针对目标检测的隐蔽式对抗扰动生成方法
DOI:
CSTR:
作者:
作者单位:

(1.天津大学 微电子学院,天津 300072; 2.天津师范大学 数学科学学院,天津300382; 3.天津市成像与感知微电子技术重点实验室,天津 300072)

作者简介:

史再峰 (1977-),男,博士,副教授,硕士/博士生导师,主要从事影像感知与智能计算、CT影像处理方面的研究.

通讯作者:

中图分类号:

基金项目:

国家自然科学基金(62071326)资助项目


Stealthy adversarial perturbation generation method for object detection
Author:
Affiliation:

(1.School of Microelectronics, Tianjin University, Tianjin 300072, China;2.School of Mathematical Sciences, Tianjin Normal University, Tianjin 300382, China;3.Tianjin Key Laboratory of Imaging and Sensing Microelectronic Technology, Tianjin 300072, China)

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    针对现有面向目标检测的白盒攻击方法在不可察觉性上的不足,从扰动生成过程与扰动成本的限制两方面,提出一种隐蔽式对抗扰动生成方法(stealthy adversarial perturbation generation,SPG)。 该方法首先利用图像的纹理信息,赋予扰动在难以被人眼察觉的高纹理区域更高的权重,然后采用扰动位置选取策略降低修改的像素点数目,最后进行对抗扰动的解耦计算,自适应地搜索具有最佳L2范数度量的对抗扰动。所提方法以4种主流目标检测器作为攻击对象,在COCO-MS 2014和PASCAL-VOC数据集上与对比方法进行了评估。实验结果表明,本文攻击方法的不可察觉性的度量值优于对比方法,其生成的对抗扰动具有低于0.239的L0范数和2.9×10-5以内的L2范数,同时使得目录检测器的mAP降低至9%以下。

    Abstract:

    To address the shortcomings of the current white-box adversarial attacks against object detection about imperceptibility,this paper proposes a stealthy adversarial perturbations generation (SPG) method from the perspective of both generation process and the limitation of perturbations cost.First,the perturbations in the high-texture region of images which is hard to detected by human eyes are assigned a higher weight by texture information.Then,a perturbations position selection strategy is applied to reduce the number of improved perturbed pixels.Finally,these adversarial perturbations are decoupled to adaptively search for the best L2 norm metric.The proposed method and comparative methods are evaluated on the MS-COCO 2014 and PASCAL-VOC datasets against 4 dominant object detectors.Experimental results show that the metric value of imperceptibility of this method is greater than that of other methods.The mAP of the object detectors is degraded to below 9%.The L0 norm is less than 0.239,and the L2 norm of adversarial perturbations is less than 2.9×10-5 respectively.

    参考文献
    相似文献
    引证文献
引用本文

丁程,史再峰,佟博文,王若琪,曹清洁.针对目标检测的隐蔽式对抗扰动生成方法[J].光电子激光,2023,34(9):915~922

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2022-03-06
  • 最后修改日期:2022-10-29
  • 录用日期:
  • 在线发布日期: 2023-10-24
  • 出版日期:
文章二维码