Methods and devices for evaluating performances of image identification model and image identification model attack method, and medium

Xiao Zihao,Gao Wei,Dong Yinpeng,Tian Tian,Zhu Jun
2020-01-01
International Scholarly Research Notices
Abstract:The invention provides methods and devices for evaluating the performances of an image identification model and an image identification model attack method, and a medium. The method for evaluating theperformance of an image identification model comprises the steps of obtaining an original sample and an adversarial sample generated based on the original sample; respectively identifying the original sample and the adversarial sample by adopting a to-be-evaluated image identification model to obtain respective identification results; and determining the performance of the image identification model according to the target number and/or the target classification situation in the identification results. The method for evaluating the performance of an image identification model attack method comprises the following steps of: acquiring an original sample and an adversarial sample generated based on the original sample by adopting a to-be-evaluated attack method; respectively identifying theoriginal sample and the adversarial sample by adopting an image identification model to obtain respective identification results; and determining the performance of the to-be-evaluated attack method according to the target number and/or the target classification situation in the identification result. The performances of an attack algorithm and a to-be-attacked model can be better evaluated.
What problem does this paper attempt to address?