and enabling the reinforcement learning attack model to take a test target as input and a DDoS attack scheme for the test target as output; according to a received DDoS defense test request of a target gateway, obtaining a target DDoS attack scheme for the target gateway through the reinforcement learning attack model; performing a DDoS attack test on the target gateway according to the target DDoS attack scheme to obtain test data of the target gateway; and analyzing the test data according to the test data to obtain a test result of the target gateway. The problems that in the prior art, diversified and highly-real DDoS attack testing means are lacked, and more intelligent defense evaluation cannot be carried out for a complex network environment are at least solved.
Owner:SICHUAN TIANYI COMHEART TELECOM

Network attack optimization method and system for information physical system of power distribution network

The invention relates to the field of power distribution network system protection, and discloses a power distribution network cyber-physical system network attack optimization method which comprises the following steps: S1, establishing an upper-layer attack model which is used for simulating a decision of an attacker for causing the maximum load loss under the constraint of limited attack resources; s2, establishing a lower-layer rescheduling model, wherein the lower-layer rescheduling model is used for simulating a response decision taking minimization of load shedding loss and scheduling cost as targets after a power distribution network dispatcher is attacked; and S3, constructing an attack and defense double-layer optimization model combining the upper-layer attack model and the lower-layer rescheduling model. Through sequential logic based on attack and defense, the first stage starts from the perspective of attackers to maximize attack consequences and minimize attack cost, and the second stage minimizes scheduling and operation cost from the perspective of dispatchers to guarantee power supply of key users, so that the influence of network attacks on the power distribution network is comprehensively and accurately evaluated.
Owner:NORTH CHINA ELECTRIC POWER UNIV

Network intrusion detection method, device and equipment

The invention provides a network intrusion detection method, device and equipment, belongs to the technical field of network security, and solves the problems that a traditional network intrusion detection method is insufficient in cross-modal feature fusion, weak in complex attack modeling capability and poor in adaptive capability. The method comprises the following steps: acquiring network flow data; preprocessing the network traffic data to obtain a traffic data packet; performing feature extraction on the traffic data packet to obtain a multi-modal feature set; performing point-line analysis processing on the multi-modal feature set to obtain heterogeneous graph data; inputting the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector; and determining intrusion type data according to the graph-level feature vector. According to the scheme, the detection accuracy of diversified attacks is improved, the structure perception capability of complex attacks is enhanced, and the robustness and generalization are improved.
Owner:ZHENGZHOU UNIVERSITY OF AERONAUTICS +1

Security alarm information processing method and device based on multi-agent cooperation

The invention discloses a security alarm information processing method and device based on multi-agent cooperation, and relates to the technical field of honey point alarms, and the method comprises the steps: obtaining an original alarm flow from a honey point management module, and carrying out the preprocessing of the original alarm flow, and obtaining an alarm set; pushing the alarm set to an alarm noise reduction agent so as to filter false alarm information through a large language model noise reducer, then transmitting the false alarm information to a priority marker to endow the alarm set with a corresponding priority mark, and storing the marked alarm set into a historical alarm database; and pushing the alarm set to an attack model agent to generate an attack hypothesis through an attack mapping large language model, transmitting the attack hypothesis to an attack path backtracking engine, querying a historical alarm database to obtain associated historical attack data, and generating a corresponding analysis report after constructing a specific attack path. According to the invention, the problem of low safety alarm information analysis efficiency and accuracy in the prior art is solved.
Owner:POWERCHINA JIANGXI ELECTRIC POWER ENGINEERING CO LTD

Multi-round jailbreak attack defense training method and device for large language model

The invention discloses a multi-round jailbreak attack defense training method and device for a large language model. The method comprises the steps that an attack model used for generating query statements and a victim model used for providing response statements are constructed; utilizing an attack model to extract harmful targets of the plurality of received jailbreak prompt words, and generating a clue data set; constructing a clue tree based on the clue data set, and determining a plurality of paths of the clue tree, thereby generating a plurality of inquiry chains through iteration of the plurality of paths by using an attack model; inquiring the victim model by using each inquiry chain, determining unsafe response statements in a plurality of response statements generated by the victim model, and generating a plurality of question and answer chains based on each unsafe response statement and the corresponding inquiry statement; and based on the plurality of question and answer chains and historical dialogue information extracted from the target model, constructing a security training data set, and training the target model by using the security training data set.
Owner:BEIHANG UNIV

A method for imperceptible watermark attack based on transformer and prompt guidance

