Journal of Optoelectronics · Laser, Volume. 34, Issue 9, 915(2023)
Stealthy adversarial perturbation generation method for object detection
To address the shortcomings of the current white-box adversarial attacks against object detection about imperceptibility,this paper proposes a stealthy adversarial perturbations generation (SPG) method from the perspective of both generation process and the limitation of perturbations cost.First,the perturbations in the high-texture region of images which is hard to detected by human eyes are assigned a higher weight by texture information.Then,a perturbations position selection strategy is applied to reduce the number of improved perturbed pixels.Finally,these adversarial perturbations are decoupled to adaptively search for the best L2 norm metric.The proposed method and comparative methods are evaluated on the MS-COCO 2014 and PASCAL-VOC datasets against 4 dominant object detectors.Experimental results show that the metric value of imperceptibility of this method is greater than that of other methods.The mAP of the object detectors is degraded to below 9%.The L0 norm is less than 0.239,and the L2 norm of adversarial perturbations is less than 2.9×10-5 respectively.
Get Citation
Copy Citation Text
DING Cheng, SHI Zaifeng, TONG Bowen, WANG Ruoqi, CAO Qingjie. Stealthy adversarial perturbation generation method for object detection[J]. Journal of Optoelectronics · Laser, 2023, 34(9): 915
Received: Mar. 6, 2022
Accepted: --
Published Online: Sep. 25, 2024
The Author Email: SHI Zaifeng (shizaifeng@tju.edu.cn)