检测变压器易受对抗攻击,需提升其在自动驾驶中的安全性。
Evaluating the Adversarial Robustness of Detection Transformers
- 扩展多种白盒攻击方法测试DETR模型脆弱性
- 发现DETR对对抗扰动敏感,且跨网络迁移能力弱
- 提出针对DETR的新型无目标攻击,扰动极小但有效
鲁棒目标检测对自动驾驶和移动机器人至关重要,准确识别车辆、行人与障碍物是保障安全的关键。尽管检测变压器(DETR)取得进展,其对抗攻击下的鲁棒性仍研究不足。本文在白盒与黑盒攻击下,基于MS-COCO和KITTI数据集,全面评估DETR及其变体。扩展了FGSM、PGD和CW等主流白盒攻击方法,揭示DETR模型对对抗攻击高度敏感,与传统CNN检测器类似。大规模可迁移性分析显示,DETR变体间具有高内部可迁移性,但向CNN模型的跨网络迁移能力有限。此外,提出一种专为DETR设计的新型无目标攻击,利用其中间损失函数,在极小扰动下即可引发误分类。通过自注意力特征图可视化,揭示对抗攻击如何影响DETR内部表示。结果表明,标准对抗攻击下检测变压器存在关键漏洞,亟需加强其在安全关键场景中的鲁棒性研究。
原文摘要 · Abstract (English)
Robust object detection is critical for autonomous driving and mobile robotics, where accurate detection of vehicles, pedestrians, and obstacles is essential for ensuring safety. Despite the advancements in object detection transformers (DETRs), their robustness against adversarial attacks remains underexplored. This paper presents a comprehensive evaluation of DETR model and its variants under both white-box and black-box adversarial attacks, using the MS-COCO and KITTI datasets to cover general and autonomous driving scenarios. We extend prominent white-box attack methods (FGSM, PGD, and CW) to assess DETR vulnerability, demonstrating that DETR models are significantly susceptible to adversarial attacks, similar to traditional CNN-based detectors. Our extensive transferability analysis reveals high intra-network transferability among DETR variants, but limited cross-network transferability to CNN-based models. Additionally, we propose a novel untargeted attack designed specifically for DETR, exploiting its intermediate loss functions to induce misclassification with minimal perturbations. Visualizations of self-attention feature maps provide insights into how adversarial attacks affect the internal representations of DETR models. These findings reveal critical vulnerabilities in detection transformers under standard adversarial attacks, emphasizing the need for future research to enhance the robustness of transformer-based object detectors in safety-critical applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。