返回
Adversarial attack algorithm for traffic sign recognition
DOI:10.1007/s11042-022-14067-5.png)
摘要
En 中文
Deep learning suffers from the threat of adversarial attacks, and its defense methods have become a research hotspot. In all applications of deep learning, intelligent driving is an important and promising one, facing serious threat of adversarial attack in the meanwhile. To address the adversarial attack, this paper takes the traffic sign recognition as a typical object, for it is the core function of intelligent driving. Considering that the black box attack does not need to know the internal characteristics of the model, it can have more practical value. However, the existing black box attack algorithm has high visit time and low efficiency in attacking sample generation. In this regard, the SimBA algorithm with high efficiency is selected and improved according to the characteristics of traffic signs, named the L-SimBA algorithm. According to the graphic characteristics of traffic signs that are already known, L-SimBA algorithm limits the search subspace consciously and specifies the set of search directions, and that is the core idea of it. By this way, L-SimBA algorithm can generate adversarial samples faster. Experimental comparison shows that in the field of traffic sign recognition, L-SimBA algorithm is better than SimBA algorithm. On the premise of obtaining similar quality adversarial attack samples, the success rate of adversarial measures gets higher, and the number of model visits reduces considerably, thus the attack efficiency of the algorithm improves greatly.
Keyword:
Adversarial attack
Black box
Traffic sign recognition
Algorithm security
期刊
IF:
3
论文数:
1.9W
被引数:
3.2W
机构
引用论文
Detection Tolerant Black-Box Adversarial Attack Against Automatic Modulation Classification With Deep Learning基于深度学习的针对自动调制分类的检测容忍黑盒对抗攻击
Adversarial Attacks Against Face Recognition: A Comprehensive Study针对人脸识别的对抗性攻击: 一项综合研究
IEEE ACCESS
IF3.6
Back in Black: A Comparative Evaluation of Recent State-Of-The-Art Black-Box Attacks
IEEE ACCESS
IF3.6

