• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

同时优化黑盒对抗补丁攻击的扰动和位置。

Simultaneously Optimizing Perturbations and Positions for Black-Box Adversarial Patch Attacks.

出版信息

IEEE Trans Pattern Anal Mach Intell. 2023 Jul;45(7):9041-9054. doi: 10.1109/TPAMI.2022.3231886. Epub 2023 Jun 5.

DOI:10.1109/TPAMI.2022.3231886
PMID:37015667
Abstract

Adversarial patch is an important form of real-world adversarial attack that brings serious risks to the robustness of deep neural networks. Previous methods generate adversarial patches by either optimizing their perturbation values while fixing the pasting position or manipulating the position while fixing the patch's content. This reveals that the positions and perturbations are both important to the adversarial attack. For that, in this article, we propose a novel method to simultaneously optimize the position and perturbation for an adversarial patch, and thus obtain a high attack success rate in the black-box setting. Technically, we regard the patch's position, the pre-designed hyper-parameters to determine the patch's perturbations as the variables, and utilize the reinforcement learning framework to simultaneously solve for the optimal solution based on the rewards obtained from the target model with a small number of queries. Extensive experiments are conducted on the Face Recognition (FR) task, and results on four representative FR models show that our method can significantly improve the attack success rate and query efficiency. Besides, experiments on the commercial FR service and physical environments confirm its practical application value. We also extend our method to the traffic sign recognition task to verify its generalization ability.

摘要

对抗补丁是一种重要的真实世界对抗攻击形式,它给深度神经网络的鲁棒性带来了严重的风险。以前的方法通过在固定粘贴位置的同时优化其扰动值,或者在固定补丁内容的同时操纵位置来生成对抗补丁。这表明位置和扰动对对抗攻击都很重要。为此,本文提出了一种新的方法,用于同时优化对抗补丁的位置和扰动,从而在黑盒设置中获得高攻击成功率。从技术上讲,我们将补丁的位置、预先设计的超参数来确定补丁的扰动作为变量,并利用强化学习框架,根据从少量查询的目标模型获得的奖励,同时求解基于最优解。在人脸识别 (FR) 任务上进行了广泛的实验,对四个代表性的 FR 模型的实验结果表明,我们的方法可以显著提高攻击成功率和查询效率。此外,商业 FR 服务和物理环境中的实验证实了其实际应用价值。我们还将该方法扩展到交通标志识别任务,以验证其泛化能力。

相似文献

1
Simultaneously Optimizing Perturbations and Positions for Black-Box Adversarial Patch Attacks.同时优化黑盒对抗补丁攻击的扰动和位置。
IEEE Trans Pattern Anal Mach Intell. 2023 Jul;45(7):9041-9054. doi: 10.1109/TPAMI.2022.3231886. Epub 2023 Jun 5.
2
Adversarial Sticker: A Stealthy Attack Method in the Physical World.对抗性贴纸:物理世界中的一种隐蔽攻击方法。
IEEE Trans Pattern Anal Mach Intell. 2023 Mar;45(3):2711-2725. doi: 10.1109/TPAMI.2022.3176760. Epub 2023 Feb 3.
3
Adversarial Patch Attacks on Deep-Learning-Based Face Recognition Systems Using Generative Adversarial Networks.基于生成对抗网络的深度学习人脸识别系统对抗性补丁攻击。
Sensors (Basel). 2023 Jan 11;23(2):853. doi: 10.3390/s23020853.
4
Optimizing Latent Variables in Integrating Transfer and Query Based Attack Framework.在集成基于迁移和查询的攻击框架中优化潜在变量
IEEE Trans Pattern Anal Mach Intell. 2025 Jan;47(1):161-171. doi: 10.1109/TPAMI.2024.3461686. Epub 2024 Dec 4.
5
Universal Adversarial Patch Attack for Automatic Checkout Using Perceptual and Attentional Bias.利用感知和注意偏差的通用对抗补丁攻击实现自动结账。
IEEE Trans Image Process. 2022;31:598-611. doi: 10.1109/TIP.2021.3127849. Epub 2021 Dec 22.
6
Generalizable Black-Box Adversarial Attack With Meta Learning.基于元学习的可推广黑盒对抗攻击
IEEE Trans Pattern Anal Mach Intell. 2024 Mar;46(3):1804-1818. doi: 10.1109/TPAMI.2022.3194988. Epub 2024 Feb 6.
7
Adversarial Robustness of Deep Reinforcement Learning Based Dynamic Recommender Systems.基于深度强化学习的动态推荐系统的对抗鲁棒性
Front Big Data. 2022 May 3;5:822783. doi: 10.3389/fdata.2022.822783. eCollection 2022.
8
Query-Efficient Black-Box Adversarial Attacks Guided by a Transfer-Based Prior.基于迁移先验引导的查询高效黑盒对抗攻击
IEEE Trans Pattern Anal Mach Intell. 2022 Dec;44(12):9536-9548. doi: 10.1109/TPAMI.2021.3126733. Epub 2022 Nov 7.
9
A Distributed Black-Box Adversarial Attack Based on Multi-Group Particle Swarm Optimization.基于多群组粒子群优化的分布式黑盒对抗攻击。
Sensors (Basel). 2020 Dec 14;20(24):7158. doi: 10.3390/s20247158.
10
ABCAttack: A Gradient-Free Optimization Black-Box Attack for Fooling Deep Image Classifiers.ABC攻击:一种用于欺骗深度图像分类器的无梯度优化黑盒攻击。
Entropy (Basel). 2022 Mar 15;24(3):412. doi: 10.3390/e24030412.

引用本文的文献

1
A Local Adversarial Attack with a Maximum Aggregated Region Sparseness Strategy for 3D Objects.一种针对3D物体的具有最大聚合区域稀疏性策略的局部对抗攻击。
J Imaging. 2025 Jan 13;11(1):25. doi: 10.3390/jimaging11010025.