Login| Sign Up| Help| Contact|

Patent Searching and Data


Title:
METHOD AND APPARATUS FOR CERTIFYING DEFENSE AGAINST IMAGE TRANSFORMATION
Document Type and Number:
WIPO Patent Application WO/2023/225999
Kind Code:
A1
Abstract:
A method for certifying defense against image transformation is disclosed. The method comprises generating a surrogate neural network consisting of three individual neural networks to simulate the image transformation, wherein a first neural network is an encoder for transformation parameters, a second neural network is an encoder for input images, a third neural network is a transformation network for outputs of the first and second neural networks, and the transformation parameters are augmented in dimension and added to the surrogate neural network. The method further comprises certifying the defense against the image transformation by using the surrogate neural network based on randomized smoothing.

Inventors:
ZHU JUN (CN)
HAO ZHONGKAI (CN)
YING CHENGYANG (CN)
DONG YINPENG (CN)
SU HANG (CN)
SONG JIAN (CN)
CHENG ZE (CN)
Application Number:
PCT/CN2022/095571
Publication Date:
November 30, 2023
Filing Date:
May 27, 2022
Export Citation:
Click for automatic bibliography generation   Help
Assignee:
BOSCH GMBH ROBERT (DE)
UNIV TSINGHUA (CN)
International Classes:
G06N3/04; G06N3/08
Foreign References:
EP3648015A22020-05-06
US20190244103A12019-08-08
US20210166123A12021-06-03
US10984272B12021-04-20
US20220030246A12022-01-27
CN110796608A2020-02-14
US20210300433A12021-09-30
Attorney, Agent or Firm:
NTD PATENT & TRADEMARK AGENCY LTD. (CN)
Download PDF: