Adversarial attacks on Faster R-CNN object detector
Wang, Yutong1,4; Wang, Kunfeng3; Zhu, Zhanxing2; Wang, Fei-Yue1
刊名NEUROCOMPUTING
2020-03-21
卷号382期号:页码:87-95
关键词Adversarial attack Object detection White-box attack Black-box attack
ISSN号0925-2312
DOI10.1016/j.neucom.2019.11.051
英文摘要

Adversarial attacks have stimulated research interests in the field of deep learning security. However, most of existing adversarial attack methods are developed on classification. In this paper, we use Projected Gradient Descent (PGD), the strongest first-order attack method on classification, to produce adversarial examples on the total loss of Faster R-CNN object detector. Compared with the state-of-the-art Dense Adversary Generation (DAG) method, our attack is more efficient and more powerful in both white-box and black-box attack settings, and is applicable in a variety of neural network architectures. On Pascal VOC2007, under white-box attack, DAG has 5.92% mAP on Faster R-CNN with VGG16 backbone using 41.42 iterations on average, while our method achieves 0.90% using only 4 iterations. We also analyze the difference of attacks between classification and detection, and find that in addition to misclassification, adversarial examples on detection also lead to mis-localization. Besides, we validate the adversarial effectiveness of both Region Proposal Network (RPN) and Fast R-CNN loss, the components of the total loss. Our research will provide inspiration for further efforts in adversarial attacks on other vision tasks. (C) 2019 Elsevier B.V. All rights reserved.

资助项目National Natural Science Foundation of China[U1811463] ; National Key R&D Program of China[2018YFC1704400]
WOS研究方向Computer Science
语种英语
出版者ELSEVIER
WOS记录号WOS:000512881200010
内容类型期刊论文
源URL[http://ir.ia.ac.cn/handle/173211/28588]  
专题自动化研究所_复杂系统管理与控制国家重点实验室_先进控制与自动化团队
通讯作者Wang, Kunfeng
作者单位1.The State Key Laboratory for Management and Control of Complex Systems, Institute of Automation, Chinese Academy of Sciences
2.School of Mathematical Sciences, Peking University
3.College of Information Science and Technology, Beijing University of Chemical Technology
4.University of Chinese Academy of Sciences
推荐引用方式
GB/T 7714
Wang, Yutong,Wang, Kunfeng,Zhu, Zhanxing,et al. Adversarial attacks on Faster R-CNN object detector[J]. NEUROCOMPUTING,2020,382(无):87-95.
APA Wang, Yutong,Wang, Kunfeng,Zhu, Zhanxing,&Wang, Fei-Yue.(2020).Adversarial attacks on Faster R-CNN object detector.NEUROCOMPUTING,382(无),87-95.
MLA Wang, Yutong,et al."Adversarial attacks on Faster R-CNN object detector".NEUROCOMPUTING 382.无(2020):87-95.
个性服务
查看访问统计
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。


©版权所有 ©2017 CSpace - Powered by CSpace