Real-Time Robust Video Object Detection System Against Physical-World Adversarial Attacks

被引:1
|
作者
Han, Husheng [1 ,2 ,3 ]
Hu, Xing [1 ,4 ]
Hao, Yifan [3 ]
Xu, Kaidi [5 ]
Dang, Pucheng [1 ,2 ,3 ]
Wang, Ying [6 ]
Zhao, Yongwei [7 ]
Du, Zidong [1 ,4 ]
Guo, Qi
Wang, Yanzhi [6 ]
Zhang, Xishan [1 ,7 ]
Chen, Tianshi [8 ]
机构
[1] Chinese Acad Sci, Inst Comp Technol, State Key Lab Processors, Beijing 100190, Peoples R China
[2] Univ Chinese Acad Sci, Sch Comp Sci, Beijing 100049, Peoples R China
[3] Cambricon Technol, Dept Architecture Algorithm, Beijing 100191, Peoples R China
[4] Chinese Acad Sci, Shanghai Innovat Ctr Processor Technol, Beijing 100190, Peoples R China
[5] Drexel Univ, Coll Comp & Informat, Dept Comp Sci, Philadelphia, PA 19104 USA
[6] Northeastern Univ, Dept Elect & Comp Engn, Boston, MA 02115 USA
[7] Cambricon Technol, Dept Architecture Algorithm, Beijing 100191, Peoples R China
[8] Cambricon Technol, Beijing 100191, Peoples R China
关键词
Object detection; Streaming media; Optical flow; Feature extraction; Real-time systems; Task analysis; Detectors; Adversarial patch attack; deep learning security; domain-specific accelerator; hardware/software co-design; real time;
D O I
10.1109/TCAD.2023.3305932
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
DNN-based video object detection (VOD) powers autonomous driving and video surveillance industries with rising importance and promising opportunities. However, adversarial patch attack yields huge concern in live vision tasks because of its practicality, feasibility, and powerful attack effectiveness. This work proposes Themis, a software/hardware system to defend against adversarial patches for real-time robust VOD. We observe that adversarial patches exhibit extremely localized superficial feature importance in a small region with nonrobust predictions, and thus propose the adversarial region detection algorithm for adversarial effect elimination. Themis also proposes a systematic design to efficiently support the algorithm by eliminating redundant computations and memory traffics. Experimental results show that the proposed methodology can effectively recover the system from the adversarial attack with negligible hardware overhead.
引用
收藏
页码:366 / 379
页数:14
相关论文
共 50 条
  • [1] Robust Physical-World Attacks on Face Recognition
    Zheng, Xin
    Fan, Yanbo
    Wu, Baoyuan
    Zhang, Yong
    Wang, Jue
    Pan, Shirui
    PATTERN RECOGNITION, 2023, 133
  • [2] Towards a physical-world adversarial patch for blinding object detection models
    Wang, Yajie
    Lv, Haoran
    Kuang, Xiaohui
    Zhao, Gang
    Tan, Yu-an
    Zhang, Quanxin
    Hu, Jingjing
    INFORMATION SCIENCES, 2021, 556 : 459 - 471
  • [3] Adversarial Camera Patch: An Effective and Robust Physical-World Attack on Object Detectors
    Tiliwalidi, Kalibinuer
    Hui, Bei
    Hui, Chengyin
    Ge, Jingjing
    PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY, ICCWS 2024, 2024, 19 : 374 - 384
  • [4] Adversarial Objectness Gradient Attacks in Real-time Object Detection Systems
    Chow, Ka-Ho
    Liu, Ling
    Loper, Margaret
    Bae, Juhyun
    Gursoy, Mehmet Emre
    Truex, Stacey
    Wei, Wenqi
    Wu, Yanzhao
    2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 263 - 272
  • [5] Adversarial Camouflage: Hiding Physical-World Attacks with Natural Styles
    Duan, Ranjie
    Ma, Xingjun
    Wang, Yisen
    Bailey, James
    Qin, A. K.
    Yang, Yun
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 997 - 1005
  • [6] REAL-TIME, UNIVERSAL, AND ROBUST ADVERSARIAL ATTACKS AGAINST SPEAKER RECOGNITION SYSTEMS
    Xie, Yi
    Shi, Cong
    Lie, Zhuohang
    Liu, Jian
    Chen, Yingying
    Yuan, Bo
    2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 1738 - 1742
  • [7] ROSA: Robust Salient Object Detection Against Adversarial Attacks
    Li, Haofeng
    Li, Guanbin
    Yu, Yizhou
    IEEE TRANSACTIONS ON CYBERNETICS, 2020, 50 (11) : 4835 - 4847
  • [8] Self-Supervised Adversarial Training of Monocular Depth Estimation Against Physical-World Attacks
    Cheng, Zhiyuan
    Han, Cheng
    Liang, James
    Wang, Qifan
    Zhang, Xiangyu
    Liu, Dongfang
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2024, 46 (12) : 9084 - 9101
  • [9] A robust real-time object detection and tracking system
    Yue, Zhanfeng
    Narasimha, Pramod Lakshmi
    Topiwala, Pankaj
    ACQUISITION, TRACKING, POINTING, AND LASER SYSTEMS TECHNOLOGIES XXII, 2008, 6971
  • [10] Survey of Physical Adversarial Attacks Against Object Detection Models
    Cai, Wei
    Di, Xingyu
    Jiang, Xinhao
    Wang, Xin
    Gao, Weijie
    Computer Engineering and Applications, 2024, 60 (10) : 61 - 75