量子混合模型提升交通标志识别抗攻击能力
Quantum Computing Supported Adversarial Attack-Resilient Autonomous Vehicle Perception Module for Traffic Sign Classification
- 用经典网络提取特征,接入量子电路构建混合模型
- 对抗攻击下仍保持91%以上准确率,PGD攻击下达85%
- 适合关注自动驾驶安全与量子计算应用的研究者
基于深度学习(DL)的图像分类模型对自动驾驶感知模块至关重要,错误分类可能引发严重后果。对抗攻击是常见网络攻击,可导致深度学习模型输出错误,例如使自动驾驶感知模块误识交通标志。本研究构建并比较了混合经典-量子深度学习(HCQ-DL)模型与经典深度学习(C-DL)模型,验证其在对抗攻击下的鲁棒性。采用AlexNet和VGG-16作为特征提取器,在量子系统前进行预处理。测试超过1000个量子电路,评估其在投影梯度下降(PGD)、快速梯度符号攻击(FGSA)和梯度攻击(GA)三种典型无目标攻击下的表现。在无攻击场景下,HCQ-DL模型准确率高于95%;在GA和FGSA攻击下,准确率仍高于91%,优于C-DL模型。在PGD攻击下,基于AlexNet的HCQ-DL模型准确率达85%,而对应C-DL模型低于21%。结果表明,相较于经典模型,HCQ-DL模型在对抗环境下对交通标志分类具有更高准确率。
原文摘要 · Abstract (English)
Deep learning (DL)-based image classification models are essential for autonomous vehicle (AV) perception modules since incorrect categorization might have severe repercussions. Adversarial attacks are widely studied cyberattacks that can lead DL models to predict inaccurate output, such as incorrectly classified traffic signs by the perception module of an autonomous vehicle. In this study, we create and compare hybrid classical-quantum deep learning (HCQ-DL) models with classical deep learning (C-DL) models to demonstrate robustness against adversarial attacks for perception modules. Before feeding them into the quantum system, we used transfer learning models, alexnet and vgg-16, as feature extractors. We tested over 1000 quantum circuits in our HCQ-DL models for projected gradient descent (PGD), fast gradient sign attack (FGSA), and gradient attack (GA), which are three well-known untargeted adversarial approaches. We evaluated the performance of all models during adversarial attacks and no-attack scenarios. Our HCQ-DL models maintain accuracy above 95\% during a no-attack scenario and above 91\% for GA and FGSA attacks, which is higher than C-DL models. During the PGD attack, our alexnet-based HCQ-DL model maintained an accuracy of 85\% compared to C-DL models that achieved accuracies below 21\%. Our results highlight that the HCQ-DL models provide improved accuracy for traffic sign classification under adversarial settings compared to their classical counterparts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。