IP Library › Granted Patent US 12,217,176
Granted Patent B2
US 12,217,176 · App. 17/593,558 · Granted Feb 4, 2025

Automatic identification and classification of adversarial attacks

Inventors: Eric Piegert (Kriftel, DE); Michelle Karg (Lindau, DE); Christian Scharfenberger (Lindau, DE)
Assignee: Conti Temic microelectronic GmbH
G06N3/08G06N3/045G06V10/454G06V10/764G06V10/82G06V20/56H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,217,176
App. No.
17/593,558
Filed
Sep 21, 2021
Granted
Feb 4, 2025
Kind
B2
Art Unit
2494
USPC
726/23
Abstract

A method for identifying adversarial attacks on an image based detection system for automated driving includes providing a reference signal and a potentially manipulated signal. The method also includes calculating a plurality of metrics which quantify differences between the signals in different ways. The method further includes creating a multi-dimensional feature space based on the calculated metrics and classifying the type of attack based on the calculated metrics. The class of the adversarial attack may then be output.

Claims (34)

1. A method for identifying and classifying adversarial attacks on an automated detection system, comprising:

providing a reference signal and a potentially manipulated signal, wherein each signal includes at least one of an image signal, a video signal, or an audio signal,

calculating a set of n metrics which quantify differences between the reference signal and the potentially manipulated signal in different ways, with n being a natural number greater than one

creating an n-dimensional feature space based on the calculated metrics,

classifying the type of adversarial attack on the basis of the calculated metrics in the n-dimensional feature space, and

outputting the class of the adversarial attack,

wherein the automated detection system comprises at least one trained neural network, and the reference signal and the potentially manipulated signal are provided following completion of a training phase of the at least one neural network, and

wherein subsets are created from the n metrics in order to extract most relevant m metrics, with m being a natural number less than n and, wherein the classification of the type of the adversarial attack is effected on the basis of the calculated metrics in the m-dimensional feature space.

2. The method according to claim 1 , further comprising introducing a specific counter-measure against a class of adversarial attacks identified as critical.

3. The method according to claim 1 , wherein the automated detection system comprises a camera-based sensor system of a vehicle, wherein the potentially manipulated signals are image or video signals which have been acquired by at least one camera of the camera-based sensor system.

4. The method according to claim 3 , wherein the method for identifying an adversarial attack is performed during a signal data transfer from the vehicle to an online database.

5. The method according to claim 3 , wherein the automated detection system comprises a multicamera system in a vehicle and wherein the potentially manipulated image or video signal and the reference image or video signal are overlapping or temporally offset acquisitions of the same scene by various individual cameras.

6. The method according to claim 3 , wherein the metrics are calculated on the entire potentially manipulated image.

7. The method according to claim 3 , wherein the metrics are calculated on an image detail of the potentially manipulated image.

8. The method according to claim 3 , wherein the metrics are calculated from at least one of a series of images and a series of image details.

9. The method according to claim 3 , wherein the n metrics contain multiple metrics which are selected from the group of:

SSIM, L1-norm, L2-norm, KL divergence, MSE, MAE, PSNR, L∞-norm, L0-norm, Edge metrics, hash metrics, and Fourier transform metrics.

10. The method according to claim 1 , wherein the creation of the subsets is implemented based on machine learning and wherein at least the most relevant m metrics are automatically learned with the aid of representation learning.

11. A system for identifying adversarial attacks on an automated detection system, comprising an input interface, an identification unit, and an output interface, wherein

the input interface is configured to receive a reference signal and a potentially manipulated signal, wherein each signal includes at least one of an image signal, a video signal, or an audio signal, and to provide the potentially manipulated signal to the identification unit;

wherein the identification unit comprises processor circuitry and is configured:

to calculate a set of n metrics, which quantify differences between the reference signal and the potentially manipulated signal in different ways,

to create a n-dimensional feature space based on the calculated metrics, and

to classify the type of adversarial attack on the basis of the calculated metrics in the n-dimensional feature space, and

the output interface is configured to output the class of the adversarial attack established by the identification unit

wherein the automated detection system comprises at least one trained neural network such that the reference signal and the potentially manipulated signal are received by the system following completion of a training phase of the at least one neural network, and

wherein subsets are created from the n metrics in order to extract most relevant m metrics, with m being a natural number less than n and, wherein the classification of the type of the adversarial attack is effected on the basis of the calculated metrics in the m-dimensional feature space.

12. The system according to claim 11 , further comprising a second system which receives the class of the adversarial attack from the output interface, the second system introducing a specific counter-measure against if the class of adversarial attacks is identified as critical.

13. The system according to claim 11 , wherein the automated detection system comprises a camera-based sensor system of a vehicle, wherein the potentially manipulated signals are image or video signals which have been acquired by at least one camera of the camera-based sensor system.

14. The system according to claim 13 , wherein identifying an adversarial attack is performed during a signal data transfer from the vehicle to an online database.

15. The system according to claim 11 , wherein the metrics are calculated on an image detail of the potentially manipulated image.

16. The system according to claim 11 , wherein the creation of the subsets is implemented based on machine learning, and wherein the most relevant m metrics are automatically learned with representation learning.