The application provides a kind of based on Transform and prompt guide imperceptible watermark attack method, belongs to digital information security technical field.Method includes: through existing data set and QPHFMs watermark algorithm construction training data set, adjusts the size of original watermark image and original non-watermark image containing uniformly, obtains standardization training data;Imperceptible watermark attack network TFP-WAN containing Transform encoder-decoder framework and dynamic prompt module is constructed, dynamic prompt module includes PGM and PIM;MAE is used as loss function in TFP-WAN;Standardization training data is input into TFP-WAN and iteratively trained until reaching preset iteration number, and the watermark attack model of training completion is obtained;The image after attack is output after inputting the watermark image to be attacked into watermark attack model.The application realizes the attack to robust watermark algorithm with higher error rate.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES)

Model poisoning defense method, electronic equipment and readable storage medium

The embodiment of the invention provides a model poisoning defense method, electronic equipment and a readable storage medium. The method relates to the field of distributed training, and comprises the following steps: acquiring a first model trained by adjacent participants and first similarity information maintained by the adjacent participants; determining a second similarity between a target model trained by the target participant and the first model; according to the first similarity and the second similarity, performing credibility evaluation on whether the first model is subjected to the poisoning attack to obtain a credibility evaluation result of the first model; determining a model aggregation mode of the first model and the target model based on the credibility evaluation result; and according to the model aggregation mode, performing model aggregation processing on the target model and the first model to obtain an aggregated target model. According to the method and the device, the technical problem that the performance of the aggregated global model is reduced due to the fact that the attacked model is difficult to distinguish by related technologies for completely decentralized distributed training and then through a model aggregation process is solved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

System and method for inferring attacks on a sequence recommendation system

The application discloses a kind of inference system and method for sequence recommendation system member inference attack, including label data generation module, difference feature construction module and attack model training module;Step 1, label data generation is carried out;Step 2, the difference feature construction of member and non-member is carried out;Step 3, the training of attack model is carried out.Compared with prior art, the application can guarantee the data privacy of user in a wider range of scenarios;Fill in the blank of member inference attack in more stringent scenarios;Significantly improve the attack inference effect.
Owner:TIANJIN UNIV

Attack method, device and equipment of decentralized federated learning system and medium

The application relates to the technical field of federated learning, and discloses an attack method, device, equipment and medium for a decentralized federated learning system. The method comprises the following steps: connecting the network identifier of a malicious client and the network identifier of each benign client to obtain a communication graph; restoring the image proportion of each benign client according to the gradient information of each benign client, determining state data in a simulation environment based on the image proportion of each benign client and the communication graph; determining a current attack model in the simulation environment based on a reinforcement learning mode and the state data; obtaining the loss value of each benign client in the tth round of training and the loss value of each benign client in the next round of training based on the current attack model; and determining an attack report of the decentralized federated learning system based on attack benefits. Through the attack report, the attack mode can be identified, and the anti-attack capability of the decentralized federated learning system can be improved.
Owner:湖南工商大学

A sliding mode fault-tolerant control method for high-temperature forging dynamic three-dimensional measurement

The application discloses a kind of high-temperature forging dynamic three-dimensional measurement-oriented sliding mode fault-tolerant control methods, and specific implementation steps include: establishing the discrete-time singular perturbation Markov jump state space model of high-temperature forging measurement system;Design probability dynamic event trigger mechanism, utilize internal dynamic variable intelligent judgment data transmission time to save bandwidth resources;For possible fraud attacks and actuator failure, build the corresponding attack model and fault model;Sliding surface and sliding control rate function are constructed;Deduce the sufficient condition for guaranteeing system reachability and closed-loop system finite time boundedness;Iterative solution controller gain and dynamic trigger parameters.The application considers network security, resource-constrained and actuator degradation and other multiple constraints under the high-temperature forging dynamic three-dimensional measurement scene, while guaranteeing the system finite time stability, significantly improves the robust cooperative control ability and operation safety of measurement system.
Owner:QINGDAO UNIV OF TECH

Side channel protection method and device based on noise disturbance, equipment and medium

