IP Library › Granted Patent US 12,046,027
Granted Patent B2
US 12,046,027 · App. 18/135,046 · Granted Jul 23, 2024

Adversarial detection using discriminator model of generative adversarial network architecture

Inventors: Miriam Hanna Manevitz (Hasharon, IL); Aviv Ben Arie (Hasharon, IL)
Assignee: Intuit Inc.
G06V10/82G06N3/045G06V10/774
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,046,027
App. No.
18/135,046
Granted
Jul 23, 2024
Kind
B2
Abstract

A method includes training, using first real data objects, a generative adversarial network having a generator model and a discriminator model to create a trained generator model that generates realistic data, and training, using adversarial data objects and second real data objects, the discriminator model to output an authenticity binary class for the adversarial data objects and the second real data objects. The method further includes deploying the discriminator model to a production system. In the production system, the discriminator model outputs the authenticity binary class to a system classifier model.

Claims (62)

1. A method comprising:

performing a first training, using a first plurality of real data objects, a generative adversarial network having a generator model and a discriminator model to create a trained generator model that generates realistic data, wherein the performing the first training trains both the generator model and the discriminator model;

performing a second training, using a plurality of adversarial data objects and a second plurality of real data objects, of the discriminator model to output an authenticity binary class for the plurality of adversarial data objects and the second plurality of real data objects, wherein the second training is distinct from the first training; and

deploying the discriminator model to a production system,

wherein, in the production system, the discriminator model outputs the authenticity binary class of an unknown data object to a system classifier model, wherein the system classifier model is separate from the discriminator model.

2. The method of claim 1 , wherein the plurality of adversarial data objects are data objects that are used in real system attacks to a production system.

3. The method of claim 1 , wherein training the generative adversarial network comprises:

producing, by the generator model, a plurality of generated data objects from a plurality of random input vectors;

classifying, the discriminator model, the plurality of generated data objects and the first plurality of real data objects to obtain a predicted authenticity binary class for each of the plurality of generated data objects and the first plurality of real data objects;

executing a discriminator loss function using the predicted authenticity binary class to obtain a discriminator loss; and

updating the discriminator model using the discriminator loss.

4. The method of claim 3 , wherein training the generative adversarial network further comprises:

executing a generator loss function using the predicted authenticity binary class to obtain a generator loss; and

updating the generator model using the generator loss.

5. The method of claim 1 , wherein training the discriminator model comprises:

classifying, by the discriminator model, the plurality of adversarial data objects and the second plurality of real data objects to obtain a predicted authenticity binary class for each of the plurality of adversarial data objects and the second plurality of real data objects;

executing a fine tuning discriminator loss function on the predicted authenticity binary class for each of the plurality of adversarial data objects and the second plurality of real data objects to obtain a discriminator loss; and

updating the discriminator model using the discriminator loss.

6. The method of claim 1 , wherein the discriminator model is a convolutional neural network, and wherein the plurality of adversarial data objects and the first plurality of real data objects, and the second plurality of real data objects are images.

7. The method of claim 1 , further comprising:

training the system classifier model to classify contents in an unknown data object.

8. The method of claim 1 , further comprising:

training the system classifier model to output a location of contents in an unknown data object.

9. The method of claim 1 , wherein the plurality of adversarial data objects comprises historical data objects from known attacks.

10. A system comprising:

a generative adversarial network comprising a generator model and a discriminator model, the generative adversarial network is trained in a first training, using a first plurality of real data objects, to create a trained generator model that generates realistic data, wherein the first training trains both the generator model and the discriminator model; and

a discriminator model fine tuning training system comprising the discriminator model and configured to train in a second training, using a plurality of adversarial data objects and a second plurality of real data objects, the discriminator model to output an authenticity binary class for the plurality of adversarial data objects and the second plurality of real data objects, wherein the second training is distinct from the first training,

wherein the system is configured to deploy the discriminator model to a production system, and

wherein, in the production system, the discriminator model outputs the authenticity binary class of an unknown data object to a system classifier model, wherein the system classifier model is separate from the discriminator model.

