返回
Relevance attack on detectors
DOI:10.1016/j.patcog.2021.108491.png)
摘要
En 中文
This paper focuses on high-transferable adversarial attacks on detectors, which are hard to attack in a black-box manner, because of their multiple-output characteristics and the diversity across architectures. To pursue a high attack transferability, one plausible way is to find a common property across detectors, which facilitates the discovery of common weaknesses. We are the first to suggest that the relevance map from interpreters for detectors is such a property. Based on it, we design a Relevance Attack on Detectors (RAD), which achieves a state-of-the-art transferability, exceeding existing results by above 20%. On MS COCO, the detection mAPs for all 8 black-box architectures are more than halved and the segmentation mAPs are also significantly influenced. Given the great transferability of RAD, we generate the first adversarial dataset for object detection and instance segmentation, i.e., Adversarial Objects in COntext (AOCO), which helps to quickly evaluate and improve the robustness of detectors. (c) 2021 Elsevier Ltd. All rights reserved.
Keyword:
Adversarial attack
Attack transferability
Black-box attack
Relevance map
Interpreters
Object detection
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
7.6
论文数:
1.3W
被引数:
4.5W
机构
引用论文
Fooling deep neural detection networks with adaptive object-oriented adversarial perturbation
PATTERN RECOGNITION
IF7.6
Explaining nonlinear classification decisions with deep Taylor decomposition用深度泰勒分解解释非线性分类决策
PATTERN RECOGNITION
IF7.6
A black-box adversarial attack strategy with adjustable sparsity and generalizability for deep image classifiers一种稀疏度和泛化可调的深度图像分类器黑盒对抗攻击策略
PATTERN RECOGNITION
IF7.6
没有更多内容

