提出轻量级自编码器方法AutoDetect,高效识别军事目标检测中的投毒攻击样本。
AutoDetect: Designing an Autoencoder-based Detection Method for Poisoning Attacks on Object Detection Applications in the Military Domain
- 基于自编码器设计图像块重建误差检测法,快速区分干净与中毒数据。
- 在自建军用车辆数据集上验证,对贴片式投毒攻击检出率显著优于现有方法。
- 适合军事场景中资源受限环境下的实时投毒检测,兼具高效与低开销优势。
投毒攻击正威胁军事领域人工智能系统的安全与鲁棒性。开源数据集和预训练模型的广泛使用加剧了这一风险。尽管威胁严重,但针对目标检测系统投毒攻击的研究仍十分有限,尤其在军事场景中后果更严重。本文通过构建小型定制数据集MilCivVeh,研究实际军事目标检测器在投毒攻击下的脆弱性。采用改进版BadDet(一种基于贴片的投毒攻击)进行测试,发现虽可实现正向攻击成功率,但需大量数据被污染,限制其实际可行性。为应对检测挑战,我们评估了专用投毒检测与工业视觉异常检测方法,均表现不足。因此提出AutoDetect:一种基于自编码器的简单、快速、轻量级的贴片检测方法。该方法利用图像块的重构误差有效分离干净与中毒样本,在性能上优于现有方法,且对时间和内存消耗更低。研究强调:军事领域大规模、具代表性的数据集是进一步评估投毒风险与优化检测技术的前提。
原文摘要 · Abstract (English)
Poisoning attacks pose an increasing threat to the security and robustness of Artificial Intelligence systems in the military domain. The widespread use of open-source datasets and pretrained models exacerbates this risk. Despite the severity of this threat, there is limited research on the application and detection of poisoning attacks on object detection systems. This is especially problematic in the military domain, where attacks can have grave consequences. In this work, we both investigate the effect of poisoning attacks on military object detectors in practice, and the best approach to detect these attacks. To support this research, we create a small, custom dataset featuring military vehicles: MilCivVeh. We explore the vulnerability of military object detectors for poisoning attacks by implementing a modified version of the BadDet attack: a patch-based poisoning attack. We then assess its impact, finding that while a positive attack success rate is achievable, it requires a substantial portion of the data to be poisoned -- raising questions about its practical applicability. To address the detection challenge, we test both specialized poisoning detection methods and anomaly detection methods from the visual industrial inspection domain. Since our research shows that both classes of methods are lacking, we introduce our own patch detection method: AutoDetect, a simple, fast, and lightweight autoencoder-based method. Our method shows promising results in separating clean from poisoned samples using the reconstruction error of image slices, outperforming existing methods, while being less time- and memory-intensive. We urge that the availability of large, representative datasets in the military domain is a prerequisite to further evaluate risks of poisoning attacks and opportunities patch detection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。