IP Library › Granted Patent US 12,462,543
Granted Patent B2
US 12,462,543 · App. 17/690,797 · Granted Nov 4, 2025

Training method and apparatus of adversarial attack model, generating method and apparatus of adversarial image, electronic device, and storage medium

Inventors: Jiachen Li (Guangdong, CN); Baoyuan Wu (Guangdong, CN); Yong Zhang (Guangdong, CN); Yanbo Fan (Guangdong, CN); Zhifeng Li (Guangdong, CN); Wei Liu (Guangdong, CN)
Assignee: Tencent Technology (Shenzhen) Company Limited
G06V10/82G06V10/24G06V10/28G06V10/776G06V10/778G06V2201/07H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,543
App. No.
17/690,797
Filed
Mar 9, 2022
Granted
Nov 4, 2025
Kind
B2
Art Unit
2682
USPC
382/156
Abstract

Aspects of the disclosure are directed to a training method and apparatus of an adversarial attack model, a generating method and apparatus of an adversarial image, an electronic device, and a storage medium. The adversarial attack model can include a generator network, and the training method can include using the generator network to generate an adversarial attack image based on a training digital image, and performing an adversarial attack on a target model based on the adversarial attack image, to obtain an adversarial attack result. The training method can further include obtaining a physical image corresponding to the training digital image, and training the generator network based on the training digital image, the adversarial attack image, the adversarial attack result, and the physical image.

Claims (58)

1 . A training method of an adversarial attack model including a generator network and a discriminator network, the training method comprising:

using the generator network to generate an adversarial attack image based on a training digital image;

performing, by processing circuitry, an adversarial attack on a target model by applying a geometric transformation to the adversarial attack image and inputting the transformed image to the target model to obtain an adversarial attack result;

obtaining a physical image by printing the training digital image on a physical medium and capturing the physical image of the training digital image printed on the physical medium;

using the discriminator network to perform image discrimination between (i) the adversarial attack image generated from the training digital image and (ii) the physical image captured from a physical representation of the training digital image to determine a discrimination loss; and

training the generator network and the discriminator network to minimize a combined loss function including an adversarial attack loss based on the adversarial attack result and the discrimination loss.

2 . The training method according to claim 1 , wherein the training the generator network further includes:

obtaining a target label corresponding to the training digital image;

determining an adversarial attack loss based on the target label and the adversarial attack result, and training the generator network based on the adversarial attack loss; and

jointly training the generator network and the discriminator network based on the adversarial attack loss and the discrimination loss.

3 . The training method according to claim 2 , wherein the jointly training the generator network and the discriminator network further comprises:

using the adversarial attack loss and the discrimination loss to construct a target loss; and

jointly training the generator network and the discriminator network based on the target loss.

4 . The training method according to claim 3 , wherein the using the adversarial attack loss and the discrimination loss to construct the target loss further comprises:

constructing a first target function based on the adversarial attack loss;

constructing a second target function based on the discrimination loss; and

determining a final target function based on the first target function and the second target function,

wherein the jointly training the generator network and the discriminator network based on the target loss further includes training both the generator network and the discriminator network based on the final target function.

5 . The training method according to claim 2 , wherein the jointly training the generator network and the discriminator network further comprises:

constructing a first target function based on the adversarial attack loss;

constructing a second target function based on the discrimination loss;

training the generator network based on the first target function and the second target function; and

training the discriminator network based on the second target function.

6 . The training method according to claim 1 , wherein the geometric transformation comprises at least one of translation, scaling, flip, rotation, and shear.

7 . The training method according to claim 1 , wherein the obtaining the physical image corresponding to the training digital image further comprises:

printing and scanning the training digital image to obtain the physical image.

8 . The training method according to claim 1 , wherein the obtaining the physical image corresponding to the training digital image further comprises:

printing and photographing the training digital image to obtain the physical image.

9 . A generating method of an adversarial image, comprising:

training, by processing circuitry, the adversarial attack model including the generator network to obtain a trained adversarial attack model; and

using, by processing circuitry, the trained adversarial attack model to generate the adversarial image based on an inputted digital image,

wherein the adversarial attack model is trained according to the training method of claim 1 .

10 . The generating method according to claim 9 , further comprising:

training the target model by using the adversarial image to defend against the adversarial attack performed by using the adversarial image.

11 . An electronic device, comprising:

a processor; and

a memory that stores one or more computer programs that, when executed by a processor, cause the processor to perform the generating method of the adversarial image according to claim 9 .

12 . A non-transitory computer-readable storage medium that stores a computer programs that, when executed by a processor, causes the processor to perform the generating method of the adversarial image according to claim 9 .

13 . An electronic device, comprising:

a processor; and

a memory that stores a non-transitory computer-readable instruction that, when executed by the processor, causes the processor to perform the training method of the adversarial attack model according to claim 1 .

14 . A non-transitory computer-readable storage medium that stores a computer program that, when executed by a processor, causes the processor to perform the training method of the adversarial attack model according to claim 1 .

15 . A training apparatus of an adversarial attack model that includes a generator network and a discriminator network, the training apparatus comprising:

processing circuitry configured to:

use the generator network to generate an adversarial attack image based on a training digital image;

perform an adversarial attack on a target model by applying a geometric transformation to the adversarial attack image and inputting the transformed image to the target model to obtain an adversarial attack result;

obtain a physical image by printing the training digital image on a physical medium and capturing the physical image of the training digital image printed on the physical medium;

use the discriminator network to perform image discrimination between (i) the adversarial attack image generated from the training digital image and (ii) the physical image captured from a physical representation of the training digital image to determine a discrimination loss; and

train the generator network and the discriminator network to minimize a combined loss function including an adversarial attack loss based on the adversarial attack result and the discrimination loss.

