The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 14, 2025

Filed:

Mar. 21, 2022
Applicant:

Xidian University, Xi'an, CN;

Inventors:

Yang Xiao, Xi'an, CN;

Chengjia Yan, Xi'an, CN;

Qingqi Pei, Xi'an, CN;

Assignee:

XIDIAN UNIVERSITY, Xi'an, CN;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06K 9/62 (2022.01); G06F 18/213 (2023.01); G06F 18/214 (2023.01); G06F 18/22 (2023.01); G06F 18/2415 (2023.01); G06T 5/70 (2024.01); G06V 30/164 (2022.01); G06V 30/18 (2022.01);
U.S. Cl.
CPC ...
G06F 18/2415 (2023.01); G06F 18/213 (2023.01); G06F 18/214 (2023.01); G06F 18/22 (2023.01); G06T 5/70 (2024.01); G06T 2207/20081 (2013.01); G06V 30/164 (2022.01); G06V 30/18 (2022.01);
Abstract

A method for defending against an adversarial sample in image classification includes: denoising, by an adversarial denoising network, an input image to acquire a reconstructed image; acquiring, by a target classification model, a predicted category probability distribution of the reconstructed image; acquiring, by the target classification model, a predicted category probability distribution of the original input image; calculating an adversarial score of the input image, and determining the input image as an adversarial sample or a benign sample according to a threshold; outputting a category prediction result of the reconstructed image if the input image is determined as the adversarial sample; and outputting a category prediction result of the original input image if the input image is determined as the benign sample. A system for defending against an adversarial sample in image classification, and a data processing terminal are further provided.


Find Patent Forward Citations

Loading…