Gradient-Free Sparse Adversarial Attack on Object Detection Models
At a glance
- الاستشهادات
- 2
- المراجع
- 16
- Comments
- 0
Abstract
The rapid increase of object detection's applications leads to a growing need for these models to be robust to adversarial examples. However, it has been shown that deep neural networks (DNNs) are vulnerable to adversarial examples. In this work, we explore the vulnerability of recent object detection models by generating sparse adversarial examples that differ from the original images by only a few pixels. Moreover, to be suitable for real-world scenarios, we consider the context in which we are ignorant of victim models and employ a gradient-free approach to generate imperceptible adversarial examples. Notably, there are two challenges that we have to address simultaneously: reducing the number of perturbed pixels and limiting the number of queries needed to successfully find an adversarial example. Existing methods usually try to solve only one of those challenges, regardless of the poor quality of the other, and result in high computational resources or perceptible adversarial examples. Our study aims to use only a small number of queries to generate imperceptible perturbations that make object detectors yield wrong predictions. Our experiments are conducted with the convolutional neural network-based YOLO family and the vision transformer-based models (i.e., DINO and DETR) on the PASCAL-VOC dataset.
Publication details
- DOI
- 10.1145/3712256.3726305
- OpenAlex
- W4412106740
- Document type
- conference-paper
- Language
- EN
- Source
- Proceedings of the Genetic and Evolutionary Computation Conference
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.