Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

80 results about "Attack model" patented technology

In cryptanalysis, attack models or attack types are a classification of cryptographic attacks specifying the kind of access a cryptanalyst has to a system under attack when attempting to "break" an encrypted message (also known as ciphertext) generated by the system. The greater the access the cryptanalyst has to the system, the more useful information he can get to utilize for breaking the cypher.

Heterogeneous cluster hybrid attack defense control method and system oriented to urban confrontation environment, terminal equipment and medium

The invention discloses a hybrid attack defense control method and system for a heterogeneous cluster in an urban confrontation environment, terminal equipment and a medium, and relates to the technical field of unmanned platform cluster control, and the method comprises the steps: constructing an ideal system model of an unmanned platform cluster comprising a leader and a plurality of followers, constructing an information physical hybrid attack model based on the model; using the attack model to simulate an attack behavior of an attacker on an ideal system to obtain an attacked system model; based on an attacked system model, constructing a distributed elastic security estimator with a compensation mechanism, compensating attack influence for each follower and estimating an expected position; and based on the expected position of the follower, constructing a distributed elastic safety controller with a compensation mechanism, and controlling the follower. By designing the estimator and the controller, attack interference is counteracted, control input is generated, and safe collaboration of the heterogeneous nonlinear unmanned cluster under the cyber-physical hybrid attack is guaranteed.
Owner:BEIJING INST OF TECH

Dynamic event trigger fault detection method under DoS network attack

The invention relates to the technical field of network detection, and provides a dynamic event trigger fault detection method under DoS network attack, which comprises the following steps: establishing a linear state space model of a network control system; defining a non-attack interval and an attack interval of system operation, and constraining attack frequency and duration; the observer gain is switched according to the current non-attack interval or attack interval of the system; a dynamic event triggering mechanism is constructed, and the triggering condition depends on the output state and the internal dynamic variable of the full-order switching observer and is used for dynamically adjusting the data transmission frequency; establishing a closed-loop switching system model; and analyzing system index stability according to the closed-loop switching system model, and cooperatively designing observer gain, controller gain and event triggering parameters. According to the invention, through quantification of the DoS attack model, the dynamic event triggering mechanism and collaborative optimization design, the effects of effectively detecting the system fault and improving the utilization rate of the network channel are achieved.
Owner:GUANGZHOU UNIVERSITY

Privacy training data leakage risk black box detection method and device for classification model

The invention discloses a classification model privacy disclosure risk black box detection method and device, and relates to the technical field of machine learning security, and the method comprises the steps: constructing an auxiliary data set; generating an auxiliary model covering different privacy risk levels; training a shadow model and a black box member reasoning attack model corresponding to the shadow model; evaluating the privacy risk score of each auxiliary model by using the attack model, and labeling a high-risk / low-risk label; calculating a correction prediction entropy difference, and screening the first k samples with the maximum difference to form a query data set; extracting a prediction result of each auxiliary model on the query set, calculating and correcting a prediction entropy and a mean value, a variance, a kurtosis and a skewness thereof, and splicing into a k + 4-dimensional risk feature vector; training a risk detection classifier; similar features of the model to be detected are extracted and input into the classifier, and the classifier performs five-level privacy disclosure risk level mapping according to the final risk probability prediction value and outputs the five-level privacy disclosure risk level mapping. The method is mainly applied to risk assessment of classification models in high-privacy sensitive fields such as financial credit investigation and medical diagnosis.
Owner:BEIHANG UNIV

Large model output data security detection method and system based on adversarial attack

The invention discloses a large model output data security detection method and system based on adversarial attacks. The method comprises the following steps: constructing and optimizing a strategy space containing a plurality of attack strategies, and grading and sorting the strategies to improve the attack efficiency; generating a single-strategy antagonism prompt by the attack model according to the optimized strategy space, and performing effectiveness evaluation and feedback correction on the prompt by the judgment model; inputting a prompt passing the evaluation into the target large model to obtain a response, and performing malicious degree scoring on the response by the judgment model; and if the single-strategy attack is not successful, introducing an optimization mechanism based on a genetic algorithm, generating a more complex multi-strategy antagonism prompt through strategy variation and crossover, and carrying out iterative attack until the target large model is successfully broken into the prison. According to the method, the security defects of the large model can be efficiently and comprehensively detected in a self-adaptive and multi-strategy attack mode.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Method and device for determining initial fault line combination of power system considering cascading failure propagation, electronic equipment and storage medium

