Journal of Optoelectronics · Laser, Volume. 34, Issue 9, 915(2023)

Stealthy adversarial perturbation generation method for object detection

DING Cheng1, SHI Zaifeng1,2、*, TONG Bowen1, WANG Ruoqi1, and CAO Qingjie3
Author Affiliations
  • 1[in Chinese]
  • 2[in Chinese]
  • 3[in Chinese]
  • show less

    To address the shortcomings of the current white-box adversarial attacks against object detection about imperceptibility,this paper proposes a stealthy adversarial perturbations generation (SPG) method from the perspective of both generation process and the limitation of perturbations cost.First,the perturbations in the high-texture region of images which is hard to detected by human eyes are assigned a higher weight by texture information.Then,a perturbations position selection strategy is applied to reduce the number of improved perturbed pixels.Finally,these adversarial perturbations are decoupled to adaptively search for the best L2 norm metric.The proposed method and comparative methods are evaluated on the MS-COCO 2014 and PASCAL-VOC datasets against 4 dominant object detectors.Experimental results show that the metric value of imperceptibility of this method is greater than that of other methods.The mAP of the object detectors is degraded to below 9%.The L0 norm is less than 0.239,and the L2 norm of adversarial perturbations is less than 2.9×10-5 respectively.

    Tools

    Get Citation

    Copy Citation Text

    DING Cheng, SHI Zaifeng, TONG Bowen, WANG Ruoqi, CAO Qingjie. Stealthy adversarial perturbation generation method for object detection[J]. Journal of Optoelectronics · Laser, 2023, 34(9): 915

    Download Citation

    EndNote(RIS)BibTexPlain Text
    Save article for my favorites
    Paper Information

    Received: Mar. 6, 2022

    Accepted: --

    Published Online: Sep. 25, 2024

    The Author Email: SHI Zaifeng (shizaifeng@tju.edu.cn)

    DOI:10.16136/j.joel.2023.09.0306

    Topics