首页> 外国专利> Black-box adversarial attacks on videos

Black-box adversarial attacks on videos

机译:对视频的黑匣子对抗攻击

摘要

A method for generating black-box adversarial attacks on video recognition models is provided, comprising a) passing input video frames into a public image model, to obtain pixel-wise tentative perturbations; b) partitioning the tentative perturbations into tentative perturbation patches; c) estimating the rectification weight required for each patch, via querying the target video model; d) applying the patch-wise rectification weight on the patches, to obtain the rectified pixel-wise perturbations; e) applying one step projected gradient descent (PGD) perturbation on the input video, according to the rectified pixel-wise perturbations; and f) iteratively performing steps a)-e) until an attack succeeds or a query limit is reached. Systems and networks therefor are also provided.
机译:提供了一种在视频识别模型上产生黑匣子对抗攻击的方法,包括:a)将输入视频帧传递到公共图像模型中,以获得逐像素的暂定扰动; b)将暂定扰动划分为暂定扰动块; c)通过查询目标视频模型,估计每个补丁所需的整流权重; d)在斑块上施加逐块整流权重,以获得整流后的逐像素扰动; e)根据校正后的逐像素扰动,对输入视频应用一步投影梯度下降(PGD)扰动; f)重复执行步骤a)-e),直到攻击成功或达到查询限制。为此还提供了系统和网络。

著录项

  • 公开/公告号US10783401B1

    专利类型

  • 公开/公告日2020-09-22

    原文格式PDF

  • 申请/专利权人 FUDAN UNIVERSITY;

    申请/专利号US202016798393

  • 发明设计人 YUGANG JIANG;LINXI JIANG;XINGJUN MA;

    申请日2020-02-23

  • 分类号G06K9/62;G06N20;G06F16/73;G06N7;G06K9;G06F21/57;

  • 国家 US

  • 入库时间 2022-08-21 11:30:22

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号