Adversarial patch attacks against aerial imagery object detectors

被引:14
|
作者
Tang, Guijian [1 ,2 ]
Jiang, Tingsong [2 ]
Zhou, Weien [2 ]
Li, Chao [2 ,3 ]
Yao, Wen [2 ]
Zhao, Yong [1 ]
机构
[1] Natl Univ Def Technol, Coll Aerosp Sci & Engn, 109 Deya Rd, Changsha 410073, Peoples R China
[2] Chinese Acad Mil Sci, Def Innovat Inst, 53 Fengtai East St, Beijing 100071, Peoples R China
[3] Xidian Univ, Sch Artificial Intelligence, Xian 710071, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial patch attacks; Aerial imagery; Object detection; Black; -box;
D O I
10.1016/j.neucom.2023.03.050
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Although Deep Neural Networks (DNNs)-based object detectors are widely used in various fields, espe-cially on aerial imagery object detections, it has been observed that a small elaborately designed patch attached to the images can mislead the DNNs-based detectors into producing erroneous output. However, the target detectors being attacked are quite simple, and the attack efficiency is relatively low in previous works, making it not practicable in real scenarios. To address these limitations, a new adversarial patch attack algorithm is proposed in this paper. Firstly, we designed a novel loss function using the intermediate outputs of the models rather than the model's final outputs interpreted by the detection head to optimize adversarial patches. The experiments conducted on the DOTA, RSOD, and NWPU VHR-10 datasets demonstrate that our method can significantly degrade the performance of the detectors. Secondly, we conducted intensive experiments to investigate the impact of different out-puts of the detection model on generating adversarial patches, demonstrating the class score is not as effective as the objectness score. Thirdly, we comprehensively analyzed the attack transferability across different aerial imagery datasets, verifying that the patches generated on one dataset are also effective in attacking another. Moreover, we proposed ensemble training to boost the attack's transferability across models. Our work alarms the application of DNNs-based object detectors in aerial imagery.(c) 2023 Elsevier B.V. All rights reserved.
引用
收藏
页码:128 / 140
页数:13
相关论文
共 50 条
  • [1] Adversarial patch-based false positive creation attacks against aerial imagery object detectors
    Tang, Guijian
    Yao, Wen
    Jiang, Tingsong
    Zhao, Yong
    Sun, Jialiang
    NEUROCOMPUTING, 2024, 579
  • [2] CodeMosaic Patch: Physical Adversarial Attacks Against Infrared Aerial Object Detectors
    He, Hangwei
    Wu, Libing
    Wang, Enshu
    Wang, Yizhou
    Zhao, Yu
    PRICAI 2024: TRENDS IN ARTIFICIAL INTELLIGENCE, PT I, 2025, 15281 : 54 - 68
  • [3] Black-box adversarial patch attacks using differential evolution against aerial imagery object detectors
    Tang, Guijian
    Yao, Wen
    Li, Chao
    Jiang, Tingsong
    Yang, Shaowu
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 137
  • [4] Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch Detection
    Liu, Jiang
    Levine, Alexander
    Lau, Chun Pong
    Chellappa, Rama
    Feizi, Soheil
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 14953 - 14962
  • [5] Physical Adversarial Attacks on an Aerial Imagery Object Detector
    Du, Andrew
    Chen, Bo
    Chin, Tat-Jun
    Law, Yee Wei
    Sasdelli, Michele
    Rajasegaran, Ramesh
    Campbell, Dillon
    2022 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2022), 2022, : 3798 - 3808
  • [6] Detecting Physical Adversarial Patch Attacks with Object Detectors
    Jutras, Melanie
    Liang, Ethan
    Leary, Sara
    Ward, Chris
    Manville, Keith
    2022 IEEE APPLIED IMAGERY PATTERN RECOGNITION WORKSHOP, AIPR, 2022,
  • [7] Invisibility Spell: Adversarial Patch Attack Against Object Detectors
    Zhang, Jianyi
    Guan, Ronglin
    Zhao, Zhangchi
    Li, Xiuying
    Sun, Zezheng
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, PT I, SECURECOMM 2023, 2025, 567 : 88 - 109
  • [8] Naturalistic Physical Adversarial Patch for Object Detectors
    Hu, Yu-Chih-Tuan
    Kung, Bo-Han
    Tan, Daniel Stanley
    Chen, Jun-Cheng
    Hua, Kai-Lung
    Cheng, Wen-Huang
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7828 - 7837
  • [9] ADVERSARIAL ATTACKS ON OBJECT DETECTORS WITH LIMITED PERTURBATIONS
    Shi, Zhenbo
    Yang, Wei
    Xu, Zhenbo
    Chen, Zhi
    Li, Yingjie
    Zhu, Haoran
    Huang, Liusheng
    2021 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP 2021), 2021, : 1375 - 1379
  • [10] DetectorGuard: Provably Securing Object Detectors against Localized Patch Hiding Attacks
    Xiang, Chong
    Mittal, Prateek
    CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 3177 - 3196