The invention relates to the technical field of encrypted transmission, and discloses a side channel protection method and device based on noise disturbance, equipment and a medium. The method comprises the following steps: performing iterative training on disturbance to be adjusted according to a preset disturbance discrimination model to obtain expected disturbance with unlearnable characteristics; converting the desired perturbations into guard noise that can be generated by the cryptographic device; determining a data acquisition mode for the side channel; when the data acquisition mode is a training stage, determining an encryption state of the password device, and generating a target type of protection noise according to the encryption state; and when the data acquisition mode is an attack stage, controlling the password device to stop generating the protection noise. According to the method and the device, the expected disturbance of the unlearnable characteristic is added in the training stage of the side channel attack model, so that the training effect of the side channel attack model is interfered, the attack of the side channel attack model fails in the attack stage, and the protection effect and the security are remarkably improved.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Cyber-physical system hazard assessment method and system superimposed with new energy fluctuation and data injection attack

The present application relates to a kind of new energy fluctuation and data injection attack superimposed cyber-physical fusion hazard evaluation method and system, wherein the method comprises the following steps: constructing new energy fluctuation and data injection attack superimposed attack model, attack model introduces data injection attack vector and the change vector caused by new energy output uncertainty in line flow;Through the calculation of line load security constraint, determine the cyber-physical fusion hazard under new energy fluctuation and data injection attack superposition based on attack model.Compared with the prior art, the present application can determine the worst case by new energy output uncertainty and malicious data attack superposition caused by power grid ontology hazard level, can help operation and maintenance personnel to find the key risk node in power system.
Owner:SHANGHAI JIAOTONG UNIV

Adversarial sample generation method and evaluation method for evaluating robustness of AIGI detector

The invention discloses an adversarial sample generation method and an evaluation method for robustness evaluation of an AIGI detector, and relates to the technical field of robustness evaluation. A pre-trained substitution model is selected and comprises a feature extractor and a classifier, K additional models are added behind the feature extractor in parallel, and a Bayesian model is constructed and used for simulating an attacked model; performing frequency domain attack on the Bayesian model by using the adversarial sample, during each attack, adding disturbance to the spatial domain of the original adversarial sample, converting the original adversarial sample from the spatial domain to the frequency domain, performing random spectrum transformation, and according to an attack optimization target, calculating a frequency domain gradient for updating the adversarial sample; furthermore, the frequency domain attack and the space domain attack are mixed, the space domain gradient is calculated during each attack, the frequency domain gradient and the space domain gradient are added and averaged to obtain a uniform gradient direction, the gradient direction is used to update the adversarial sample, and the final adversarial sample is obtained after the set iteration attack times. According to the method, an adversarial sample is generated by using a frequency-based post-training Bayesian attack (FPBA), so that high-quality attacks with certain generalization ability are performed on the AIGI detector, and the robustness of the AIGI detector is evaluated under white-box attacks and black-box attacks.
Owner:HEFEI UNIV OF TECH

Multi-agent SAC beam forming optimization method and system for secure communication

The invention belongs to the technical field of communication security, and particularly relates to a multi-agent SAC beam forming optimization method and system for security communication. Comprising the steps of constructing a communication system model; considering that the malicious node has two intelligent behavior modes of sleep and eavesdropping, constructing an attack model; deriving a key generation rate and a data transmission rate, and generating a joint optimization problem of the key generation rate and the data transmission rate; a friendly node is set, channel information provided by the friendly node is utilized, and a malicious node eavesdropping channel and behavior are predicted through LSTM; a multi-agent SAC algorithm is introduced, eavesdropping channels and behaviors of malicious nodes predicted by LSTM are integrated, beam forming vectors in the joint optimization problem are cooperatively optimized, and an optimal beam forming strategy is obtained. According to the method, a unified beam forming optimization framework is constructed, dynamic evaluation and suppression of eavesdropping risks are realized under the condition of partial observable channels, and the joint security of two legal communication parties in key generation and data transmission is improved.
Owner:SHANDONG UNIV

ICPS comprehensive security control method and system based on time delay detection under multi-source hybrid attack

The invention discloses an ICPS comprehensive security control method and system based on time delay detection under multi-source hybrid attack, and relates to the technical field of ICPS security control. The method comprises the following steps: constructing a multi-source mixed attack model in which DoS attack and FDI attack coexist; under the driving of the D-ADETCS, an ICPS comprehensive security control strategy suffering from the multi-source mixed attack and the actuator fault at the same time is designed, specifically, the data security state of the ICPS is diagnosed by monitoring the data transmission delay of the ICPS, and a corresponding data compensator and a data restorer are called according to the diagnosis result, so that active intrusion tolerance control over the multi-source mixed attack is achieved; and based on the compensated / repaired data, designing a robust observer and a comprehensive safety controller by using a mechanism analysis method so as to realize passive intrusion tolerance control on the multi-source mixed attack and active fault tolerance control on the actuator fault. The method has good mobility and adaptability, is verified on typical experiment platforms such as a four-container water tank and can also be popularized to more complex industrial scenes.
Owner:LANZHOU UNIVERSITY OF TECHNOLOGY

