Adversarial Image Generation via Entropy-Enhanced Noise

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing adversarial attack methods on deep neural networks (DNNs) are ineffective when the target network employs defense mechanisms, as the noise features in generated adversarial images are too obvious, making it difficult for the attacks to succeed and thus reducing security.

Innovation Solution

A black box attack method is proposed, where a reference model classification-equivalent to the target classification model is constructed to generate adversarial images with enhanced noise entropy, making it difficult for the target classification model to recognize the adversarial samples without affecting human perception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional adversarial attack methods are used to generate adversarial images, then the attack can be implemented, but the noise features are too obvious making the attack ineffective against defended networks

Engineering Contradiction:
Improveadversarial attack effectivenessVSAvoidnoise feature obviousness
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the noise generation process by changing parameters from direct gradient-based noise to entropy-enhanced noise. The adversarial model increases the information entropy of the noise, making it more random and less detectable while maintaining attack effectiveness. This parameter change in noise characteristics resolves the contradiction between attack effectiveness and noise obviousness.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an adversarial model as an intermediary between the target network and the adversarial examples. This intermediary processes and transforms the noise through entropy enhancement, acting as a mediator that obscures the noise features while preserving the adversarial properties. The intermediary hides the direct connection between the attack and the obvious noise patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If noise is added to make the image imperceptible to humans, then human perception is maintained, but the classification accuracy of the target model must be reduced

Engineering Contradiction:
Improveimperceptibility to human eyeVSAvoidclassification accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent applies different noise characteristics to different regions and aspects of the image. The entropy-enhanced noise is distributed in a way that maintains local imperceptibility to humans while collectively affecting the model's classification accuracy. The local quality of noise is optimized to be imperceptible individually but effective collectively against the model.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11995155B2Adversarial image generation method, computer device, and computer-readable storage medium
Publication Date: 2024.05.28 SHENZHEN INST OF ADVANCED TECH
  • US11995155B2 patent drawing
  • US11995155B2 patent drawing
  • US11995155B2 patent drawing

AI summary

An adversarial image generation method, a computer device, and a computer-readable storage medium are provided. The method includes the following. A reference model classification-equivalent with a target classification model is generated according to the target classification model. A target image is obtained and an original noise for the target image is generated according to the reference model. A first noise and the original noise are input into an adversarial model and a second noise corresponding to the first noise is output when the adversarial model meets a convergence condition, where the second noise enhances an information entropy of the original noise. An enhanced noise image corresponding to the target image is generated according to the second noise and the target image, where a classification accuracy of the enhanced noise image in the target classification model is less than a classification accuracy of the target image in the target classification model.