SSIM-Based Autoencoder Modeling to Defeat Adversarial Patch Attacks

被引:1
作者
Lee, Seungyeol [1 ]
Hong, Seongwoo [1 ]
Kim, Gwangyeol [2 ]
Ha, Jaecheol [1 ]
机构
[1] Hoseo Univ, Dept Informat Secur, Asan 31499, South Korea
[2] Sinsiway Inc, Seoul 05836, South Korea
关键词
object detection; YOLO; adversarial patch attack; structural similarity index measure; autoencoder;
D O I
10.3390/s24196461
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Object detection systems are used in various fields such as autonomous vehicles and facial recognition. In particular, object detection using deep learning networks enables real-time processing in low-performance edge devices and can maintain high detection rates. However, edge devices that operate far from administrators are vulnerable to various physical attacks by malicious adversaries. In this paper, we implement a function for detecting traffic signs by using You Only Look Once (YOLO) as well as Faster-RCNN, which can be adopted by edge devices of autonomous vehicles. Then, assuming the role of a malicious attacker, we executed adversarial patch attacks with Adv-Patch and Dpatch. Trying to cause misdetection of traffic stop signs by using Adv-Patch and Dpatch, we confirmed the attacks can succeed with a high probability. To defeat these attacks, we propose an image reconstruction method using an autoencoder and the Structural Similarity Index Measure (SSIM). We confirm that the proposed method can sufficiently defend against an attack, attaining a mean Average Precision (mAP) of 91.46% even when two adversarial attacks are launched.
引用
收藏
页数:13
相关论文
共 24 条
[1]  
[Anonymous], 2016, P NEUR INF PROC SYST
[2]  
Brown T.B., 2017, P NIPS 2017 WORKSH M
[3]   Towards Evaluating the Robustness of Neural Networks [J].
Carlini, Nicholas ;
Wagner, David .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :39-57
[4]  
Chan H.L., 2022, TrafficSign detection Dataset Open Source Dataset
[5]   Robust Physical-World Attacks on Deep Learning Visual Classification [J].
Eykholt, Kevin ;
Evtimov, Ivan ;
Fernandes, Earlence ;
Li, Bo ;
Rahmati, Amir ;
Xiao, Chaowei ;
Prakash, Atul ;
Kohno, Tadayoshi ;
Song, Dawn .
2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, :1625-1634
[6]  
Goodfellow I.J., 2015, 2015 INT C LEARN REP
[7]   Naturalistic Physical Adversarial Patch for Object Detectors [J].
Hu, Yu-Chih-Tuan ;
Kung, Bo-Han ;
Tan, Daniel Stanley ;
Chen, Jun-Cheng ;
Hua, Kai-Lung ;
Cheng, Wen-Huang .
2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, :7828-7837
[8]  
Jiang L., 2024, P IEEE CVF C COMP VI, P14973
[9]  
Lengyel H., 2019, PERNERS CONTACTS, V27, P156
[10]   Microsoft COCO: Common Objects in Context [J].
Lin, Tsung-Yi ;
Maire, Michael ;
Belongie, Serge ;
Hays, James ;
Perona, Pietro ;
Ramanan, Deva ;
Dollar, Piotr ;
Zitnick, C. Lawrence .
COMPUTER VISION - ECCV 2014, PT V, 2014, 8693 :740-755