16 . The training apparatus according to claim 15 , wherein the processing circuitry is configured to:

obtain a target label corresponding to the training digital image;

determine an adversarial attack loss based on the target label and the adversarial attack result, and train the generator network based on the adversarial attack loss; and

jointly train the generator network and the discriminator network based on the adversarial attack loss and the discrimination loss.

17 . A generating apparatus of an adversarial image comprising processing circuitry that is configured to:

train an adversarial attack model including a generator network and a discriminator network to obtain a trained adversarial attack model; and

use the trained adversarial attack model to generate the adversarial image based on an inputted digital image,

wherein training the adversarial attack model includes using the generator network to generate an adversarial attack image based on a training digital image; performing an adversarial attack on a target model by applying a geometric transformation to based on the adversarial attack image and inputting the transformed image to the target model to obtain an adversarial attack result; obtaining a physical image by printing the training digital image on a physical medium and capturing the physical image of the training digital image printed on the physical medium; using the discriminator network to perform image discrimination between (i) the adversarial attack image generated from the training digital image and (ii) the physical image captured from a physical representation of the training digital image to determine a discrimination loss; and training the generator network and the discriminator network to minimize a combined loss function including an adversarial attack loss based on the adversarial attack result and the discrimination loss.

18 . The generating apparatus according to claim 17 , wherein the processing circuitry is further configured to train the target model by using the adversarial image to defend against an adversarial attack performed by using the adversarial image.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2022
From: LI, JIACHEN; WU, BAOYUAN; ZHANG, YONG; FAN, YANBO; LI, ZHIFENG; LIU, WEI
To: TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED
Reel/Frame 060354/0677 →
Priority Claims (1)
CN 202010107342.9 · Feb 21, 2020 · national
Continuity (2)
Continuation PCTCN2020128009 · Nov 11, 2020
Related Publication 20220198790A1 · Jun 23, 2022
References Cited (34)
US 20040101160A1 · Kunisa · 2004 [cited by examiner]
US 20160307071A1 · Perronnin · 2016 [cited by examiner]
US 20170351935A1 · Liu et al. · 2017 [cited by applicant]
US 20190130253A1 · Schultz · 2019 [cited by examiner]
US 20190147320A1 · Mattyus · 2019 [cited by examiner]
US 20190220755A1 · Carbune · 2019 [cited by examiner]
US 20190238568A1 · Goswami · 2019 [cited by examiner]
US 20200082097A1 · Poliakov · 2020 [cited by examiner]
US 20200265318A1 · Malkiel · 2020 [cited by examiner]
US 20210398289A1 · Schmidt · 2021 [cited by examiner]
CN 108510061A · 2018 [cited by applicant]
CN 109196526A · 2019 [cited by applicant]
CN 109447263A · 2019 [cited by applicant]
CN 109801221A · 2019 [cited by applicant]
CN 110163093A · 2019 [cited by applicant]
CN 110210573A · 2019 [cited by applicant]
CN 110334806A · 2019 [cited by examiner]
CN 110352430A · 2019 [cited by applicant]
CN 110443203A · 2019 [cited by applicant]
CN 110728629A · 2020 [cited by applicant]
CN 111340214A · 2020 [cited by applicant]
Athalye, Anish, et al. “Synthesizing robust adversarial examples.” International conference on machine learning. PMLR, 2018. [cited by applicant]
Eykholt, Kevin, et al. “Robust physical-world attacks on deep learning visual classification.” Proceedings of the IEEE conference on computer vision and pattern recognition. 2018. [cited by applicant]
Jan, Steve TK, et al. “Connecting the digital and physical world: Improving the robustness of adversarial attacks.” Proceedings of the AAAI Conference on Artificial Intelligence. vol. 33. No. 01. 2019. [cited by applicant]
Goodfellow, Ian, et al. “Generative adversarial nets.” Advances in neural information processing systems 27 (2014). [cited by applicant]
Deng, Jia, et al. “Imagenet: A large-scale hierarchical image database.” 2009 IEEE conference on computer vision and pattern recognition. Ieee, 2009. [cited by applicant]
Simonyan, Karen, and Andrew Zisserman. “Very deep convolutional networks for large-scale image recognition.” arXiv preprint arXiv:1409.1556 (2014). [cited by applicant]
Madry, Aleksander, et al. “Towards deep learning models resistant to adversarial attacks.” arXiv preprint arXiv:1706.06083 (2017). [cited by applicant]
International Search Report and Written Opinion issued Jan. 27, 2021 in International Application. No. PCT/CN2020/128009 with English translation. 10 pgs. [cited by applicant]
Chinese Office Action issued Oct. 20, 2020 in Chinese Application No. 202010107342.9 with English translation, 11 pgs. [cited by applicant]
Chinese Office Action Issued Mar. 24, 2021 in Chinese Application No. 202010107342.9 with English translation; 5 pgs. [cited by applicant]
Jiachen Li, et al., Interaction-aware Multi-agent Tracking and Probabilistic Behavior Prediction via Adversarial Learning, 2019 International Conference on Robotics and Automation (ICRA), Palais-des congres de Montreal,… [cited by applicant]
Yonghao Xu, Can We generate Good Samples Hyperspectral Classification? A Generative Adversarial Network Based Method, International Geoscience and Remote Sensing Symposium 4 pgs. [cited by applicant]
Yinan Yang, et al., Research on Generation Technology of Small Sample Data Based on Generative Adversarial Network, Electric Power Construction, vol. 40, No. 5, May 2019, 7 pgs. [cited by applicant]