

浏览全部资源
扫码关注微信
西安科技大学计算机科学与技术学院,西安,710054
Online First:10 July 2024,
Published:2024
移动端阅览
YU Zhenhua, YIN Zheng, YE Ou, et al. Adversarial Example Generation Method Based on Style Transfer[J]. 2024, 58(7): 191-202.
YU Zhenhua, YIN Zheng, YE Ou, et al. Adversarial Example Generation Method Based on Style Transfer[J]. 2024, 58(7): 191-202. DOI: 10.7652/xjtuxb202407018.
针对现有面向目标检测的对抗样本生成方法泛化能力弱的问题
提出了一种融合风格迁移的对抗样本生成方法。首先
提出一种新的对抗补丁生成方法
使用风格迁移方法将风格图像不同层次特征提取并融合
生成无明显物体特征且纹理丰富的对抗补丁; 然后
利用梯度类激活映射方法生成目标的特征热图
对目标不同区域在目标检测模型中的关键程度进行可视化表示; 最后
构建一种热图引导机制
引导对抗补丁在攻击目标的关键位置进行攻击以提高其泛化能力
生成最终对抗样本。在DroNet室外数据集上进行实验
结果表明:针对单阶段目标检测模型YOLOv5生成的对抗样本
采用所提方法计算得到的攻击成功率可达84.07%; 应用于攻击两阶段目标检测模型Faster R-CNN时
采用所提方法计算得到的攻击成功率仍保持在67.65%; 与现有的主流方法相比
所提方法生成的对抗样本攻击效果较好
且具有良好的泛化能力。
In response to the limited generalization in existing object detection-oriented adversarial example generation methods
an adversarial example generation method based on style transfer is proposed. Firstly
a novel adversarial patch generation method is introduced
leveraging style transfer techniques to blend features extracted from different layers of style images. This process generates adversarial patches that lack distinct object features but are rich in texture. Subsequently
a gradient-based activation mapping method is employed to generate feature heatmaps for the target
visually illustrating the significance of different regions of the target within the object detection model. Finally
a heatmap-guided mechanism is established to guide the adversarial patch to attack critical positions of the target
thereby enhancing its generalization ability and generating the ultimate adversarial examples. The proposed method's performance is verified through experiments conducted on the DroNet outdoor dataset. The experimental results demonstrate that this method achieves a success rate of 84.07% in generating adversarial samples for the single-stage object detection model YOLOv5. When applied to attack the two-stage object detection model Faster R-CNN
the success rate remains at 67.65%. Compared to prevailing methods
the adversarial examples generated by the proposed method exhibit superior attack effectiveness and good generalization capabilities.
许德刚, 王露, 李凡. 深度学习的典型目标检测算法研究综述 [J]. 计算机工程与应用, 2021, 57(8): 10-25.
XU Degang, WANG Lu, LI Fan. Review of typical object detection algorithms for deep learning [J]. Computer Engineering and Applications, 2021, 57(8): 10-25.
张珂, 冯晓晗, 郭玉荣, 等. 图像分类的深度卷积神经网络模型综述 [J]. 中国图象图形学报, 2021, 26(10): 2305-2325.
ZHANG Ke, FENG Xiaohan, GUO Yurong, et al. Overview of deep convolutional neural networks for image classification [J]. Journal of Image and Graphics, 2021, 26(10): 2305-2325.
田萱, 王亮, 丁琪. 基于深度学习的图像语义分割方法综述 [J]. 软件学报, 2019, 30(2): 440-468.
TIAN Xuan, WANG Liang, DING Qi. Review of image semantic segmentation based on deep learning [J]. Journal of Software, 2019, 30(2): 440-468.
张新钰, 高洪波, 赵建辉, 等. 基于深度学习的自动驾驶技术综述 [J]. 清华大学学报(自然科学版), 2018, 58(4): 438-444.
ZHANG Xinyu, GAO Hongbo, ZHAO Jianhui, et al. Overview of deep learning intelligent driving methods [J]. Journal of Tsinghua University(Science and Technology), 2018, 58(4): 438-444.
张西宁, 郭清林, 刘书语. 深度学习技术及其故障诊断应用分析与展望 [J]. 西安交通大学学报, 2020, 54(12): 1-13.
ZHANG Xining, GUO Qinglin, LIU Shuyu. Analysis and prospect of deep learning technology and its fault diagnosis application [J]. Journal of Xi'an Jiaotong University, 2020, 54(12): 1-13.
LIU Liangkai, LU Sidi, ZHONG Ren, et al. Computing systems for autonomous driving: state of the art and challenges [J]. IEEE Internet of Things Journal, 2021, 8(8): 6469-6486.
FERNANDO T, GAMMULLE H, DENMAN S, et al. Deep learning for medical anomaly detection? a survey [J]. ACM Computing Surveys, 2022, 54(7): 141.
张思思, 左信, 刘建伟. 深度学习中的对抗样本问题 [J]. 计算机学报, 2019, 42(8): 1886-1904.
ZHANG Sisi, ZUO Xin, LIU Jianwei. The problem of the adversarial examples in deep learning [J]. Chinese Journal of Computers, 2019, 42(8): 1886-1904.
SZEGEDY C, ZAREMBA W, SUTSKEVER I, et al. Intriguing properties of neural networks [EB/OL].(2014-02-19)[2023-06-16]. https://arxiv.org/abs/1312.6199.
