IP Library › Granted Patent US 12,386,962
Granted Patent B2
US 12,386,962 · App. 18/177,707 · Granted Aug 12, 2025

Adversarial attack detection and avoidance in computer vision

Inventor: Amir Afrasiabi (Fircrest, WA)
Assignee: The Boeing Company
G06F21/566G06V10/774G06V10/86G06F2221/034G06V2201/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,962
App. No.
18/177,707
Granted
Aug 12, 2025
Kind
B2
Abstract

Techniques for adversarial attack avoidance for machine learning (ML) are disclosed. These techniques include receiving one or more images at a trained ML model and receiving attack data at the ML model. The techniques further include predicting an object depicted in the one or more images using the ML model, based on the one or more images, metadata relating to the one or more images, and the attack data. The ML model uses the metadata to prevent the attack data from changing a result of the predicting.

Claims (34)

1. A method, comprising:

receiving, from a computing system implementing a machine learning (ML) model, one or more images depicting an object, wherein the ML model is trained using training data representing the object and additional training metadata relating to the object, the additional training metadata comprising temporal metadata that includes two or more training images depicting the object at different times;

receiving, from the computing system, attack data at the ML model; and

outputting, to the computing system, an object classification of the object depicted in the one or more images predicted using the ML model, based on the one or more images, the additional training metadata, and the attack data;

wherein the ML model uses the additional training metadata to prevent the attack data from changing the object classification of the object.

2. The method of claim 1 , wherein the attack data comprises adversarial attack data intended to change the object classification of the object by the ML model.

3. The method of claim 1 , wherein the ML model is trained using a multi-dimensional array relating to the training data and the additional training metadata.

4. The method of claim 1 , wherein the additional training metadata further comprises object relationship data for the object.

5. The method of claim 4 , wherein the object relationship data comprises a graph relating to the object depicted in the one or more images.

6. The method of claim 5 , wherein the graph comprises a plurality of vertices and edges relating to sub-components of the object.

7. The method of claim 6 , wherein the graph is generated using a second ML model to identify the sub-components.

8. The method of claim 7 , wherein the graph is further generated by identifying bounding boxes for each of the sub-components and calculating a respective centroid for each bounding box, each of the vertices in the graph relating to one or more of the centroids.

9. A non-transitory computer-readable medium including computer program code that, when executed by operation of one or more computer processors, performs operations comprising:

receiving, from a computing system implementing a machine learning (ML) model, one or more images depicting an object wherein the ML model is trained using training data representing the object and additional training metadata relating to the object, the additional training metadata comprising temporal metadata that includes two or more training images depicting the object at different times;

receiving, from the computing system, attack data at the ML model; and

outputting, to the computing system, an object classification of the object depicted in the one or more images predicted using the ML model, based on the one or more images, the additional training metadata, and the attack data;

wherein the ML model uses the additional training metadata to prevent the attack data from changing the object classification of the object.

10. The non-transitory computer-readable medium of claim 1 , wherein the additional training metadata further comprises object relationship data for the object.

11. The non-transitory computer-readable medium of claim 3 , wherein the object relationship data comprises a graph relating to the object depicted in the one or more images.

12. The non-transitory computer-readable medium of claim 9 , wherein the attack data comprises adversarial attack data intended to change the object classification of the object by the ML model.

13. The non-transitory computer-readable medium of claim 9 , wherein the ML model is trained using a multi-dimensional array relating to the training data and the additional training metadata.

14. The non-transitory computer-readable medium of claim 11 , wherein the graph comprises a plurality of vertices and edges relating to sub-components of the object.

15. A system, comprising:

a computer processor; and

a memory having instructions stored thereon which, when executed on the computer processor, performs operations comprising:

receiving, from the system, one or more images depicting an object at a machine learning (ML) model implemented by the system, wherein the ML model is trained using training data representing the object and additional training metadata relating to the object, the additional training metadata comprising temporal metadata that includes two or more training images depicting the object at different times;

receiving, from the system, attack data at the ML model; and

outputting, to the system, an object classification of the object depicted in the one or more images predicted using the ML model, based on the one or more images, the additional training metadata, and the attack data;

wherein the ML model uses the additional training metadata to prevent the attack data from changing the object classification of the object.

16. The system of claim 14 , wherein the additional training metadata further comprises object relationship data for the object.

17. The system of claim 7 , wherein the object relationship data comprises a graph relating to the object depicted in the one or more images.

18. The system of claim 15 , wherein the attack data comprises adversarial attack data intended to change the object classification of the object by the ML model.

19. The system of claim 15 , wherein the ML model is trained using a multi-dimensional array relating to the training data and the additional training metadata.

20. The system of claim 17 , wherein the graph comprises a plurality of vertices and edges relating to sub-components of the object.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2023
From: AFRASIABI, AMIR
To: THE BOEING COMPANY
Reel/Frame 062863/0471 →
Continuity (1)
Related Publication 20240296225A1 · Sep 5, 2024
References Cited (18)
US 10867444B2 · Russell · 2020 [cited by examiner]
US 11100368B2 · Chu · 2021 [cited by examiner]
US 12069077B2 · Armelin · 2024 [cited by examiner]
US 20200151505A1 · Saito · 2020 [cited by examiner]
US 20200349414A1 · Bazhenov et al. · 2020 [cited by applicant]
US 20220101304A1 · Kang · 2022 [cited by examiner]
US 20230115046A1 · Karta · 2023 [cited by examiner]
US 20230269263A1 · Yarabolu · 2023 [cited by examiner]
US 20240096105A1 · Zhao · 2024 [cited by examiner]
US 20240214404A1 · Sharma · 2024 [cited by examiner]
US 20240248958A1 · Soryal · 2024 [cited by examiner]
US 20240355107A1 · Liba · 2024 [cited by examiner]
US 20240407663A1 · Pietsch · 2024 [cited by examiner]
European Patent Office, Extended European Search Report for European Patent Application No. 24150718.5, dated May 8, 2024. [cited by applicant]
Renu Gopal Mani: “A Survey on Digital Image Forensics: Metadata and Image forgeries”, CEUR Workshop Proceedings (CEUR-WS.org), Jan. 27, 2022 (Jan. 27, 2022), XP0931 53340, Retrieved from the Internet: URL:https://ceur-w… [cited by applicant]
Zhao Yifan et al: “Graph-based High-Order Relation Discovery for Fin⋅⋅ grained Recognition”, 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), IEEE, Jun. 20, 2021 (Jun. 20, 2021), pp. 15074-150… [cited by applicant]
Wang Chuanming et al: “Global Structure Graph Guided Fine-Grained Vehicle Recognition”, ICASSP 2020—2020 IEEE International Conference on Acoustics, Speech and Signal Processing (Icassp), IEEE, May 4, 2020 (May 4, 2020)… [cited by applicant]
Anonymous: “Adversarial machine learning—Wikipedia”, XP093153248, Retrieved from the Internet: URL:https://en.wikipedia.org/wiki/Adversarial_machine_learning. [cited by applicant]