IP Library › Granted Patent US 12,242,657
Granted Patent B2
US 12,242,657 · App. 17/873,661 · Granted Mar 4, 2025

Method and system of crown based for adversarial attacks

Inventors: Leslie Rice (Pittsburgh, PA); Huan Zhang (Pittsburgh, PA); Wan-Yi Lin (Wexford, PA); Jeremy Kolter (Pittsburgh, PA)
Assignee: Robert Bosch GmbH
G06F21/64G06V10/454G06V10/764
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,657
App. No.
17/873,661
Granted
Mar 4, 2025
Kind
B2
Abstract

A method of identifying an attack comprising receiving an input of one or more images, wherein the one or more images includes a patch size and size, divide the image into a first sub-image and a second sub-image, classify the first sub-image and the second sub-image, wherein classifying is accomplished via introducing a variable in a pixel location associated with the first and second sub-image, and in response to classifying the first and second sub-image and identifying an adversarial patch, output a notification indicating that the input is not certified.

Claims (40)

1. A method of identifying an attack comprising:

receiving an input of one or more images, wherein the one or more images includes a patch size and size;

dividing one of the one or more images into a first sub-image and a second sub-image;

dividing a domain of a verification problem into a plurality of sub-domains;

verifying the first sub-image and the second sub-image until all sub-domains are certified or split until each sub-domain contains only one patch location;

classifying the first sub-image and the second sub-image, wherein classifying is accomplished via introducing a Boolean variable in a pixel location associated with the first and second sub-image, wherein the Boolean variable identifies the pixel location; and

in response to classifying the first and second sub-image and identifying an adversarial patch, outputting a notification indicating that the input is not certified.

2. The method of claim 1 , wherein classifying is accomplished via utilizing a branch and bound at an input space associated with the first and second sub-image.

3. The method of claim 1 , wherein the method includes utilizing mixed integer programming to formulate a patch attack problem utilizing a patch size associated with the one of the one or more images.

4. The method of claim 3 , wherein the method includes utilizing a convex program solver to resolve the patch attack problem.

5. The method of claim 1 , wherein the image is LIDAR, radar, sonar, thermal, heat, or temperature image.

6. The method of claim 1 , wherein the method includes utilizing bagsnet or convmixer as a feature extractor configured to utilize an image size associated with the one of the one or more images to output a feature map.

7. The method of claim 1 , extractor has a receptive field smaller than the one of the one or more images.

8. A system for classifying an image, comprising:

a sensor configured to generate one or more images; a controller in communication with the sensor and configured to:

receive an input of one or more images, wherein the one or more images includes a patch size and image size;

divide one of the one or more images into a first sub-image and a second sub-image;

divide a domain of a verification problem into a plurality of sub-domains;

verify the first sub-image and the second sub-image until all sub-domains are certified or split until each sub-domain contains only one patch location;

classify the first sub-image and the second sub-image, wherein classifying is accomplished via introducing a Boolean variable in a pixel location associated with the first and second sub-image, wherein the Boolean variable identifies the pixel location; and

in response to classifying the first and second sub-image and identifying an adversarial patch, output a notification indicating that the input is not certified.

9. The system of claim 8 , wherein the image is LIDAR, radar, sonar, thermal, heat, or temperature image.

10. The system of claim 8 , wherein classifying is accomplished via utilizing a branch and bound at an input space associated with the first and second sub-image.

11. The system of claim 8 , wherein the controller is further configured to verify the first sub-image and second sub-image utilizing 1 ={x i,j ,x∈ ,and(i,j)∈S 1 }, 2 ={x i,j ,x∈ ,and(i,j)∈S 2 }.

12. The system of claim 8 , wherein the system includes a feature extractor configured to take an image size associated with one of the one or more images and output a feature map.

