提出首个评估野火检测模型抗攻击能力的通用框架,提升预警系统可靠性。
Adversarial Robustness for Deep Learning-based Wildfire Prediction Models
- 设计全局与局部扰动生成对抗样本,适配CNN和Transformer架构。
- 发现变换模型在全局攻击下精度下降超70%,难以区分云与烟雾。
- 基于框架提出四种野火数据增强方法,有效提升模型鲁棒性。
快速蔓延的野火近年来严重破坏社会资产,凸显了早期预警系统对加速救援的重要性。基于摄像头的深度神经网络(DNN)进行烟雾检测为野火预测提供了有前景的解决方案。然而,烟雾在时空上稀少,导致训练数据不足,引发模型过拟合与偏差问题。当前主流DNN(如卷积神经网络CNN与Transformer)因架构差异,使得鲁棒性评估复杂化。为此,我们提出WARP(Wildfire Adversarial Robustness Procedure),首个面向野火检测模型的模型无关对抗鲁棒性评估框架。WARP通过图像全局和局部扰动生成对抗样本:全局攻击叠加高斯噪声,局部攻击嵌入PNG贴图,适用于两种模型并生成真实对抗场景。利用WARP评估实时CNN与Transformer,发现其关键缺陷:部分情况下,变压器模型在全局攻击下精度下降超过70%;两类模型在局部攻击中普遍无法区分云状PNG贴图与真实烟雾。为进一步提升鲁棒性,我们基于WARP方法与结果,提出四种面向野火的数据增强技术,丰富烟雾图像数据,显著提升模型精度与鲁棒性。这些进展为构建可靠早期野火预警系统迈出重要一步,或成为抵御野火破坏的第一道防线。
原文摘要 · Abstract (English)
Rapidly growing wildfires have recently devastated societal assets, exposing a critical need for early warning systems to expedite relief efforts. Smoke detection using camera-based Deep Neural Networks (DNNs) offers a promising solution for wildfire prediction. However, the rarity of smoke across time and space limits training data, raising model overfitting and bias concerns. Current DNNs, primarily Convolutional Neural Networks (CNNs) and transformers, complicate robustness evaluation due to architectural differences. To address these challenges, we introduce WARP (Wildfire Adversarial Robustness Procedure), the first model-agnostic framework for evaluating wildfire detection models' adversarial robustness. WARP addresses inherent limitations in data diversity by generating adversarial examples through image-global and -local perturbations. Global and local attacks superimpose Gaussian noise and PNG patches onto image inputs, respectively; this suits both CNNs and transformers while generating realistic adversarial scenarios. Using WARP, we assessed real-time CNNs and Transformers, uncovering key vulnerabilities. At times, transformers exhibited over 70% precision degradation under global attacks, while both models generally struggled to differentiate cloud-like PNG patches from real smoke during local attacks. To enhance model robustness, we proposed four wildfire-oriented data augmentation techniques based on WARP's methodology and results, which diversify smoke image data and improve model precision and robustness. These advancements represent a substantial step toward developing a reliable early wildfire warning system, which may be our first safeguard against wildfire destruction.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。