Transferable Adversarial Attacks for Image and Video Object Detection

被引:0
|
作者
Wei, Xingxing [1 ]
Liang, Siyuan [2 ]
Chen, Ning [1 ]
Cao, Xiaochun [2 ]
机构
[1] Tsinghua Univ, THBI Lab, State Key Lab Intell Tech & Syst, Dept Comp Sci & Tech Inst Artificial Intelligence, Beijing, Peoples R China
[2] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
基金
中国博士后科学基金;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Identifying adversarial examples is beneficial for understanding deep networks and developing robust models. However, existing attacking methods for image object detection have two limitations: weak transferability-the generated adversarial examples often have a low success rate to attack other kinds of detection methods, and high computation cost-they need much time to deal with video data, where many frames need polluting. To address these issues, we present a generative method to obtain adversarial images and videos, thereby significantly reducing the processing time. To enhance transferability, we manipulate the feature maps extracted by a feature network, which usually constitutes the basis of object detectors. Our method is based on the Generative Adversarial Network (GAN) framework, where we combine a high-level class loss and a low-level feature loss to jointly train the adversarial example generator. Experimental results on PASCAL VOC and ImageNet VID datasets show that our method efficiently generates image and video adversarial examples, and more importantly, these adversarial examples have better transferability, therefore being able to simultaneously attack two kinds of representative object detection models: proposal based models like Faster-RCNN and regression based models like SSD.
引用
收藏
页码:954 / 960
页数:7
相关论文
共 50 条
  • [41] Transferable Adversarial Attacks on Vision Transformers with Token Gradient Regularization
    Zhang, Jianping
    Huang, Yizhan
    Wu, Weibin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 16415 - 16424
  • [42] Prompt-Driven Contrastive Learning for Transferable Adversarial Attacks
    Yang, Hunmin
    Jeong, Jongoh
    Yoon, Kuk-Jin
    COMPUTER VISION-ECCV 2024, PT XLIII, 2025, 15101 : 36 - 53
  • [43] ATTA: Adversarial Task -transferable Attacks on Autonomous Driving Systems
    Hang, Qingjie
    Hang, Maosen
    Qiu, Han
    Hang, Tianwei
    Msahli, Mounira
    Memmi, Gerard
    23RD IEEE INTERNATIONAL CONFERENCE ON DATA MINING, ICDM 2023, 2023, : 798 - 807
  • [44] DIVERSE GENERATIVE PERTURBATIONS ON ATTENTION SPACE FOR TRANSFERABLE ADVERSARIAL ATTACKS
    Kim, Woo Jae
    Hong, Seunghoon
    Yoon, Sung-Eui
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 281 - 285
  • [45] Using bilateral filtering and autoencoder to defend against adversarial attacks for object detection
    Wang, Xiaoqin
    Sun, Lei
    Mao, Xiuqing
    Yang, Youhuan
    Liu, Peiyuan
    JOURNAL OF ELECTRONIC IMAGING, 2022, 31 (04)
  • [46] ADC: Adversarial attacks against object Detection that evade Context consistency checks
    Yin, Mingjun
    Li, Shasha
    Song, Chengyu
    Asif, M. Salman
    Roy-Chowdhury, Amit K.
    Krishnamurthy, Srikanth, V
    2022 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2022), 2022, : 2836 - 2845
  • [47] Adversarial Objectness Gradient Attacks in Real-time Object Detection Systems
    Chow, Ka-Ho
    Liu, Ling
    Loper, Margaret
    Bae, Juhyun
    Gursoy, Mehmet Emre
    Truex, Stacey
    Wei, Wenqi
    Wu, Yanzhao
    2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 263 - 272
  • [48] Salient object detection dataset with adversarial attacks for genetic programming and neural networks
    Olague, Matthieu
    Olague, Gustavo
    Pineda, Roberto
    Ibarra-Vazquez, Gerardo
    DATA IN BRIEF, 2024, 57
  • [49] DETECTION OF ADVERSARIAL ATTACKS AND CHARACTERIZATION OF ADVERSARIAL SUBSPACE
    Esmaeilpour, Mohammad
    Cardinal, Patrick
    Koerich, Alessandro Lameiras
    2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 3097 - 3101
  • [50] Adversarial Stylometry in the Wild: Transferable Lexical Substitution Attacks on Author Profiling
    Emmery, Chris
    Kadar, Akos
    Chrupala, Grzegorz
    16TH CONFERENCE OF THE EUROPEAN CHAPTER OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (EACL 2021), 2021, : 2388 - 2402