arXiv:2508.21472cs.CV2025-08

针对船只检测的对抗补丁攻击,只在目标区域局部增强以提高成功率。

Adversarial Patch Attack for Ship Detection via Localized Augmentation

  • 仅对目标区域进行局部增强,避免背景干扰
  • 在HRSC2016数据集上提升攻击成功率与迁移性
  • 适合研究模型安全性和对抗攻击的人员

基于遥感图像的当前船只检测技术主要依赖深度神经网络(DNN)的目标检测能力。然而,DNN易受对抗补丁攻击影响,可能导致检测模型误分类或完全逃避目标。已有研究证明,基于数据变换的方法可提升对抗样本的迁移性。但过度增强图像背景或无关区域会引入额外干扰,导致检测模型产生误检,这些错误并非由对抗补丁直接引起,而是源于背景与非目标区域的过量增强。本文提出一种局部增强方法,仅对目标区域应用增强,避免对非目标区域造成影响。通过减少背景干扰,使损失函数更聚焦于对抗补丁对检测模型的影响,从而提升攻击成功率。在HRSC2016数据集上的实验表明,该方法有效提高了对抗补丁攻击的成功率并增强了其迁移能力。

原文摘要 · Abstract (English)

Current ship detection techniques based on remote sensing imagery primarily rely on the object detection capabilities of deep neural networks (DNNs). However, DNNs are vulnerable to adversarial patch attacks, which can lead to misclassification by the detection model or complete evasion of the targets. Numerous studies have demonstrated that data transformation-based methods can improve the transferability of adversarial examples. However, excessive augmentation of image backgrounds or irrelevant regions may introduce unnecessary interference, resulting in false detections of the object detection model. These errors are not caused by the adversarial patches themselves but rather by the over-augmentation of background and non-target areas. This paper proposes a localized augmentation method that applies augmentation only to the target regions, avoiding any influence on non-target areas. By reducing background interference, this approach enables the loss function to focus more directly on the impact of the adversarial patch on the detection model, thereby improving the attack success rate. Experiments conducted on the HRSC2016 dataset demonstrate that the proposed method effectively increases the success rate of adversarial patch attacks and enhances their transferability.

对抗攻击船只检测局部增强

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。