Font Size: a A A

Research On Adversarial Attack And Defenseof EEG-based Emotion Recognition

Posted on:2024-03-28Degree:MasterType:Thesis
Country:ChinaCandidate:D Y ZhangFull Text:PDF
GTID:2530307079460464Subject:Software engineering
Abstract/Summary:
EEG signals come from the central nervous system and are closely related to human emotion changes.It is one of the most important research objects in the field of emotion recognition.As new efficient algorithms and models are constantly proposed in the computer field,deep learning is also gradually applied to EEG processing,feature extraction,emotion recognition and other fields.However,with the deepening of the research,the vulnerability of deep learning algorithms has also attracted wide attention,among which the counter attack is one of the most powerful methods.In order to test whether there are security problems in using deep learning related algorithms and technologies in the emotion recognition problem based on EEG,this paper respectively conducts offensive and defensive studies on emotion recognition based on single mode EEG and emotion recognition based on multi-mode EEG.Under the condition of ensuring the feasibility of deep learning model of emotion recognition,This paper probes into the threat of counterattack to the emotion recognition problem of singlemode and multimode EEG signals and puts forward the corresponding defensive measures,which are verified on the data set.In the adversarial attack research based on the emotion recognition problem of single mode EEG,EEG samples for the antagonistic attack experiment are firstly made according to the characteristics of single mode EEG and the input characteristics of antagonistic attack.In order to more comprehensively verify the effectiveness of antagonistic attack on the emotion recognition field of EEG,In this paper,a variety of single-step adversarial attacks and iterative adversarial attacks are simulated respectively under white box,black box and grey box conditions.At the same time,each method is tested on different data sets.The results show that adversarial attacks have the potential to attack the emotion recognition model based on EEG.For example,the classification accuracy of the model can be reduced from 89.74% to 0.8% when the attack capability is the strongest.In the research of adversarial attack based on multimodal EEG signal emotion recognition problem,the layered CNN model is applied to the recognition of multimode EEG in the sample production stage.This method can obtain the multi-mode data set with better characteristics and improve the accuracy of the model’s emotion recognition.The classification accuracy of multi-modal data sets DEAP and MAHNOB-HCI was improved to 92.11% and 89.60%,respectively.Similarly,a variety of different antagonistic attacks are carried out on the multi-modal EEG recognition model.The experimental results show that the antagonistic attack method can also destroy the recognition ability of the emotion recognition model based on the multimodal EEG,which has a strong threat.In order to reduce the impact of adversarial attacks,this thesis proposes an improved iterative hybrid NAT adversarial training method,which makes up for the shortcomings of incomplete training signal samples,makes the emotion recognition model more robust,and can resist the harm of adversarial attacks to a certain extent.The effectiveness and feasibility of the proposed method have been verified on different single-modal EEG datasets and multi-modal EEG datasets.
Keywords/Search Tags:EEG signals, emotion recognition, adversarial attack, adversarial training, multimodal signals
Related items