返回
Toward Generic and Controllable Attacks Against Object Detection
DOI:10.1109/TGRS.2024.3417958.png)
摘要
En 中文
Existing adversarial attacks against object detectors (ODs) have two inherent limitations. First, ODs have complex meta-structure designs, hence most advanced attacks for ODs concentrate on attacking specific detector-intrinsic structures [e.g., RPN and nonmaximal suppression (NMS)], which makes it hard for them to work on other new detectors. Second, most works against ODs make adversarial examples (AEs) by adding image-level perturbations into original images, which brings redundant perturbations in semantically meaningless areas (e.g., backgrounds). This article proposes a generic white-box attack on mainstream ODs with controllable perturbations. For a generic attack, LGP treats ODs as black boxes and only attacks their outputs, thereby eliminating the limitations of detector-intrinsic structures. Regarding controllability, we establish an object-wise constraint to induce the attachment of perturbations to foregrounds. Experimentally, the proposed LGP successfully attacked 16 state-of-the-art ODs on MS-COCO and DOTA datasets, with promising imperceptibility and transferability obtained. Code is publicly released in https://github.com/liguopeng0923/LGP.git.
Keyword:
Perturbation methods
Detectors
Object detection
Proposals
Glass box
Robustness
Optimization
Adversarial examples (AE)
controllable imperceptibility
generic attacks
object detection
期刊
IF:
8.6
论文数:
2.1W
被引数:
10.7W
机构
引用论文
Multicomponent Orbital-Optimized Perturbation Theory with Density Fitting: Anharmonic Zero-Point Energies in Protonated Water Clusters具有密度拟合的多组分轨道优化摄动理论: 质子化水团簇中的非谐零点能量
A General Gaussian Heatmap Label Assignment for Arbitrary-Oriented Object Detection面向任意对象检测的通用高斯热图标签分配

