conference-paper

An adversarial attack method for Yolov4 based on changeable-perturbation-step PGD

Research footprint

At a glance

الاستشهادات
3
المراجع
21
Comments
0
Paper overview

Abstract

With the development of artificial intelligence, the object detection model based on deep learning has also achieved great results. The detection model has also developed from the traditional manual extraction of features to the current neural network extraction. The classic single-stage detection model is based on YOLO series is representative. However, with constant research, it is discovered that the detection model based on deep neural network also inherits the shortcomings of neural network and is vulnerable to adversarial attacks. This paper proposes an optimized attack algorithm based on PGD, which realizes the adversarial attack on the YOLOv4 object detection model. Experiments have proved that this attack method in this paper reduces the mAP indicator from 87.61% to 0.12% on the VOC data set, and from 69.17% to 0.37% on the COCO data set. It has a certain improvement in the evaluation indicators PSNR and SSIM, and the attack effect Compared with the original PGD, the quality of the generated adversarial example is better.

Record transparency

Publication details

DOI
10.1117/12.2639388
OpenAlex
W4301726669
Document type
conference-paper
Language
EN
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.