Adversarial Attack and Defense of YOLO Detectors in Autonomous Driving Scenarios

Adversarial Attack and Defense of YOLO Detectors in Autonomous Driving Scenarios
复制标题

DOI:
10.1109/iv51971.2022.9827222
复制
发表时间:
2022-02
期刊:
2022 IEEE Intelligent Vehicles Symposium (IV)
影响因子:
--
通讯作者:
Jung Im Choi;Qing Tian
Jung Im Choi;Qing Tian
中科院分区:
其他
文献类型:
--
作者:
Jung Im Choi;Qing Tian

文献摘要

相似文献

视觉检测是自动驾驶的关键任务,是自动驾驶规划和控制的重要基础。深度神经网络在各种视觉任务中取得了有希望的结果,但众所周知,它们容易受到对抗性攻击。人们需要先全面了解深度视觉探测器的脆弱性,然后才能提高其鲁棒性。然而,只有少数对抗性攻击/防御工作关注对象检测,并且大多数仅采用分类和/或定位损失,忽略了对象性方面。在本文中,我们发现了 YOLO 检测器中与对象性相关的严重对抗漏洞,并针对自动驾驶车辆视觉检测的对象性方面提出了一种有效的攻击策略。此外,为了解决此类漏洞,我们提出了一种新的用于视觉检测的对象感知对抗训练方法。实验表明,所提出的针对对象性方面的攻击比 KITTI 和 COCO_traffic 数据集上的分类和/或定位损失生成的攻击分别有效 45.17% 和 43.50%。此外,所提出的对抗性防御方法可以将 KITTI 和 COCO_traffic 上的检测器针对面向对象攻击的鲁棒性分别提高高达 21% 和 12%。
Visual detection is a key task in autonomous driving, and it serves as a crucial foundation for self-driving planning and control. Deep neural networks have achieved promising results in various visual tasks, but they are known to be vulnerable to adversarial attacks. A comprehensive understanding of deep visual detectors’ vulnerability is required before people can improve their robustness. However, only a few adversarial attack/defense works have focused on object detection, and most of them employed only classification and/or localization losses, ignoring the objectness aspect. In this paper, we identify a serious objectness-related adversarial vulnerability in YOLO detectors and present an effective attack strategy targeting the objectness aspect of visual detection in autonomous vehicles. Furthermore, to address such vulnerability, we propose a new objectness-aware adversarial training approach for visual detection. Experiments show that the proposed attack targeting the objectness aspect is 45.17% and 43.50% more effective than those generated from classification and/or localization losses on the KITTI and COCO_traffic datasets, respectively. Also, the proposed adversarial defense approach can improve the detectors’ robustness against objectness-oriented attacks by up to 21% and 12% mAP on KITTI and COCO_traffic, respectively.