Toward Generic and Controllable Attacks Against Object Detection

被引:1
|
作者
Li, Guopeng [1 ]
Xu, Yue [2 ]
Ding, Jian [3 ]
Xia, Gui-Song [4 ,5 ]
机构
[1] Wuhan Univ, Sch Comp Sci, Wuhan 430079, Peoples R China
[2] Wuhan Univ, Sch Cyber Sci & Engn, Wuhan 430079, Peoples R China
[3] Wuhan Univ, State Key Lab LIESMARS, Wuhan 430079, Peoples R China
[4] Wuhan Univ, Natl Engn Res Ctr Multimedia Software, Sch Comp Sci, Wuhan 430072, Peoples R China
[5] Wuhan Univ, Inst Artificial Intelligence, Wuhan 430072, Peoples R China
来源
IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING | 2024年 / 62卷
基金
中国国家自然科学基金;
关键词
Perturbation methods; Detectors; Object detection; Proposals; Glass box; Robustness; Optimization; Adversarial examples (AE); controllable imperceptibility; generic attacks; object detection;
D O I
10.1109/TGRS.2024.3417958
中图分类号
P3 [地球物理学]; P59 [地球化学];
学科分类号
0708 ; 070902 ;
摘要
Existing adversarial attacks against object detectors (ODs) have two inherent limitations. First, ODs have complex meta-structure designs, hence most advanced attacks for ODs concentrate on attacking specific detector-intrinsic structures [e.g., RPN and nonmaximal suppression (NMS)], which makes it hard for them to work on other new detectors. Second, most works against ODs make adversarial examples (AEs) by adding image-level perturbations into original images, which brings redundant perturbations in semantically meaningless areas (e.g., backgrounds). This article proposes a generic white-box attack on mainstream ODs with controllable perturbations. For a generic attack, LGP treats ODs as black boxes and only attacks their outputs, thereby eliminating the limitations of detector-intrinsic structures. Regarding controllability, we establish an object-wise constraint to induce the attachment of perturbations to foregrounds. Experimentally, the proposed LGP successfully attacked 16 state-of-the-art ODs on MS-COCO and DOTA datasets, with promising imperceptibility and transferability obtained. Code is publicly released in https://github.com/liguopeng0923/LGP.git.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] ROSA: Robust Salient Object Detection Against Adversarial Attacks
    Li, Haofeng
    Li, Guanbin
    Yu, Yizhou
    IEEE TRANSACTIONS ON CYBERNETICS, 2020, 50 (11) : 4835 - 4847
  • [2] Pattern Corruption-Assisted Physical Attacks Against Object Detection in UAV Remote Sensing
    Zhang, Yu
    Gong, Zhiqiang
    Wen, Hao
    Hu, Xikun
    Xia, Xiaoyan
    Jiang, Hejun
    Zhong, Ping
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2024, 17 : 12931 - 12944
  • [3] Threatening Patch Attacks on Object Detection in Optical Remote Sensing Images
    Sun, Xuxiang
    Cheng, Gong
    Pei, Lei
    Li, Hongda
    Han, Junwei
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2023, 61
  • [4] Gaussian Combined Distance: A Generic Metric for Object Detection
    Guan, Ziqian
    Fu, Xieyi
    Huang, Pengjun
    Zhang, Hengyuan
    Du, Hubin
    Liu, Yongtao
    Wang, Yinglin
    Ma, Qang
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2025, 22
  • [5] INFORMATION DISTRIBUTION BASED DEFENSE AGAINST PHYSICAL ATTACKS ON OBJECT DETECTION
    Zhou, Guangzhi
    Gao, Hongchao
    Chen, Peng
    Liu, Jin
    Dai, Jiao
    Han, Jizhong
    Li, Ruixuan
    2020 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO WORKSHOPS (ICMEW), 2020,
  • [6] Physical Adversarial Attacks Against Aerial Object Detection With Feature-Aligned Expandable Textures
    Zhang, Yu
    Chen, Jianqi
    Peng, Zhenbang
    Dang, Yi
    Shi, Zhenwei
    Zou, Zhengxia
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62
  • [7] Deep Regionlets: Blended Representation and Deep Learning for Generic Object Detection
    Xu, Hongyu
    Lv, Xutao
    Wang, Xiaoyu
    Ren, Zhou
    Bodla, Navaneeth
    Chellappa, Rama
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2021, 43 (06) : 1914 - 1927
  • [8] Regionlets for Generic Object Detection
    Wang, Xiaoyu
    Yang, Ming
    Zhu, Shenghuo
    Lin, Yuanqing
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2015, 37 (10) : 2071 - 2084
  • [9] Adversarial Attacks for Object Detection
    Xu, Bo
    Zhu, Jinlin
    Wang, Danwei
    PROCEEDINGS OF THE 39TH CHINESE CONTROL CONFERENCE, 2020, : 7281 - 7287
  • [10] Using bilateral filtering and autoencoder to defend against adversarial attacks for object detection
    Wang, Xiaoqin
    Sun, Lei
    Mao, Xiuqing
    Yang, Youhuan
    Liu, Peiyuan
    JOURNAL OF ELECTRONIC IMAGING, 2022, 31 (04)