Backdoor attack method, system, storage medium and device based on large model

The application provides a large model-based backdoor attack method, system, storage medium and equipment. A tokenizer and a known corpus of an attacked model are obtained, a set of candidate words is integrated by selecting adverbs in the known corpus; each adverb in the set of candidate words is converted into a word unit sequence composed of several basic word units; a tail word unit and a preset specific word unit are combined into a trigger combination, and the frequency of the trigger combination in the original training set is counted; when the frequency of the trigger combination is less than a first threshold value and the number of word units ending with the tail word unit is not less than a second threshold value, the corresponding adverb is added to a trigger substructure set; a data training set is constructed, the data training set includes a dirty training set, the input of the sample in the dirty training set contains the trigger combination, and the output of the sample in the dirty training set is an attack result; and the attacked model is trained by using the data training set. The problem of insufficient concealment of the trigger used for attack in the large model is solved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Denial of service attack strategy making method for consistency control of multi-agent system

The DoS attack strategy making method based on the multilayer cut points is provided for consistency control of the multi-agent system, and the state consistency of the multi-agent system is effectively influenced under the condition that it is guaranteed that the attacker consumes relatively little energy. The method comprises the steps that a multi-agent system consistency model and a DoS attack model are established, an objective function is obtained by taking energy consumption of an attacker and a system consistency error as two indexes, multi-layer cut points are used for replacing an attack action space to improve the optimization efficiency of the objective function, and an attack strategy is obtained by optimizing the objective function. The attack research essence is to guarantee the improvement of the system security performance, and the method provided by the invention can be used as a link for testing the system security to help discover the defects in the aspect of system defense.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Black-box model inversion attack method and device for text classification model

The application relates to a black box model inversion attack method and device for a text classification model, wherein the method comprises the following steps: extracting a text sequence beginning fragment in a public data set, and constructing an auxiliary data set according to the text sequence beginning fragment; taking the text sequence beginning fragment in the auxiliary data set as a query to access an attack model, generating a complete text sequence, scoring the complete text sequence, obtaining a text sequence score satisfying a preset maximization condition, taking the text sequence score satisfying the preset maximization condition as a target to iteratively optimize parameters of the attack model, and generating a trained attack model; generating a text sequence-score pair set by using the trained attack model; based on the text sequence-score pair set, filtering out a text sequence greater than or equal to a preset score threshold, and generating a final inversion attack result of the attack model according to the text sequence. Therefore, the problems of few sources of model inversion attack information and high attack difficulty of the model inversion attack on the text classification model in a black box scenario are solved.
Owner:BEIHANG UNIV

Graph federal learning privacy auditing method based on label preference reasoning

The invention relates to the technical field of information security, in particular to a graph federal learning privacy auditing method based on label preference reasoning. Comprising the following steps: S1, a server trains an attack model by using an auxiliary data set; s2, carrying out the t-th round of training, and uploading a local model; s3, the server calculates the model sensitivity of each client; s4, the server executes aggregation according to a calculation result in the step S3; s5, the server sends the aggregation models respectively; s6, carrying out the (t + 1) th round of training, and uploading the local model; s7, calculating the model sensitivity of the (t + 1) th round of the target client; s8, the server calculates the model sensitivity based on the aggregation models in the steps S4 and S7; calculating the sensitivity difference DMS of the two models; and S9, inputting the DMS into the attack model, and reasoning to obtain the label preference of the target client. According to the method, the accuracy of label reasoning can be remarkably improved, and potential privacy disclosure risks in the FGL system can be quantitatively evaluated as an effective privacy auditing mechanism.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Method and device for gray-box adversarial attack on learning model

The present disclosure relates to a method and device for a gray-box adversarial attack on a learning model, and more specifically to a method and device for performing a gray-box adversarial attack on a learning model generated by semi-supervised learning. According to an embodiment, a method for attacking a main model, performed by a computing device may include: training an attack model using shared labeled data; performing an attack on the attack model to generate an adversarial example; and inputting the adversarial example to the main model to induce an inference about the adversarial example.
Owner:POSTECH ACADEMY INDUSTRY FOUNDATION