Disturbed Input Data Generator for Neural Network Robustness
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deep neural networks used in driver assistance systems are susceptible to adversarial perturbations, making them non-robust against disturbances in input data, which can lead to unsafe output data even with small changes in input.
Innovation Solution
A method for generating disturbed input data for neural networks by defining metrics for measuring the magnitude and direction of changes in sensor data, particularly digital images, and using optimization algorithms to create target disturbances that can be applied to the input data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If deep neural networks are used for analyzing sensor data in driver assistance systems, then the system can achieve high levels of automation and intelligent decision-making, but the networks become susceptible to adversarial perturbations and non-robust against disturbances in input data
Solution Approach 1:
The patent applies preliminary action by generating disturbed input data in advance before the neural network processes it. The method creates multiple variations of input data (images) with different disturbances (noise, blur, contrast changes) and feeds these pre-disturbed data to the neural network during training or testing. This allows the system to anticipate and prepare for potential disturbances rather than reacting to them after they occur, thereby improving robustness while maintaining automation capabilities.
Solution Approach 2:
The patent implements feedback by measuring the output of the neural network on disturbed input data and comparing it with the original output. The method calculates the difference between the network's response to disturbed and undisturbed input, and uses this feedback information to adjust the network parameters or flag potential failures. This feedback mechanism allows the system to detect and compensate for disturbances, improving reliability without sacrificing automated decision-making.
2Productivity
If neural networks are trained without human expert intervention using automatic parameter adaptation, then the training process becomes efficient and scalable, but the networks become largely nontransparent and cannot be systematically tested or formally verified
Solution Approach 1:
The patent applies copying by creating synthetic test cases that replicate real-world driving scenarios with controlled disturbances. Instead of requiring complex real-world testing, the method generates virtual copies of driving scenes with various perturbations (noise, blur, contrast changes) that can be systematically tested. These synthetic test cases allow thorough verification of neural network behavior without the complexity and safety risks of real-world testing, while maintaining the efficiency of automated training processes.
Solution Approach 2:
The patent implements segmentation by breaking down the testing process into discrete, manageable components. The method segments the input data into multiple disturbed versions (different types and levels of disturbance) and tests the neural network on each segment separately. This segmentation allows systematic verification of specific aspects of network performance (e.g., robustness to noise, robustness to blur) independently, making the black-box network testable and verifiable while maintaining automated training efficiency.
3Measurement precision
If small manipulations are applied to input data to test network robustness, then the network can be evaluated for susceptibility to adversarial perturbations, but the manipulations may be barely or not perceptible to humans while still causing considerable changes in output data
Solution Approach 1:
The patent applies local quality by applying different types and levels of disturbances to different regions and aspects of the input data. Instead of uniform treatment, the method creates varied disturbances (noise, blur, contrast changes, occlusions) targeted at specific areas of the image and adjusts their intensity based on local characteristics. This allows precise evaluation of network robustness to specific types of disturbances while maintaining natural appearance, enabling measurement of adversarial susceptibility without creating obviously artificial or harmful manipulations.
Data Source
AI summary
The invention relates to a method for generating disturbed input data for a neural network for analyzing sensor data, in particular digital images, of a driver assistance system, in which a first metric is defined which indicates how the magnitude of a change in sensor data is measured, a second metric is defined which indicates where a disturbance of sensor data is directed, an optimization problem is generated from a combination of the first metric and second metric, the optimization problem is solved by means of at least one solution algorithm, wherein the solution indicates a target disturbance of the input data, and disturbed input data is generated from sensor data for the neural network by means of the target disturbance.