13. The system of claim 12 , wherein the feature extractor includes either bagsnet or convmixer.

14. A method of identifying an attack comprising:

receiving an input of one or more images, wherein the one or more images includes a patch size and size;

divide one of the one or more images into a first sub-image and a second sub-image;

divide a domain of a verification problem into a plurality of sub-domains;

classify the first sub-image and the second sub-image, wherein classifying is done via locating a Boolean variable in a pixel location associated with the first and second sub-image, wherein the Boolean variable includes altering the pixel location;

verify the first sub-image and the second sub-image until all sub-domains are certified or split until each sub-domain contains only one patch location;

in response to classifying the first and second sub-image and not identifying an adversarial patch, continue to divide the one of the one or more images into a plurality of sub-images and classify the sub-images; and

output a notification indicating that the input is not certified in response to identifying an adversarial patch in one of the plurality of sub-images.

15. The method of claim 14 , the method further includes outputting a notification indicating the input is certified if all subdomains are certified.

16. The method of claim 14 , wherein the method includes utilizing mixed integer programming to formulate a patch attack problem utilizing a patch size associated with the one of the one or more images.

17. The method of claim 14 , wherein the method includes utilizing a convex program solver to resolve the patch attack problem.

18. The method of claim 14 , wherein classifying is accomplished via utilizing a branch and bound at an input space associated with the first and second sub-image.

19. The method of claim 14 , wherein the method further includes verifying the first sub-image and second sub-image utilizing 1 ={x i,j , x∈ ,and(i,j)∈S 1 }, 2 ={x i,j ,x∈ ,and(i,j)∈S 2 }.

20. The method of claim 14 , wherein the method further includes utilizing bagsnet or convmixer as a feature extractor configured to utilize an image size associated with the one of the one or more images to output a feature map.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2022
From: LIN, WAN-YI; KOLTER, JEREMY
To: ROBERT BOSCH GMBH
Reel/Frame 061094/0301 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2022
From: RICE, LESLIE; ZHANG, HUAN
To: CARNEGIE MELLON UNIVERSITY
Reel/Frame 061094/0350 →
Continuity (1)
Related Publication 20240037282A1 · Feb 1, 2024
References Cited (14)
US 11373093B2 · Gu · 2022 [cited by examiner]
US 20100124359A1 · Vaidya · 2010 [cited by examiner]
US 20230024101A1 · de Haan · 2023 [cited by examiner]
US 20230096021A1 · Trockman · 2023 [cited by examiner]
US 20240005173A1 · Lomuscio · 2024 [cited by examiner]
CN 113469873A · 2021 [cited by examiner]
“Certified Defenses for Adversarial Patches”—Chiang et al, ICLR 2020, Mar. 2020 https://openreview.net/pdf?id=HyeaSkrYPH (Year: 2020). [cited by examiner]
“Adversarial Attacks for Image Segmentation on Multiple Lightweight Models”—Kang et al., IEEE Access, Feb. 20, 2020 https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=8990068 (Year: 2020). [cited by examiner]
Chiang et al., “Certified Defenses for Adversarial Patches”, Published as a conference paper at ICLR 2020, 16 pages. [cited by applicant]
Wang et al, “Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Neural Network Robustness Verification”, 35th Conference on Neural Information Processing Systems (NeurIPS 2021), Sydney, Austra… [cited by applicant]
Anonymous, “Certified Patch Robustness Via Smoothed Vision Transformers”, Under review as a conference paper at ICLR 2022, 26 pages. [cited by applicant]
Brendel et al., “Approximating CNNS With Bag-of-Localfeatures Models Works Surprisingly Well on Imagenet”, arXiv:1904.00760v1 [cs.CV] Mar. 20, 2019, Published as a conference paper at ICLR 2019, 15 pages. [cited by applicant]
Website for “Image Classification with ConvMixer”, https://colab.research.google.com/github/keras-team/keras-io/blob/master/examples/vision/ipynb/convmixer.ipynb, retrieved on Jul. 26, 2022, 7 pages. [cited by applicant]
Oh et al., “Towards Reverse-Engineering Black-Box Neural Networks”, arXiv:1711.01768v3 [stat.ML] Feb. 14, 2018, Published as a conference paper at ICLR 2018, 20 pages. [cited by applicant]