跳到主要导航 跳到搜索 跳到主要内容

Blind object detectors via transferable background adversarial attack

  • Jiawei Lian
  • , Shaohui Mei
  • , Xiaofei Wang
  • , Yi Wang
  • , Lefan Wang
  • , Yingjie Lu
  • , Mingyang Ma
  • , Lap Pui Chau
  • Northwestern Polytechnical University Xian
  • Hong Kong Polytechnic University

科研成果: 期刊稿件文章同行评审

摘要

It has been widely substantiated that deep neural networks (DNNs) are susceptible and vulnerable to adversarial perturbations. Existing studies mainly focus on performing attacks by corrupting targeted objects (physical attack) or images (digital attack), which is intuitively acceptable and understandable in terms of the attack’s effectiveness. In contrast, our focus lies in conducting background adversarial attacks in both digital and physical domains, without causing any disruptions to the targeted objects themselves. Specifically, we propose a transferable background adversarial attack framework that generalizes well across diverse objects and models without smearing the targeted objects. Technically, we approach the background adversarial attack as an iterative optimization problem, analogous to the process of DNN learning. Besides, we offer a theoretical demonstration of its convergence under a set of mild but sufficient conditions. To strengthen the attack efficacy and transferability, we propose a new ensemble strategy tailored for adversarial perturbations and introduce an improved smooth constraint for the seamless connection of integrated perturbations. We conduct comprehensive and rigorous experiments in both digital and physical domains, demonstrating the effectiveness of the proposed transferable attack method. The findings of this research substantiate the significant discrepancy between human and machine vision on the value of background variations, which play a far more critical role than previously recognized, necessitating a reevaluation of the robustness and reliability of DNNs. The code is publicly available at GitHub Repository.

源语言英语
期刊论文编号109356
期刊Neural Networks
205
DOI
出版状态已出版 - 1月 2027

学术指纹

探究 'Blind object detectors via transferable background adversarial attack' 的科研主题。它们共同构成独一无二的学术指纹。

引用此