The invention discloses a method and device for determining an initial fault line combination of a power system considering cascading failure propagation, electronic equipment and a storage medium, and belongs to the technical field of power system fault recognition. The method comprises the following steps: constructing an attack and defense double-layer optimization model comprising an upper-layer attack model and a lower-layer defense model, wherein the upper-layer attack model aims at maximizing the load loss value, and the lower-layer defense model aims at minimizing the load loss value; the method comprises the following steps of: randomly generating a plurality of candidate fault line combinations containing a preset number of fault lines, respectively simulating a cascading fault propagation process caused by the candidate fault line combinations, obtaining a power grid working condition after a fault is ended, and calculating a load loss value of each candidate combination by utilizing a lower-layer defense model; and selecting the candidate fault line combination with the maximum load loss value as an initial fault line combination of the power system. By implementing the method, the problem that the initial fault line combination of the power system is not accurately determined in the prior art can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGDONG POWER GRID CO LTD

Multi-round jailbreak attack defense training method and device for large language model

The invention discloses a multi-round jailbreak attack defense training method and device for a large language model. The method comprises the steps that an attack model used for generating query statements and a victim model used for providing response statements are constructed; utilizing an attack model to extract harmful targets of the plurality of received jailbreak prompt words, and generating a clue data set; constructing a clue tree based on the clue data set, and determining a plurality of paths of the clue tree, thereby generating a plurality of inquiry chains through iteration of the plurality of paths by using an attack model; inquiring the victim model by using each inquiry chain, determining unsafe response statements in a plurality of response statements generated by the victim model, and generating a plurality of question and answer chains based on each unsafe response statement and the corresponding inquiry statement; and based on the plurality of question and answer chains and historical dialogue information extracted from the target model, constructing a security training data set, and training the target model by using the security training data set.
Owner:BEIHANG UNIV

A method for imperceptible watermark attack based on transformer and prompt guidance

The application provides a kind of based on Transform and prompt guide imperceptible watermark attack method, belongs to digital information security technical field.Method includes: through existing data set and QPHFMs watermark algorithm construction training data set, adjusts the size of original watermark image and original non-watermark image containing uniformly, obtains standardization training data;Imperceptible watermark attack network TFP-WAN containing Transform encoder-decoder framework and dynamic prompt module is constructed, dynamic prompt module includes PGM and PIM;MAE is used as loss function in TFP-WAN;Standardization training data is input into TFP-WAN and iteratively trained until reaching preset iteration number, and the watermark attack model of training completion is obtained;The image after attack is output after inputting the watermark image to be attacked into watermark attack model.The application realizes the attack to robust watermark algorithm with higher error rate.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES)

System and method for inferring attacks on a sequence recommendation system

The application discloses a kind of inference system and method for sequence recommendation system member inference attack, including label data generation module, difference feature construction module and attack model training module;Step 1, label data generation is carried out;Step 2, the difference feature construction of member and non-member is carried out;Step 3, the training of attack model is carried out.Compared with prior art, the application can guarantee the data privacy of user in a wider range of scenarios;Fill in the blank of member inference attack in more stringent scenarios;Significantly improve the attack inference effect.
Owner:TIANJIN UNIV

A sliding mode fault-tolerant control method for high-temperature forging dynamic three-dimensional measurement

The application discloses a kind of high-temperature forging dynamic three-dimensional measurement-oriented sliding mode fault-tolerant control methods, and specific implementation steps include: establishing the discrete-time singular perturbation Markov jump state space model of high-temperature forging measurement system;Design probability dynamic event trigger mechanism, utilize internal dynamic variable intelligent judgment data transmission time to save bandwidth resources;For possible fraud attacks and actuator failure, build the corresponding attack model and fault model;Sliding surface and sliding control rate function are constructed;Deduce the sufficient condition for guaranteeing system reachability and closed-loop system finite time boundedness;Iterative solution controller gain and dynamic trigger parameters.The application considers network security, resource-constrained and actuator degradation and other multiple constraints under the high-temperature forging dynamic three-dimensional measurement scene, while guaranteeing the system finite time stability, significantly improves the robust cooperative control ability and operation safety of measurement system.
Owner:QINGDAO UNIV OF TECH

Multi-agent SAC beam forming optimization method and system for secure communication

