Suppr超能文献

An adversarial example attack method based on predicted bounding box adaptive deformation in optical remote sensing images.

作者信息

Dai Leyu, Wang Jindong, Yang Bo, Chen Fan, Zhang Hengwei

机构信息

State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou, China.

Henan Key Laboratory of Information Security, Zhengzhou, China.

出版信息

PeerJ Comput Sci. 2024 May 28;10:e2053. doi: 10.7717/peerj-cs.2053. eCollection 2024.

Abstract

Existing global adversarial attacks are not applicable to real-time optical remote sensing object detectors based on the YOLO series of deep neural networks, which makes it difficult to improve the adversarial robustness of single-stage detectors. The existing methods do not work well enough in optical remote sensing images, which may be due to the mechanism of adversarial perturbations is not suitable. Therefore, an adaptive deformation method (ADM) was proposed to fool the detector into generating wrong predicted bounding boxes. Building upon this, we introduce the Adaptive Deformation Method Iterative Fast Gradient Sign Method (ADM-I-FGSM) and Adaptive Deformation Mechanism Projected Gradient Descent (ADM-PGD) against YOLOv4 and YOLOv5. ADM method can obtain the deformation trend values based on the length-to-width ratio of the prediction box, and the adversarial perturbation trend generated based on these trend values has better adversarial effect. Through experiments, we validate that our approach exhibits a higher adversarial success rate compared to the state-of-the-art methods. We anticipate that our unveiled attack scheme will aid in the evaluation of adversarial resilience of these models.

摘要
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/dff0/11157521/8a8a160e98ca/peerj-cs-10-2053-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验