Feature Extractor Distance Bounds for Adversarial Robustness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing adversarial training methods for content-based image retrieval are limited as they rely on known attack methods and do not effectively address unknown attack methods, making it difficult to assess the impact of adversarial examples on search results.

Innovation Solution

A learning device and method that learns a feature extractor to minimize the upper and lower bounds of the distance between images in a feature space, allowing for robustness verification against unknown adversarial attacks by ensuring that the distance between images remains consistent even with noise perturbations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If adversarial training is performed using known attack methods, then the model becomes more robust against those specific attacks, but it remains vulnerable to unknown attack methods and cannot verify the degree of impact on search results

Engineering Contradiction:
Improverobustness against known attacksVSAvoidprotection against unknown attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent uses adversarial examples (harmful inputs designed to attack the model) as training data to improve the model's robustness. By intentionally training with these malicious inputs, the model learns to resist both known and unknown attack methods, converting the harmful adversarial examples into beneficial training material that enhances overall security and verification capabilities.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Adaptability or versatility

If the distance between images in feature space is allowed to vary widely, then the feature extractor can capture more diverse characteristics, but the system becomes vulnerable to adversarial perturbations that can manipulate search results

Engineering Contradiction:
Improvefeature extraction capabilityVSAvoidvulnerability to adversarial examples
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent modifies the distance metric parameters in the feature space by introducing upper and lower bound constraints. This parameter change ensures that the distance between images remains within a controlled range, preventing adversarial perturbations from arbitrarily manipulating search results while preserving the feature extractor's ability to capture diverse characteristics through proper feature learning.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250166356A1Learning device, learning method, and recording medium
Publication Date: 2025.05.22 NEC CORP
  • US20250166356A1 patent drawing
  • US20250166356A1 patent drawing
  • US20250166356A1 patent drawing

AI summary

A learning device causes a feature amount extractor to be trained such that the upper limit and the lower limit of a distance, obtained in a case where the feature amount extractor is used, in a feature space between images become close to the distance.