The invention belongs to the technical field of communication security, and particularly relates to a multi-agent SAC beam forming optimization method and system for security communication. Comprising the steps of constructing a communication system model; considering that the malicious node has two intelligent behavior modes of sleep and eavesdropping, constructing an attack model; deriving a key generation rate and a data transmission rate, and generating a joint optimization problem of the key generation rate and the data transmission rate; a friendly node is set, channel information provided by the friendly node is utilized, and a malicious node eavesdropping channel and behavior are predicted through LSTM; a multi-agent SAC algorithm is introduced, eavesdropping channels and behaviors of malicious nodes predicted by LSTM are integrated, beam forming vectors in the joint optimization problem are cooperatively optimized, and an optimal beam forming strategy is obtained. According to the method, a unified beam forming optimization framework is constructed, dynamic evaluation and suppression of eavesdropping risks are realized under the condition of partial observable channels, and the joint security of two legal communication parties in key generation and data transmission is improved.
Owner:SHANDONG UNIV

ICPS comprehensive security control method and system based on time delay detection under multi-source hybrid attack

The invention discloses an ICPS comprehensive security control method and system based on time delay detection under multi-source hybrid attack, and relates to the technical field of ICPS security control. The method comprises the following steps: constructing a multi-source mixed attack model in which DoS attack and FDI attack coexist; under the driving of the D-ADETCS, an ICPS comprehensive security control strategy suffering from the multi-source mixed attack and the actuator fault at the same time is designed, specifically, the data security state of the ICPS is diagnosed by monitoring the data transmission delay of the ICPS, and a corresponding data compensator and a data restorer are called according to the diagnosis result, so that active intrusion tolerance control over the multi-source mixed attack is achieved; and based on the compensated / repaired data, designing a robust observer and a comprehensive safety controller by using a mechanism analysis method so as to realize passive intrusion tolerance control on the multi-source mixed attack and active fault tolerance control on the actuator fault. The method has good mobility and adaptability, is verified on typical experiment platforms such as a four-container water tank and can also be popularized to more complex industrial scenes.
Owner:LANZHOU UNIVERSITY OF TECHNOLOGY

Backdoor attack method, system, storage medium and device based on large model

The application provides a large model-based backdoor attack method, system, storage medium and equipment. A tokenizer and a known corpus of an attacked model are obtained, a set of candidate words is integrated by selecting adverbs in the known corpus; each adverb in the set of candidate words is converted into a word unit sequence composed of several basic word units; a tail word unit and a preset specific word unit are combined into a trigger combination, and the frequency of the trigger combination in the original training set is counted; when the frequency of the trigger combination is less than a first threshold value and the number of word units ending with the tail word unit is not less than a second threshold value, the corresponding adverb is added to a trigger substructure set; a data training set is constructed, the data training set includes a dirty training set, the input of the sample in the dirty training set contains the trigger combination, and the output of the sample in the dirty training set is an attack result; and the attacked model is trained by using the data training set. The problem of insufficient concealment of the trigger used for attack in the large model is solved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Denial of service attack strategy making method for consistency control of multi-agent system

The DoS attack strategy making method based on the multilayer cut points is provided for consistency control of the multi-agent system, and the state consistency of the multi-agent system is effectively influenced under the condition that it is guaranteed that the attacker consumes relatively little energy. The method comprises the steps that a multi-agent system consistency model and a DoS attack model are established, an objective function is obtained by taking energy consumption of an attacker and a system consistency error as two indexes, multi-layer cut points are used for replacing an attack action space to improve the optimization efficiency of the objective function, and an attack strategy is obtained by optimizing the objective function. The attack research essence is to guarantee the improvement of the system security performance, and the method provided by the invention can be used as a link for testing the system security to help discover the defects in the aspect of system defense.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Black-box model inversion attack method and device for text classification model

The application relates to a black box model inversion attack method and device for a text classification model, wherein the method comprises the following steps: extracting a text sequence beginning fragment in a public data set, and constructing an auxiliary data set according to the text sequence beginning fragment; taking the text sequence beginning fragment in the auxiliary data set as a query to access an attack model, generating a complete text sequence, scoring the complete text sequence, obtaining a text sequence score satisfying a preset maximization condition, taking the text sequence score satisfying the preset maximization condition as a target to iteratively optimize parameters of the attack model, and generating a trained attack model; generating a text sequence-score pair set by using the trained attack model; based on the text sequence-score pair set, filtering out a text sequence greater than or equal to a preset score threshold, and generating a final inversion attack result of the attack model according to the text sequence. Therefore, the problems of few sources of model inversion attack information and high attack difficulty of the model inversion attack on the text classification model in a black box scenario are solved.
Owner:BEIHANG UNIV

