Infrared Adversarial Patch Generation Based on Reinforcement Learning

Shuangju Zhou, Yang Li, Wenyi Tan, Chenxing Zhao, Xin Zhou, Quan Pan

科研成果: 期刊稿件文章同行评审

摘要

Recently, there has been an increasing concern about the vulnerability of infrared object detectors to adversarial attacks, where the object detector can be easily spoofed by adversarial samples with aggressive patches. Existing attacks employ light bulbs, insulators, and both hot and cold blocks to construct adversarial patches. These patches are complex to create, expensive to produce, or time-sensitive, rendering them unsuitable for practical use. In this work, a straightforward and efficacious attack methodology applicable in the physical realm, wherein the patch configuration is simplified to uniform-sized grayscale patch blocks affixed to the object, is proposed. This approach leverages materials with varying infrared emissivity, which are easy to fabricate and deploy in the real world and can be long-lasting. We use a reinforcement learning approach to gradually optimize the patch generation strategy until the adversarial attack goal is achieved, which supports multi-gray scale patches and explores the effects of patch size and grayscale. The results of our experiments demonstrate the effectiveness of the method. In our configurations, the average accuracy of YOLO v5 in digital space drops from 95.7% to 45.4%, with an attack success rate of 68.3%. It is also possible to spoof the object detector in physical space.

源语言英语
文章编号3335
期刊Mathematics
12
21
DOI
出版状态已出版 - 11月 2024

指纹

探究 'Infrared Adversarial Patch Generation Based on Reinforcement Learning' 的科研主题。它们共同构成独一无二的指纹。

引用此