首页> 外国专利> METHOD AND APPARATUS FOR IDENTIFYING ADVERSARIAL SAMPLE TO PROTECT MODEL SECURITY

METHOD AND APPARATUS FOR IDENTIFYING ADVERSARIAL SAMPLE TO PROTECT MODEL SECURITY

机译:用于识别逆势样本以保护模型安全性的方法和装置

摘要

A method for identifying an adversarial sample to protect privacy security. The method comprises: first sampling multiple non-adversarial samples relating to private data, so as to obtain a first control sample set; then adding a target sample to be tested to the first control sample set, so as to obtain a first experimental sample set; next, separately using the first control sample set and the first experimental sample set to train an initial machine learning model, so as to obtain a trained first control model and a trained first experimental model; then, using a test sample set to perform performance evaluation on the first control model and the first experimental model, separately, so as to obtain a first control value and a first experimental value for a preset evaluation index; and next, calculating the difference value between the first control value and the first experimental value as a first gain value of the target sample for the model performance. Therefore, whether the target sample is an adversarial sample can be determined on the basis of the first gain value or multiple gain values obtained by repeating the process above.
机译:一种识别敌人样本以保护隐私安全的方法。该方法包括:首先采样与私有数据相关的多个非对抗性样本,以获得第一控制样品集;然后将待测试的目标样品添加到第一控制样品集中,以便获得第一实验样品设定;接下来,单独使用第一控制样品集和第一个实验样品设定为训练初始机器学习模型,以便获得训练有素的第一控制模型和训练有素的第一实验模型;然后,使用测试样本集以单独地对第一控制模型和第一实验模型进行性能评估,以便获得预设评估指标的第一控制值和第一实验值;接下来,计算第一控制值与第一实验值之间的差值,作为用于模型性能的目标样本的第一增益值。因此,可以基于通过重复上述方法获得的第一增益值或多个增益值来确定目标样本是否是对抗性样本。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号