A CMA-ES-Based Adversarial Attack Against Black-Box Object Detectors

来源 :电子学报(英文版) | 被引量 : 0次 | 上传用户:zhan99zhan
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Object detection is one of the essential tasks of computer vision. Object detectors based on the deep neural network have been used more and more widely in safe-sensitive applications, like face recognition, video surveillance, autonomous driving, and other tasks. It has been proved that object detectors are vulnerable to adversarial attacks. We propose a novel black-box attack method, which can successfully attack regression-based and region-based object detectors. We introduce methods to reduce search dimensions, reduce the dimension of optimization problems and reduce the number of queries by using the Covariance matrix adaptation Evolution strategy (CMA-ES) as the primary method to generate adversarial examples. Our method only adds adversarial perturbations in the object box to achieve a precise attack. Our proposed attack can hide the specified object with an attack success rate of 86% and an average number of queries of 5, 124, and hide all objects with a success rate of 74%and an average number of queries of 6, 154. Our work illustrates the effectiveness of the CMA-ES method to generate adversarial examples and proves the vulnerability of the object detectors against the adversarial attacks.
其他文献
环境监测实验室作为环境监测的重要组成部分,可以对该区域内部的具体环境状况变化进行全面的预估,为环境治理提供科学准确的参考依据.随着我国对环境监测实验室的建设,投入不
农村人居环境是整个社会环境的重要组成部分,根据党中央的号召,“绿水青山就是金山银山”的理念,农村人居环境原来越受到党和国家的密切关注,乡村振兴战略也是国家大力提倡的
基于对城市给水处理技术的一些思考分析,首先分析出传统城市给水处理技术当中存在的问题;其次分析出提高城市给水处理技术的一些思考,进而提高城市供水的质量,保证城市的用水
Local binary pattern(LBP) is sensitive to noise. Noise-resistant LBP(NRLBP) addresses this problem by thresholding local neighboring pixels into three-valued states(i.e., 0, 1 and uncertain bits)and r
Compared with traditional endonasal endoscope, Virtual endonasal endoscope (VEE) is a computerized alternative solution with the advantages of being non-invasiv
A novel High-order extended Kalman Filter (HEKF) is designed for a class of complex dynamic systems with polynomial nonlinearities. The state and measurement mo
We proposes an improved grasshopper algorithm for global optimization problems. Grasshopper optimization algorithm (GOA) is a recently proposed meta-heuristic a
This paper presents the design and analysis of a distributed power amplifier with 6-dB bandwidth from 10MHz to 6GHz. To meet the stringent targeted specificatio
In a specific project, how to find a reasonable balance between a plurality of objectives and their optimal solutions has always been an important aspect for re
In recent decades, a number of protocols for Remote data integrity checking (RDIC) have been proposed.Identity (ID) based RDIC protocols are constructed to guar