17. The system according to claim 11 , wherein the reference signal and the potentially manipulated signal are overlapping or temporally offset from each other of the same scene.

18. The method according to claim 5 , wherein the reference signal and the potentially manipulated signal are temporally offset from each other of the same scene.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2022
From: PIEGERT, ERIC; KARG, MICHELLE, DR; SCHARFENBERGER, CHRISTIAN, DR
To: CONTI TEMIC MICROELECTRONIC GMBH
Reel/Frame 058890/0794 →
Priority Claims (1)
DE 10 2019 204 318.6 · Mar 28, 2019 · national
Continuity (1)
Related Publication 20220174089A1 · Jun 2, 2022
References Cited (43)
US 10800434B1 · Beecham · 2020 [cited by examiner]
US 20110135203A1 · Iwamoto et al. · 2011 [cited by applicant]
US 20140270531A1 · Nakagata · 2014 [cited by applicant]
US 20140320644A1 · Hegemann · 2014 [cited by examiner]
US 20160112624A1 · Wolfgang · 2016 [cited by applicant]
US 20180018535A1 · Yurong · 2018 [cited by applicant]
US 20180165508A1 · Othman et al. · 2018 [cited by applicant]
US 20190080089A1 · Chen · 2019 [cited by applicant]
US 20190238568A1 · Goswami · 2019 [cited by examiner]
US 20190251395A1 · Zhang · 2019 [cited by examiner]
US 20190318099A1 · Carvalho et al. · 2019 [cited by applicant]
US 20210056404A1 · Goswami · 2021 [cited by examiner]
US 20210150036A1 · Kaneko et al. · 2021 [cited by applicant]
US 20220126864A1 · Moustafa · 2022 [cited by examiner]
US 20220174089A1 · Piegert · 2022 [cited by examiner]
CN 102184537A · 2011 [cited by applicant]
CN 105261013A · 2016 [cited by applicant]
CN 108292369A · 2018 [cited by applicant]
CN 108335289A · 2018 [cited by applicant]
CN 108491837A · 2018 [cited by applicant]
DE 102013209940A1 · 2014 [cited by applicant]
EP 3641214A1 · 2020 [cited by applicant]
JP 2014182440A · 2014 [cited by applicant]
JP 2016157455A · 2016 [cited by applicant]
JP 2018165926A · 2018 [cited by applicant]
JP 2019036865A · 2019 [cited by applicant]
WO 2010087124A1 · 2010 [cited by applicant]
WO WO2012045317A1 · 2012 [cited by examiner]
WO 2014042514A2 · 2014 [cited by applicant]
WO 2018230366A1 · 2018 [cited by applicant]
Sameer, V.U., Naskar, R., Musthyala, N., Kokkalla, K. Deep Learning Based Counter-Forensic Image Classification for Camera Model Identification. Digital Forensics and Watermarking. IWDW 2017. Lecture Notes in Computer S… [cited by examiner]
Japanese Office Action dated Aug. 5, 2022 for the counterpart JJapanese Patent Application No. 2021-545871. [cited by applicant]
German Search Report dated Oct. 31, 2019 for the counterpart German Patent Application No. 10 2019 204 318.6. [cited by applicant]
International Search Report and the Written Opinion of the International Searching Authority mailed on Aug. 21, 2020 for the counterpart PCT Application No. PCT/DE2020/2000018. [cited by applicant]
N. Carlini, D. Wagner, “Audio Adversarial Examples: Targeted Attacks on Speech-to-Text”, Mar. 30, 2018, University of California, Berkeley. [cited by applicant]
N. Akhtar, A. Mian, “Threat of Adversarial Attacks on Deep Learning in Computer Vision, A Survey”, IEEE Access, vol. 6 2018, accepted Feb. 8, 2018, date of publication Feb. 19, 2018. [cited by applicant]
R Venkatesan “Robust Image Hashing” Cryptography Group, Microsoft Research, 1 Microsoft Way, Redmond, WA 98052-6399 2 Univ. of Illinois, Beckman Inst. & ECE Dep. [cited by applicant]
Jacob Goldberger et al., “An Efficient Image Similarity Measure based on Approximations of KL-Divergence Between Two Gaussian Mixtures”, Cute Systems, Tel Aviv, Israel and The Engineering Department, Tel Aviv University… [cited by applicant]
Mahmood Sharif et al., “On the Suitability of Lp-norms for Creating and Preventing Adversarial Examples”, University of North Carolina at Chapel Hill. [cited by applicant]
Alain Hore et al., “Image quality metrics: PSNR vs. SSIM”, Département d'informatique, Faculté des sciences, Université de Sherbrooke, Quebec, Canada. [cited by applicant]
Christian Szegedy et al., “Intriguing properties of neural networks”, Google Inc., New York University, University of Montreal, and Facebook Inc. [cited by applicant]
Uyeong Jang et al., “Objective Metrics and Gradient Descent Algorithms for Adversarial Examples in Machine Learning”, University of Wisconsin and Google. [cited by applicant]
Chinese First Office Action dated for the counterpart Chinese Patent Application No. 202080016237.2, dated Sep. 19, 2023, and translation of same. [cited by applicant]