Transferable Adversarial Attacks for Object Detection Using Object-Aware Significant Feature Distortion

被引:0
|
作者
Ding, Xinlong [1 ]
Chen, Jiansheng [1 ]
Yu, Hongwei [1 ]
Shang, Yu [2 ]
Qin, Yining [1 ]
Ma, Huimin [1 ]
机构
[1] Univ Sci & Technol Beijing, Sch Comp & Commun Engn, Beijing, Peoples R China
[2] Tsinghua Univ, Dept Elect Engn, Beijing, Peoples R China
基金
国家重点研发计划; 中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Transferable black-box adversarial attacks against classifiers by disturbing the intermediate-layer features have been extensively studied in recent years. However, these methods have not yet achieved satisfactory performances when directly applied to object detectors. This is largely because the features of detectors are fundamentally different from that of the classifiers. In this study, we propose a simple but effective method to improve the transferability of adversarial examples for object detectors by leveraging the properties of spatial consistency and limited equivariance of object detectors' features. Specifically, we combine a novel loss function and deliberately designed data augmentation to distort the backbone features of object detectors by suppressing significant features corresponding to objects and amplifying the surrounding vicinal features corresponding to object boundaries. As such the target object and background area on the generated adversarial samples are more likely to be confused by other detectors. Extensive experimental results show that our proposed method achieves state-of-the-art black-box transferability for untargeted attacks on various models, including one/two-stage, CNN/Transformer-based, and anchorfree/anchor-based detectors.
引用
收藏
页码:1546 / 1554
页数:9
相关论文
共 50 条
  • [1] Transferable Adversarial Attacks for Image and Video Object Detection
    Wei, Xingxing
    Liang, Siyuan
    Chen, Ning
    Cao, Xiaochun
    PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 954 - 960
  • [2] Object-Aware Domain Generalization for Object Detection
    Lee, Wooju
    Hong, Dasol
    Lim, Hyungtae
    Myung, Hyun
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 4, 2024, : 2947 - 2955
  • [3] Object-aware Image Compression with Adversarial Learning
    Du, Yunfei
    Zhao, Nan
    Duan, Yiping
    Han, Chaoyi
    2019 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA (ICCC), 2019,
  • [4] Cross-domain object detection by local to global object-aware feature alignment
    Yiguo Song
    Zhenyu Liu
    Ruining Tang
    Guifang Duan
    Jianrong Tan
    Neural Computing and Applications, 2024, 36 : 3631 - 3644
  • [5] Cross-domain object detection by local to global object-aware feature alignment
    Song, Yiguo
    Liu, Zhenyu
    Tang, Ruining
    Duan, Guifang
    Tan, Jianrong
    NEURAL COMPUTING & APPLICATIONS, 2024, 36 (07): : 3631 - 3644
  • [6] Object-aware deep feature extraction for feature matching
    Li, Zuoyong
    Wang, Weice
    Lai, Taotao
    Xu, Haiping
    Keikhosrokiani, Pantea
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (05):
  • [7] Object-aware Gaze Target Detection
    Tonini, Francesco
    Dall'Asen, Nicola
    Beyan, Cigdem
    Ricci, Elisa
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2023), 2023, : 21803 - 21812
  • [8] Feature Importance-aware Transferable Adversarial Attacks
    Wang, Zhibo
    Guo, Hengchang
    Zhang, Zhifei
    Liu, Wenxin
    Qin, Zhan
    Ren, Kui
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7619 - 7628
  • [9] Object-Aware Instance Labeling forWeakly Supervised Object Detection
    Kosugi, Satoshi
    Yamasaki, Toshihiko
    Aizawa, Kiyoharu
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 6063 - 6071
  • [10] Adversarial Attacks for Object Detection
    Xu, Bo
    Zhu, Jinlin
    Wang, Danwei
    PROCEEDINGS OF THE 39TH CHINESE CONTROL CONFERENCE, 2020, : 7281 - 7287