arrow
Return

Adversarial attacks on YOLACT instance segmentation

delete2022-05-01
delete9
PRE
AI
Z
Zhaoxin Zhang
黄
黄世泽 (Shize Huang) *
刘晓雯 cover
刘晓雯 (Xiaowen Liu)
B
Bingjie Zhang
D
Decun Dong
DOI:10.1016/j.cose.2022.102682delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Adversarial attacks have stimulated research interests in the field of deep learning security. In terms of autonomous driving technology, instance segmentation can help autonomous vehicles identify a drivable area in a driving environment and a traffic accident will happen once instance segmentation is attacked by adversarial examples. However, only few studies have been done on adversarial attacks about instance segmentation. It would be more meaningful and more practical to research adversarial attacks against instance segmentation. In this paper, we propose the improved Projected Gradient Descent (PGD) to produce adversarial examples on the total loss of You Only Look At CoefficienT (YOLACT) instance segmentation. Firstly, we design the loss function and calculate the adversarial gradient. Then we propose the improved PGD. Finally, we obtain adversarial examples of YOLACT instance segmentation. Our attack method is efficient and powerful in both white-box and black-box attack settings, and is applicable in a variety of neural network architectures. On COCO 2017, under white-box attacks, our method achieves 1.14% box mean average precision (mAP) and 1.50% mask mAP on YOLACT with ResNet101 backbone. We also compare the similarity between clean images and adversarial examples among three different backbones and compare the operation time among three different backbones. We also find that box regression loss, classification loss and mask loss are also effective separately for generating adversarial examples. Our research will provide inspiration for further efforts in efficient and effective defense methods on instance segmentation.(c) 2022 Elsevier Ltd. All rights reserved.
Keywords:
Adversarial attack
Instance segmentation
White-box attack
Deep learning
Traffic environment perception

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

T
tongji university
Scholars:
7.9W
Papers: 6.0W
Citations: 98
Cited Papers

Cited Papers

Lessons to Improve Quality in Oncology Practice: Road Map to Fill the Global Gaps
err2020-03-31
err0
errOAAI
errLayth Mula-Hussain; Adele Duimering; Muzahm Al-Khyatt; Khalifa AlKaabi; Wilson Roa; Robert Pearcey
errShare
errSave
err
IF0
err
err0
PREAI
err
errShare
errSave
Another tool towards invasion? Polyp “bail-out” in Tubastraea coccinea
err2014-08-31
err0
errOAAI
errK. C. C. Capel; A. E. Migotto; C. Zilberberg; M. V. Kitahara
errShare
errSave
Radiation Oncology in the Arab World
err2019-09-07
err0
PREAI
errLayth Mula-Hussain; Shada Jamal Wadi-Ramahi; Mohamed Saad Zaghloul; Muthana Al-Ghazi
errShare
errSave
Polyacetylenes Bearing Mesogenic Side Groups: Synthesis and Properties, 2
err2003-03-31
err0
PREAI
errPaola Stagnaro; Lucia Conzatti; Giovanna Costa; Bernard Gallot; Cinzia Tavani; Barbara Valenti
errShare
errSave
researcher View more