Defense method and an application against adversarial examples based on feature remapping
US11921819B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jul 21, 2020 |
| Grant date | Mar 5, 2024 |
| Priority date | — |
| Expiry date | Feb 9, 2041 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06V10/7747
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
A defense method against adversarial examples based on feature remapping, includes the following steps: building the feature remapping model, the feature remapping model is composed of the significant feature generation model and the nonsignificant feature generation model, and a shared discriminant model, the significant generation model is used to generate significant features, the nonsignificant generation model is used to generate nonsignificant features, and the shared discriminant model is used to discriminate fake or true of generated significant and nonsignificant features. The method combines the significant feature generation model and the nonsignificant feature generation model to build the detector that is used to detect adversarial examples and benign examples; builds the re-recognizer according to the significant feature generation model, the re-recognizer is used to recognize the type of adversarial examples while detecting; connects the detector to the output of the target model, and then use the detector to detect adversarial examples. While recognizing adversarial examples, the method connects the re-recognizer to the output of the target model, and then uses the …
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.