XIE Cihang, WANG Jianyu, ZHANG Zhishuai, et al. Adversarial examples for semantic segmentation and object detection [C]//2017 IEEE International Conference on Computer Vision. Piscataway, NJ, USA: IEEE, 2017: 1378-1387.
CHEN Pinchun, KUNG B H, CHEN Juncheng. Class-aware robust adversarial training for object detection [C]//2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway, NJ, USA: IEEE, 2021: 10415-10424.
LU Jiajun, SIBAI H, FABRY E. Adversarial examples that fool detectors [EB/OL].(2017-12-07)[2023-06-23]. https://arxiv.org/abs/1712.02494.
LIAO Quanyu, WANG Xin, KONG Bin, et al. Fast local attack: generating local adversarial examples for object detectors [C]//2020 International Joint Conference on Neural Networks. Piscataway, NJ, USA: IEEE, 2020: 1-8.
LI Debang, ZHANG Junge, HUANG Kaiqi. Universal adversarial perturbations against object detection [J]. Pattern Recognition, 2021, 110: 107584.
黄世泽, 张肇鑫, 董德存, 等. 针对车载环境感知系统的对抗样本生成方法 [J]. 同济大学学报(自然科学版), 2022, 50(10): 1377-1384.
HUANG Shize, ZHANG Zhaoxin, DONG Decun, et al. Adversarial example generation method for vehicle environment perception system [J]. Journal of Tongji University(Natural Science), 2022, 50(10): 1377-1384.
谢云旭, 吴锡, 彭静. 无锚框模型类梯度全局对抗样本生成 [J]. 计算机工程, 2023, 49(10): 186-193.
XIE Yunxu, WU Xi, PENG Jing. Generation of gradient global adversarial samples with anchor-free model [J]. Computer Engineering, 2023, 49(10): 186-193.
WANG Yajie, LÜ Haoran, KUANG Xiaohui, et al. Towards a physical-world adversarial patch for blinding object detection models [J]. Information Sciences, 2021, 556: 459-471.
ZHANG Haotian, MA Xu. Misleading attention and classification: an adversarial attack to fool object detection models in the real world [J]. Computers Security, 2022, 122: 102876.
丁程, 史再峰, 佟博文, 等. 针对目标检测的隐蔽式对抗扰动生成方法 [J]. 光电子·激光, 2023, 34(9): 915-922.
DING Cheng, SHI Zaifeng, TONG Bowen, et al. Stealthy adversarial perturbation generation method for object detection [J]. Journal of Optoelectronics·Laser, 2023, 34(9): 915-922.
王烨奎, 曹铁勇, 郑云飞, 等. 基于特征图关注区域的目标检测对抗攻击方法 [J]. 计算机工程与应用, 2023, 59(2): 261-270.
WANG Yekui, CAO Tieyong, ZHENG Yunfei, et al. Adversarial attacks for object detection based on region of interest of feature maps [J]. Computer Engineering and Applications, 2023, 59(2): 261-270.
HU Zhanhao, HUANG Siyuan, ZHU Xiaopei, et al.Adversarial texture for fooling person detectors in the physical world [C]//2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway, NJ, USA: IEEE, 2022: 13297-13306.
LIU Xin, YANG Huanrui, LIU Ziwei, et al. DPatch: an adversarial patch attack on object detectors [EB/OL].(2019-04-23)[2023-08-18]. https://arxiv.org/abs/1806.02299.
DU A, CHEN Bo, CHIN T J, et al. Physical adversarial attacks on an aerial imagery object detector [C]//2022 IEEE/CVF Winter Conference on Applications of Computer Vision. Piscataway, NJ, USA: IEEE, 2022: 3798-3808.
LANG Dapeng, CHEN Deyun, SHI Ran, et al.Attention-guided digital adversarial patches on visual detection [J]. Security and Communication Networks, 2021, 2021: 1-11.
GATYS L A, ECKER A S, BETHGE M. Image style transfer using convolutional neural networks [C]//2016 IEEE Conference on Computer Vision and Pattern Recognition. Piscataway, NJ, USA: IEEE, 2016: 2414-2423.
SIMONYAN K, ZISSERMAN A. Very deep convolutional networks for large-scale image recognition [EB/OL].(2015-04-10)[2023-07-11]. https://arxiv.org/abs/1409.1556.
SELVARAJU R R, COGSWELL M, DAS A, et al. Grad-CAM: visual explanations from deep networks via gradient-based localization [C]//2017 IEEE International Conference on Computer Vision. Piscataway, NJ, USA: IEEE, 2017: 618-626.
LOQUERCIO A, MAQUEDA A I, DEL-BLANCO C R, et al. DroNet: learning to fly by driving [J]. IEEE Robotics and Automation Letters, 2018, 3(2): 1088-1095.
REN Shaoqing, HE Kaiming, GIRSHICK R, et al. Faster R-CNN: towards real-time object detection with region proposal networks [C]//Proceedings of the 28th International Conference on Neural Information Processing Systems. Cambridge, MA, USA: MIT Press, 2015: 91-99.
REDMON J, DIVVALA S, GIRSHICK R, et al. You only look once: unified, real-time object detection [C]//2016 IEEE Conference on Computer Vision and Pattern Recognition. Piscataway, NJ, USA: IEEE, 2016: 779-788.
0
Views
8
下载量
0
CSCD
Publicity Resources
Related Articles
Related Author
Related Institution
京公网安备11010802024621