Method and device for gray-box adversarial attack on learning model

The present disclosure relates to a method and device for a gray-box adversarial attack on a learning model, and more specifically to a method and device for performing a gray-box adversarial attack on a learning model generated by semi-supervised learning. According to an embodiment, a method for attacking a main model, performed by a computing device may include: training an attack model using shared labeled data; performing an attack on the attack model to generate an adversarial example; and inputting the adversarial example to the main model to induce an inference about the adversarial example.
Owner:POSTECH ACADEMY INDUSTRY FOUNDATION

Multi-dimensional composite attack model training method and system for electromagnetic signal intelligent modulation identification

The invention discloses a multi-dimensional composite attack model training method and system for electromagnetic signal intelligent modulation identification, and relates to the field of deep learning security. The method comprises the following steps: constructing a benign training set according to an electromagnetic signal, selecting a target category label sample to construct a to-be-poisoning data set, generating a poisoning sample by performing phase rotation and amplitude conversion on a sample constellation diagram feature, and constructing a poisoning data set; selecting a sample different from the target category label to construct a data set of a backdoor trigger to be added, constructing the backdoor trigger according to the sample dimension and adding the backdoor trigger into the sample, and modifying the label to obtain a backdoor data set; and constructing a poisoning training set according to the poisoning data set, the backdoor data set and the benign training set, and training to obtain a poisoning model. According to the method, data poisoning attack and backdoor attack are combined, two attack effects can be achieved at the same time, the prediction accuracy of a benign sample is kept, security vulnerabilities of an electromagnetic signal modulation recognition model can be revealed, and support is provided for formulation of a protection strategy.
Owner:XIDIAN UNIV

Knowledge migration-based split reasoning member reasoning attack method and device

The invention discloses a split reasoning member reasoning attack method and device based on knowledge migration, and the method comprises the steps: extracting part of knowledge of a target model through knowledge migration, and carrying out member reasoning attack on this basis. Specifically, the method comprises the following steps: firstly, constructing a shadow model, and carrying out knowledge migration on the shadow model to obtain a reconstructed shadow model; and then training an attack model by using the plurality of reconstructed shadow models, thereby realizing symmetry between an attack training process and an actual application scene. Then, knowledge migration is carried out on the target model, a plurality of reconstructed target models are generated, information of the reconstructed models is extracted through the attack model, and therefore member reasoning attack is completed. Compared with the prior art, the method has the advantages that the success rate of attacks is remarkably increased through integrated symmetric design of attack model training and actual attacks.
Owner:WUHAN UNIV

A distributed resilient state estimation method and system based on encryption-decryption

This invention provides a distributed resilient state estimation method and system based on encryption-decryption, applied to a discrete-time linear system including at least two sensors. The method includes: establishing a system model based on relevant system parameter information; the parameter information includes at least noise information from a first sensor; when an attacker launches a fake data injection attack, acquiring the system's attacked variable parameters and the fake data injected by the attacker; determining the system's attack model based on the system model, variable parameters, and fake data; processing the attack model based on preset encryption and decryption strategies to obtain processed first data; determining a distributed estimation strategy for the system based on the first data; determining an attack detection model for the system based on the distributed estimation strategy; and when the attack detection model detects a fake data injection attack on the system, determining a resilient state estimation strategy for the system based on the attack detection model.
Owner:WUHAN INST OF TECH

An adversarial training method for improving robustness of a natural language processing model

The application discloses an adversarial training method for improving robustness of a natural language processing model, and comprises the following steps: sending original text into the model for training; generating an adversarial sample of an attack model by using a combination algorithm; and finally adding the adversarial sample into original samples for adversarial training.
Owner:ANHUI UNIV

