Adversarial patch attacks against aerial imagery object detectors

被引:14
作者
Tang, Guijian [1 ,2 ]
Jiang, Tingsong [2 ]
Zhou, Weien [2 ]
Li, Chao [2 ,3 ]
Yao, Wen [2 ]
Zhao, Yong [1 ]
机构
[1] Natl Univ Def Technol, Coll Aerosp Sci & Engn, 109 Deya Rd, Changsha 410073, Peoples R China
[2] Chinese Acad Mil Sci, Def Innovat Inst, 53 Fengtai East St, Beijing 100071, Peoples R China
[3] Xidian Univ, Sch Artificial Intelligence, Xian 710071, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial patch attacks; Aerial imagery; Object detection; Black; -box;
D O I
10.1016/j.neucom.2023.03.050
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Although Deep Neural Networks (DNNs)-based object detectors are widely used in various fields, espe-cially on aerial imagery object detections, it has been observed that a small elaborately designed patch attached to the images can mislead the DNNs-based detectors into producing erroneous output. However, the target detectors being attacked are quite simple, and the attack efficiency is relatively low in previous works, making it not practicable in real scenarios. To address these limitations, a new adversarial patch attack algorithm is proposed in this paper. Firstly, we designed a novel loss function using the intermediate outputs of the models rather than the model's final outputs interpreted by the detection head to optimize adversarial patches. The experiments conducted on the DOTA, RSOD, and NWPU VHR-10 datasets demonstrate that our method can significantly degrade the performance of the detectors. Secondly, we conducted intensive experiments to investigate the impact of different out-puts of the detection model on generating adversarial patches, demonstrating the class score is not as effective as the objectness score. Thirdly, we comprehensively analyzed the attack transferability across different aerial imagery datasets, verifying that the patches generated on one dataset are also effective in attacking another. Moreover, we proposed ensemble training to boost the attack's transferability across models. Our work alarms the application of DNNs-based object detectors in aerial imagery.(c) 2023 Elsevier B.V. All rights reserved.
引用
收藏
页码:128 / 140
页数:13
相关论文
共 50 条
  • [21] Semi-Supervised Exemplar Learning for Object Detection in Aerial Imagery
    Overbey, Lucas A.
    Lyle, Jamie
    Pan, Jean
    Holt, Branson
    Jaegar, Alan
    Jaeger, Ryan
    van Epps, Todd
    Ruane, Martin
    [J]. GEOSPATIAL INFORMATICS XI, 2021, 11733
  • [22] Object detection on aerial imagery to improve situational awareness for ground vehicles
    Hadia, Xian
    Price, Stanton R.
    Price, Steven R.
    Price, Stephanie J.
    Fairley, Joshua R.
    [J]. ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS II, 2020, 11413
  • [23] Small Object Detection in Aerial Imagery using RetinaNet with Anchor Optimization
    Ahmad, Mobeen
    Abdullah, Muhammad
    Han, Dongil
    [J]. 2020 INTERNATIONAL CONFERENCE ON ELECTRONICS, INFORMATION, AND COMMUNICATION (ICEIC), 2020,
  • [24] Understanding Black-Box Attacks Against Object Detectors from a User's Perspective
    Midtlid, Kim Andre
    Asheim, Johannes
    Li, Jingyue
    [J]. QUALITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY, QUATIC 2022, 2022, 1621 : 266 - 280
  • [25] Adversarial Attacks to Manipulate Target Localization of Object Detector
    Xu, Kai
    Cheng, Xiao
    Qiao, Ji
    Li, Jia-Teng
    Ji, Kai-Xuan
    Zhong, Jia-Yong
    Tian, Peng
    Mi, Jian-Xun
    [J]. IEEE ACCESS, 2024, 12 : 179418 - 179430
  • [26] Lightweight Object Detection Algorithm for UAV Aerial Imagery
    Wang, Jian
    Zhang, Fei
    Zhang, Yuesong
    Liu, Yahui
    Cheng, Ting
    [J]. SENSORS, 2023, 23 (13)
  • [27] Adversarial Pixel Masking: A Defense against Physical A.acks for Pre-trained Object Detectors
    Chiang, Ping-Han
    Chan, Chi-Shen
    Wu, Shan-Hung
    [J]. PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 1856 - 1865
  • [28] Object Detection with RetinaNet on Aerial Imagery: The Algarve Landscape
    Coelho, C.
    Costa, M. Fernanda P.
    Ferras, L. L.
    Soares, A. J.
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2021, PT II, 2021, 12950 : 501 - 516
  • [29] Location-independent adversarial patch generation for object detection
    Ding, Zhiyi
    Sun, Lei
    Mao, Xiuqing
    Dai, Leyu
    Xu, Bayi
    [J]. JOURNAL OF ELECTRONIC IMAGING, 2023, 32 (04)
  • [30] Adversarial attacks on Faster R-CNN object detector
    Wang, Yutong
    Wang, Kunfeng
    Zhu, Zhanxing
    Wang, Fei-Yue
    [J]. NEUROCOMPUTING, 2020, 382 : 87 - 95