针对航拍车检设计更真实的纹理与形状对抗攻击
Texture- and Shape-based Adversarial Attacks for Overhead Image Vehicle Detection
- 约束纹理修改的分辨率、范围和颜色,模拟真实攻击条件
- 形状改动对攻击效果影响显著,越真实越弱
- 适配实际部署场景,适合安全评估与防御研究者
航拍图像中的车辆检测因复杂背景、小目标、阴影和遮挡而困难。尽管深度学习提升了检测性能,模型仍易受对抗攻击影响,威胁可靠性。传统攻击策略常忽略实际实施限制。本文对纹理(降低分辨率、限制修改区域与色域)和形状修改施加现实约束,并分析其对攻击效果的影响。在三种目标检测架构上开展大量实验,揭示性能与实用性间的权衡:越贴近真实场景的修改,攻击效果越弱,反之亦然。代码与数据已公开,支持可复现性。
原文摘要 · Abstract (English)
Detecting vehicles in aerial images is difficult due to complex backgrounds, small object sizes, shadows, and occlusions. Although recent deep learning advancements have improved object detection, these models remain susceptible to adversarial attacks (AAs), challenging their reliability. Traditional AA strategies often ignore practical implementation constraints. Our work proposes realistic and practical constraints on texture (lowering resolution, limiting modified areas, and color ranges) and analyzes the impact of shape modifications on attack performance. We conducted extensive experiments with three object detector architectures, demonstrating the performance-practicality trade-off: more practical modifications tend to be less effective, and vice versa. We release both code and data to support reproducibility at https://github.com/humansensinglab/texture-shape-adversarial-attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。