A side channel black box attack method, device, equipment and storage medium

The application discloses a side channel black box attack method, device and equipment and a storage medium. Side channel information is collected according to a preset first collection scheme, a feature selection model is used to determine feature points of side channel leakage, and a feature vector is generated according to the determined feature points. Training data is collected according to a preset second collection scheme, the training data is cropped according to the feature vector to obtain a training data set, and labels are marked for the training data set. A deep learning model is trained according to the training data set with the marked labels to generate an attack model. Data is collected according to a preset third collection scheme, and an attack data set is generated by cutting according to the feature vector. The attack data set is input into the attack model to generate a probability vector of a key, and a side channel black box attack is completed by taking the key with the highest score as an attack key. Compared with the prior art, the universality of side channel attacks is realized, and the efficiency of side channel attacks is improved.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Dynamic password strength evaluation method for Internet of Things equipment

The invention discloses a dynamic password strength evaluation method for Internet of Things equipment, and relates to the technical field of Internet of Things security, and the method comprises the steps: obtaining a to-be-evaluated target password, carrying out the analysis of the target password, and extracting the basic characteristics of the password; generating initial password strength of the target password based on the password basic characteristics; mapping the initial password strength into attack cost according to context information of equipment corresponding to the target password; obtaining dynamic risk state data in the operation process of the equipment, and dynamically correcting the attack cost to obtain a dynamic password strength evaluation result of the target password; according to the method, probabilistic attack modeling is introduced, and equipment context and dynamic risk correction are combined, so that the problems that existing password strength evaluation is static and is separated from an actual attack environment of the Internet of Things are solved.
Owner:SHANGCE INFORMATION TECH CO LTD

A connected vehicle platoon safety control method and system

The application relates to a kind of networked vehicle platoon safety control method and system, its method includes: obtaining the longitudinal dynamics parameter of the car and the platoon configuration information based on the navigation-following architecture;Build communication attack model based on sensor and vehicle networking;Perform data security transmission protocol: receive the state data share from the front car through multiple communication channels and the corresponding encryption commitment, use the encryption commitment to verify the consistency of the received state data share;Based on the state data share verified, reconstruct the trusted state information of the front car;Use the trusted state information and the attack detection of communication attack model;Based on the trusted state information, the optimal control input of the car is calculated using a predictive control algorithm to drive the car to track the target speed and maintain the desired vehicle distance.The application improves the communication security and control robustness of networked vehicle platoon under false data attack by distributing encrypted state shares and calculating trusted states.
Owner:WUHAN TEXTILE UNIV

A combination optimization solving system and method based on a general attack and defense framework

The application discloses a combination optimization solving system and method based on a general attack and defense framework, belonging to the technical field of combination optimization, and the system comprises a multi-task modeling module, which can model combination optimization problems of different tasks as graph structure representation, and construct a Markov decision process of the graph structure according to the task type; an attack model extracts general graph features through a shared graph encoder, generates disturbances satisfying corresponding task constraints by means of a dedicated decoder and a mask processing of different tasks; and a defense model takes the graph structure and node / edge features as input, generates a decoding sequence that is adaptive to task disturbances and satisfies constraints through a selected target defense solver. The application can effectively identify security vulnerabilities of existing solvers, improve the robustness of the system in the confrontation environment, realize the whole-process coverage from problem discovery to solution through the combination of attack and defense models, and provide a solid security guarantee for industrial application of combination optimization technology.
Owner:CHENGDU UNIV OF INFORMATION TECH

Model processing method, device and equipment

The embodiment of the invention discloses a model processing method, device and equipment, and the method comprises the steps: obtaining attack behavior information used for carrying out a red team test on a target model, inputting the attack behavior information into a strategy generation model, generating one or more different attack strategies corresponding to the attack behavior information, and then, carrying out the red team test on the target model. According to the method, attack data can be generated through a pre-trained attack model based on a generated attack strategy, attack testing is performed on a target model by using the generated attack data, the attack testing of the target model is evaluated through a reward model, reward information corresponding to the attack strategy is determined, and finally, reward information corresponding to the attack strategy is obtained. The model parameters of the target model can be finely adjusted based on the reward information corresponding to the attack strategy.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD +1

A hyperspectral adversarial sample defense method based on invariant feature extraction

The application discloses a hyperspectral image anti-attack method based on invariant features, which comprises the following steps: step one, constructing a sample set; step two, pre-training a deep convolutional neural network classification model; step three, building an anti-attack model; step four, constructing a loss function of the anti-attack model; step five, iteratively training the anti-attack model; and step six, testing the trained anti-attack model. The anti-attack method can enhance the robustness of a convolutional neural network and improve the classification accuracy of a hyperspectral classification model against an anti-attack.
Owner:XIAN UNIV OF TECH

