Disturbed Input Data Generator for Neural Network Robustness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deep neural networks used in driver assistance systems are susceptible to adversarial perturbations, making them non-robust against disturbances in input data, which can lead to unsafe output data even with small changes in input.

Innovation Solution

A method for generating disturbed input data for neural networks by defining metrics for measuring the magnitude and direction of changes in sensor data, particularly digital images, and using optimization algorithms to create target disturbances that can be applied to the input data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If deep neural networks are used for analyzing sensor data in driver assistance systems, then the system can achieve high levels of automation and intelligent decision-making, but the networks become susceptible to adversarial perturbations and non-robust against disturbances in input data

Engineering Contradiction:
Improvelevel of automationVSAvoidrobustness against disturbances
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent applies preliminary action by generating disturbed input data in advance before the neural network processes it. The method creates multiple variations of input data (images) with different disturbances (noise, blur, contrast changes) and feeds these pre-disturbed data to the neural network during training or testing. This allows the system to anticipate and prepare for potential disturbances rather than reacting to them after they occur, thereby improving robustness while maintaining automation capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by measuring the output of the neural network on disturbed input data and comparing it with the original output. The method calculates the difference between the network's response to disturbed and undisturbed input, and uses this feedback information to adjust the network parameters or flag potential failures. This feedback mechanism allows the system to detect and compensate for disturbances, improving reliability without sacrificing automated decision-making.

Inventive Principle:
Principle #23Feedback

2Productivity

If neural networks are trained without human expert intervention using automatic parameter adaptation, then the training process becomes efficient and scalable, but the networks become largely nontransparent and cannot be systematically tested or formally verified

Engineering Contradiction:
Improvetraining efficiencyVSAvoidtestability and verifiability
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies copying by creating synthetic test cases that replicate real-world driving scenarios with controlled disturbances. Instead of requiring complex real-world testing, the method generates virtual copies of driving scenes with various perturbations (noise, blur, contrast changes) that can be systematically tested. These synthetic test cases allow thorough verification of neural network behavior without the complexity and safety risks of real-world testing, while maintaining the efficiency of automated training processes.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements segmentation by breaking down the testing process into discrete, manageable components. The method segments the input data into multiple disturbed versions (different types and levels of disturbance) and tests the neural network on each segment separately. This segmentation allows systematic verification of specific aspects of network performance (e.g., robustness to noise, robustness to blur) independently, making the black-box network testable and verifiable while maintaining automated training efficiency.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If small manipulations are applied to input data to test network robustness, then the network can be evaluated for susceptibility to adversarial perturbations, but the manipulations may be barely or not perceptible to humans while still causing considerable changes in output data

Engineering Contradiction:
Improverobustness evaluation precisionVSAvoidadversarial perturbations
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by applying different types and levels of disturbances to different regions and aspects of the input data. Instead of uniform treatment, the method creates varied disturbances (noise, blur, contrast changes, occlusions) targeted at specific areas of the image and adjusts their intensity based on local characteristics. This allows precise evaluation of network robustness to specific types of disturbances while maintaining natural appearance, enabling measurement of adversarial susceptibility without creating obviously artificial or harmful manipulations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12322189B2Method and generator for generating disturbed input data for a neural network
Publication Date: 2025.06.03 VOLKSWAGEN AG
  • US12322189B2 patent drawing
  • US12322189B2 patent drawing
  • US12322189B2 patent drawing

AI summary

The invention relates to a method for generating disturbed input data for a neural network for analyzing sensor data, in particular digital images, of a driver assistance system, in which a first metric is defined which indicates how the magnitude of a change in sensor data is measured, a second metric is defined which indicates where a disturbance of sensor data is directed, an optimization problem is generated from a combination of the first metric and second metric, the optimization problem is solved by means of at least one solution algorithm, wherein the solution indicates a target disturbance of the input data, and disturbed input data is generated from sensor data for the neural network by means of the target disturbance.