11. The system of claim 10 , wherein the plurality of adversarial data objects are data objects that are used in real system attacks to a production system.

12. The system of claim 10 , wherein training the generative adversarial network comprises:

producing, by the generator model, a plurality of generated data objects from a plurality of random input vectors;

classifying, the discriminator model, the plurality of generated data objects and the first plurality of real data objects to obtain a predicted authenticity binary class for each of the plurality of generated data objects and the first plurality of real data objects;

executing a discriminator loss function using the predicted authenticity binary class to obtain a discriminator loss; and

updating the discriminator model using the discriminator loss.

13. The system of claim 12 , wherein training the generative adversarial network comprises:

executing a generator loss function using the predicted authenticity binary class to obtain a generator loss; and

updating the generator model using the generator loss.

14. The system of claim 10 , wherein training the discriminator model comprises:

classifying, by the discriminator model, the plurality of adversarial data objects and the second plurality of real data objects to obtain a predicted authenticity binary class for each of the plurality of adversarial data objects and the second plurality of real data objects;

executing a fine tuning discriminator loss function on the predicted authenticity binary class for each of the plurality of adversarial data objects and the second plurality of real data objects to obtain a discriminator loss;

updating the discriminator model using the discriminator loss.

15. The system of claim 10 , wherein the discriminator model is a convolutional neural network, and wherein the plurality of adversarial data objects and the first plurality of real data objects, and the second plurality of real data objects are images.

16. A method comprising:

performing a first training, using a first plurality of real data objects, a generative adversarial network having a generator model and a discriminator model to create a trained generator model that generates realistic data, wherein the performing the first training trains both the generator model and the discriminator model by using the generator model to generate a plurality of generated data objects, and trains the discriminator model to distinguish between the plurality of generated data objects and the first plurality of real data objects;

performing a second training, using a plurality of adversarial data objects and a second plurality of real data objects, the discriminator model to output an authenticity binary class for the plurality of adversarial data objects and the second plurality of real data objects, wherein the second training is distinct from the first training;

processing, by the discriminator model, an unknown data object to generate the authenticity binary class for the unknown data object, wherein the system classifier model is separate from the discriminator model;

processing, by a system classifier model connected to the discriminator model, the unknown data object and the authenticity binary class to generate an output; and

presenting the output.

17. The method of claim 16 , wherein training the generative adversarial network comprises:

producing, by the generator model, a plurality of generated data objects from a plurality of random input vectors;

classifying, the discriminator model, the plurality of generated data objects and the first plurality of real data objects to obtain a predicted authenticity binary class for each of the plurality of generated data objects and the first plurality of real data objects;

executing a discriminator loss function using the predicted authenticity binary class to obtain a discriminator loss; and

updating the discriminator model using the discriminator loss.

18. The method of claim 17 , wherein training the generative adversarial network further comprises:

executing a generator loss function using the predicted authenticity binary class to obtain a generator loss; and

updating the generator model using the generator loss.

19. The method of claim 17 , wherein training the discriminator model comprises:

classifying, by the discriminator model, the plurality of adversarial data objects and the second plurality of real data objects to obtain a predicted authenticity binary class for each of the plurality of adversarial data objects and the second plurality of real data objects;

executing a fine tuning discriminator loss function on the predicted authenticity binary class for each of the plurality of adversarial data objects and the second plurality of real data objects to obtain a discriminator loss;

updating the discriminator model using the discriminator loss.

20. The method of claim 16 , wherein the discriminator model is a convolutional neural network, and wherein the plurality of adversarial data objects and the first plurality of real data objects, and the second plurality of real data objects are images.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2024
From: MANEVITZ, MIRIAM HANNA; BEN ARIE, AVIV
To: INTUIT INC.
Reel/Frame 067710/0955 →
Continuity (2)
Continuation 17855699 · Jun 30, 2022
Related Publication 20240005651A1 · Jan 4, 2024