IP Library Granted Patent US 12,688,674
Granted Patent B2
US 12,688,674 · App. 18/563,935 · Granted Jul 21, 2026

Detection device, detection method, and detection program

Inventors: Tomokatsu Takahashi (Musashino, JP); Masanori Yamada (Musashino, JP); Tomohiro Nagai (Musashino, JP); Yuki Yamanaka (Musashino, JP)
Assignee: NTT, Inc.
G06V10/764G06V10/761
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,688,674
App. No.
18/563,935
Granted
Jul 21, 2026
Kind
B2
Abstract

A detection device includes processing circuitry configured to acquire data to be detected and normal reference data, calculate a Learned Perceptual Image Patch Similarity (LPIPS) distance between the acquired data and the reference data, and classify the acquired data into either a Clean Sample or an Adversarial Example by using the calculated LPIPS distance.

Claims (25)

1 . A detection device comprising:

processing circuitry configured to:

acquire data to be detected;

acquire normal reference data separately from the data to be detected;

calculate a Learned Perceptual Image Patch Similarity (LPIPS) distance between the acquired data and the reference data; and

classify the acquired data into either a Clean Sample or an Adversarial Example by using the calculated LPIPS distance,

wherein the processing circuitry is further configured to determine a minimum value among a plurality of calculated LPIPS distances and to classify the acquired data using the determined minimum value.

2 . The detection device according to claim 1 , wherein the processing circuitry is further configured to classify the acquired data into either a normal Clean Sample or an abnormal Adversarial Example by using a model for classifying the data into normal or abnormal, using the calculated LPIPS distance as an abnormality score.

3 . The detection device according to claim 2 , wherein the processing circuitry is further configured to learn the model for classifying data into normal or abnormal, using the calculated LPIPS distance as an abnormality score.

4 . The detection device according to claim 1 , wherein the processing circuitry is further configured to acquire a sign photographed by a camera, as the data to be detected, and

detect an Adversarial Example.

5 . A detection method to be executed by a detection device, the detection method comprising:

acquiring data to be detected;

acquiring normal reference data separately from the data to be detected;

calculating a Learned Perceptual Image Patch Similarity (LPIPS) distance between the acquired data and the reference data; and

classifying the acquired data into either a Clean Sample or an Adversarial Example by using the calculated LPIPS distance,

wherein a minimum value among a plurality of calculated LPIPS distances is determined and the acquired data is classified using the determined minimum value.

6 . A non-transitory computer-readable recording medium storing therein a detection program that causes a computer to execute a process comprising:

acquiring data to be detected;

acquiring normal reference data separately from the data to be detected;

calculating a Learned Perceptual Image Patch Similarity (LPIPS) distance between the acquired data and the reference data; and

classifying the acquired data into either a Clean Sample or an Adversarial Example by using the calculated LPIPS distance,

wherein a minimum value among a plurality of calculated LPIPS distances is determined and the acquired data is classified using the determined minimum value.

7 . The detection device according to claim 1 , wherein the processing circuitry is further configured to acquire a prediction class of the data to be detected.

8 . The detection device according to claim 1 , wherein the detection device is incorporated into an autonomous vehicle.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2023
From: TAKAHASHI, TOMOKATSU; YAMADA, MASANORI; NAGAI, TOMOHIRO; YAMANAKA, YUKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065654/0488 →
Continuity (1)
Related Publication 20240303966A1 · Sep 12, 2024
References Cited (12)
US 20190238568A1 · Goswami · 2019 [cited by examiner]
US 20200151505A1 · Saito · 2020 [cited by examiner]
US 20210150357A1 · Karras · 2021 [cited by examiner]
US 20220174089A1 · Piegert · 2022 [cited by examiner]
US 20230022943A1 · Xiao · 2023 [cited by examiner]
US 20240005209A1 · Schmidt · 2024 [cited by examiner]
EP 3751453A1 · 2020 [cited by examiner]
Cassidy Laidlaw et al., “Perceptual Adversarial Robustness: Defense Against Unseen Threat Models”, Published as a conference paper at ICLR 2021, Jan. 25, 2021, 25 pages. [cited by applicant]
Richard Zhang et al., “The Unreasonable Effectiveness of Deep Features as a Perceptual Metric”, 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2018, 10 pages. [cited by applicant]
Goodfellow, et al., “Explaining and Harnessing Adversarial Examples”, arXiv:1412.6572v3 [stat.ML], Mar. 20, 2015, pp. 1-11. [cited by applicant]
Lee et al., “A Simple Unified Framework for Detecting Out-of-Distribution Samples and Adversarial Attacks”, arXiv:1807.03888v2 [stat.ML], Oct. 27, 2018, pp. 1-20. [cited by applicant]
Laidlaw et al., “Functional Adversarial Attacks”, arXiv:1906.00001v2 [cs.LG], Oct. 29, 2019, pp. 1-16. [cited by applicant]