实测发现对抗补丁在真实场景中效果大打折扣,64%性能差异暴露现实挑战
Breaking the Illusion: Real-world Challenges for Adversarial Patches in Object Detection
- 对比全局与局部补丁,测试其在真实世界中的攻击效果
- 补丁大小、位置、旋转等参数导致性能最高相差64%
- 研究揭示环境因素对对抗攻击的致命影响,适合防御研究者参考
对抗攻击严重威胁机器学习系统的鲁棒性与可靠性,尤其在计算机视觉应用中。本研究检验了针对YOLO目标检测网络的对抗补丁在物理世界中的表现。测试了两种攻击:可放置于场景任意位置的全局补丁,以及旨在部分覆盖特定目标以使其被移除的局部补丁。分析了补丁大小、位置、旋转、亮度和色相等因素对攻击效果的影响。结果表明,攻击效果显著依赖于这些参数,凸显在真实环境中保持攻击有效性面临巨大挑战。即使学习将数字变换参数与实际测量值对齐,补丁性能仍存在高达64%的偏差。这些发现强调了环境因素对对抗攻击的重要影响,有助于推动更稳健的实用化机器学习防御机制发展。
原文摘要 · Abstract (English)
Adversarial attacks pose a significant threat to the robustness and reliability of machine learning systems, particularly in computer vision applications. This study investigates the performance of adversarial patches for the YOLO object detection network in the physical world. Two attacks were tested: a patch designed to be placed anywhere within the scene - global patch, and another patch intended to partially overlap with specific object targeted for removal from detection - local patch. Various factors such as patch size, position, rotation, brightness, and hue were analyzed to understand their impact on the effectiveness of the adversarial patches. The results reveal a notable dependency on these parameters, highlighting the challenges in maintaining attack efficacy in real-world conditions. Learning to align digitally applied transformation parameters with those measured in the real world still results in up to a 64\% discrepancy in patch performance. These findings underscore the importance of understanding environmental influences on adversarial attacks, which can inform the development of more robust defenses for practical machine learning applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。