Method for security check of a technical unit

A method for a security check of a technical unit (1), wherein at least one first plausible model variant and, if necessary, a plurality of alternative model variants are determined, wherein the method is implemented on a test computer system (2) and wherein the method has the following steps: assigning known weaknesses to the components of the model variants; defining attack targets; creating at least one attack model related to the attack targets for each model variant; weighting the nodes of the attack model according to at least one evaluation variable; determining an evaluation of at least one test vector of the attack model with respect to the evaluation variable; determining a security value as the pessimistic value of all evaluations, and outputting a security confirmation when the security value meets a security criterion.
Owner:AVL LIST GMBH

Attack and defense drill method, system, storage medium and electronic device

PendingCN122640148AData packEvaluation result
The present disclosure relates to the technical field of big data, and particularly relates to a red teaming method, a red teaming system, a storage medium and an electronic device. The red teaming method comprises: generating a big data set with a preset data volume in response to a user inputted red teaming requirement; and generating an attack model in response to a user attack configuration operation; wherein the big data set comprises data of multiple data sources, and the data comprises offline data and real-time data; performing red teaming on a to-be-tested system according to the big data set and the attack model by using a pre-configured attack tool to obtain red teaming data, and monitoring the to-be-tested system in real time to obtain monitoring data; and evaluating the red teaming according to the red teaming data and the monitoring data to obtain an evaluation result. The red teaming method provided by the present disclosure can solve the problem of great difficulty in implementing red teaming in a big data environment.
Owner:HANGZHOU NETEASE CLOUD MUSIC TECH CO LTD

Privacy training data leakage risk detection method for sequence recommendation system

The invention discloses a sequence recommendation system-oriented privacy training data leakage risk detection method, and belongs to the technical field of sequence recommendation models and privacy protection. Aiming at the problems that the privacy training data leakage risk exists in a sequence recommendation model and the risk is difficult to accurately evaluate in a Top-K label black box scene in an existing method, the method comprises the following steps of: firstly, obtaining a target model and an auxiliary data set, dividing, training a shadow model, obtaining agent model integration through knowledge distillation, extracting comparison performance characteristics to generate a training sample, and finally obtaining a sequence recommendation model; and finally, the dichotomy attack model is used for evaluating the privacy leakage risk of the target data set. The method is mainly used for detecting the privacy training data leakage risk of the sequence recommendation model, and is suitable for third-party model security audit and privacy compliance check scenes.
Owner:BEIHANG UNIV

A method, system, and storage medium for generating adversarial malware samples based on AST and LLM.

This invention discloses a method, system, and storage medium for generating adversarial samples of malware based on Abstract Syntax Tree (AST) and Language Runtime Model (LLM). The method includes the following steps: parsing malware samples to obtain their abstract syntax tree (AST); constructing a semantically preserved set of perturbation rules based on the AST structure; building an adversarial attack model based on deep learning; optimizing the generator using a deep reinforcement learning algorithm to determine the optimal AST perturbation action; converting the selected AST perturbation action into structured prompt words and generating code variants using LLM; and compiling, verifying, and repairing the LLM-generated code to generate executable adversarial samples that retain malicious functionality. This invention addresses the problems of insufficient robustness in existing malware adversarial sample generation methods and the lack of structural constraints when directly applying large language models to generate malicious code.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Transform and prompt guidance-based imperceptible watermark attack method

The invention provides an imperceptible watermark attack method based on Transform and prompt guidance, and belongs to the technical field of digital information security. The method comprises the following steps: constructing a training data set through an existing data set and a QPHFMs watermark algorithm, and uniformly adjusting the sizes of a watermark-containing image and an original watermark-free image to obtain standardized training data; the method comprises the following steps: constructing an imperceptible watermark attack network TFP-WAN comprising a Transform encoder-decoder framework and a dynamic prompt module, wherein the dynamic prompt module comprises a PGM and a PIM; mAE is used as a loss function in the TFP-WAN; inputting the standardized training data into the TFP-WAN for iterative training until a preset number of iterations is reached, and obtaining a trained watermark attack model; and inputting a watermark-containing image to be attacked into the watermark attack model, and outputting an attacked image. According to the method, the attack on the robust watermarking algorithm is realized with a relatively high error rate.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES)