Adversarial attacks on Faster R-CNN object detector

Adversarial attacks on Faster R-CNN object detector
复制标题

DOI:
10.1016/j.neucom.2019.11.051
复制
发表时间:
2020-03-21
期刊:
影响因子:
6
通讯作者:
Wang, Fei-Yue
Wang, Fei-Yue
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wang, Yutong;Wang, Kunfeng;Wang, Fei-Yue

文献摘要

被引文献

相似文献

对抗性攻击激发了深度学习安全领域的研究兴趣。然而,大多数现有的对抗性攻击方法都是基于分类的。在本文中,我们使用投影梯度下降(PGD),这是分类上最强的一阶攻击方法,来生成关于Faster R-CNN对象检测器总损失的对抗性示例。与最先进的稠密粘附生成(DAG)方法相比,我们的攻击在白盒和黑盒攻击设置中更有效,更强大,并且适用于各种神经网络架构。在Pascal VOC 2007上,在白盒攻击下,DAG在具有VGG 16主干的Faster R-CNN上平均使用41.42次迭代具有5.92%的mAP,而我们的方法仅使用4次迭代就达到了0.90%。我们还分析了分类攻击和检测攻击的区别,发现除了误分类之外,检测上的对抗性样本也会导致误定位。此外,我们还验证了区域建议网络(RPN)和快速R-CNN损失(总损失的组成部分)的对抗有效性。我们的研究将为其他视觉任务的对抗性攻击的进一步努力提供灵感。(C)2019 Elsevier B. V.版权所有。
Adversarial attacks have stimulated research interests in the field of deep learning security. However, most of existing adversarial attack methods are developed on classification. In this paper, we use Projected Gradient Descent (PGD), the strongest first-order attack method on classification, to produce adversarial examples on the total loss of Faster R-CNN object detector. Compared with the state-of-the-art Dense Adversary Generation (DAG) method, our attack is more efficient and more powerful in both white-box and black-box attack settings, and is applicable in a variety of neural network architectures. On Pascal VOC2007, under white-box attack, DAG has 5.92% mAP on Faster R-CNN with VGG16 backbone using 41.42 iterations on average, while our method achieves 0.90% using only 4 iterations. We also analyze the difference of attacks between classification and detection, and find that in addition to misclassification, adversarial examples on detection also lead to mis-localization. Besides, we validate the adversarial effectiveness of both Region Proposal Network (RPN) and Fast R-CNN loss, the components of the total loss. Our research will provide inspiration for further efforts in adversarial attacks on other vision tasks. (C) 2019 Elsevier B.V. All rights reserved.