用量子混合神经网络检测伪造交通标志,省内存还更准。
A Hybrid Quantum-Classical AI-Based Detection Strategy for Generative Adversarial Network-Based Deepfake Attacks on an Autonomous Vehicle Traffic Sign Classification System
- 用量子态编码图像特征,大幅降低内存占用。
- 在真实与伪造标志上测试,性能优于或相当经典模型。
- 适合关注自动驾驶安全与轻量化模型的读者。
自动驾驶车辆的感知模块严重依赖深度学习模型来识别周围环境中的各类物体。交通标志识别系统是该模块的关键组成部分,帮助车辆正确识别道路标志。然而,攻击者通过篡改捕获的图像进行对抗性攻击,可能导致车辆误识别交通标志,引发严重后果。深度伪造技术可被用于此类攻击,即用生成的伪造交通标志图像替代真实图像输入到自动驾驶系统中。本文研究了基于生成对抗网络的深度伪造攻击如何欺骗交通标志识别系统,并提出一种结合量子-经典神经网络的检测策略。该方法采用振幅编码将输入图像特征表示为量子态,显著降低内存需求。作者在真实与伪造交通标志图像上评估了该混合模型及多个经典卷积神经网络基线模型。结果表明,在大多数情况下,该混合量子-经典神经网络在检测性能上达到或超过经典模型,同时所需内存不足最浅经典模型的三分之一。
原文摘要 · Abstract (English)
The perception module in autonomous vehicles (AVs) relies heavily on deep learning-based models to detect and identify various objects in their surrounding environment. An AV traffic sign classification system is integral to this module, which helps AVs recognize roadway traffic signs. However, adversarial attacks, in which an attacker modifies or alters the image captured for traffic sign recognition, could lead an AV to misrecognize the traffic signs and cause hazardous consequences. Deepfake presents itself as a promising technology to be used for such adversarial attacks, in which a deepfake traffic sign would replace a real-world traffic sign image before the image is fed to the AV traffic sign classification system. In this study, the authors present how a generative adversarial network-based deepfake attack can be crafted to fool the AV traffic sign classification systems. The authors developed a deepfake traffic sign image detection strategy leveraging hybrid quantum-classical neural networks (NNs). This hybrid approach utilizes amplitude encoding to represent the features of an input traffic sign image using quantum states, which substantially reduces the memory requirement compared to its classical counterparts. The authors evaluated this hybrid deepfake detection approach along with several baseline classical convolutional NNs on real-world and deepfake traffic sign images. The results indicate that the hybrid quantum-classical NNs for deepfake detection could achieve similar or higher performance than the baseline classical convolutional NNs in most cases while requiring less than one-third of the memory required by the shallowest classical convolutional NN considered in this study.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。