arXiv:2608.29510cs.CVcs.CR2026-09

在数据少时仍能有效防御物理对抗补丁,提升无人机目标检测鲁棒性。

ARMOR: Manifold-Oriented Training for Adversarially Robust Aerial Object Detection under Data Scarcity

论文配图:ARMOR: Manifold-Oriented Training for Adversarially Robust Aerial Object Detection under Data Scarcity
图 1 · 摘自论文原文
  • 通过掩蔽背景、随机加补丁,利用现有标签实现高效特征学习
  • 在低数据下模型置信度达0.90以上,对抗鲁棒性提升0.32
  • 适合数据稀缺的无人机检测场景,实测打印补丁仍有效

无人机目标检测在实际应用中日益普及,但模型易受物理可实现的通用对抗补丁影响而漏检。同时,训练数据稀缺构成现实约束:航拍图像采集与标注成本高,部署现场通常仅有数百张图像,远低于对抗鲁棒性基准所需的数万张。为应对模型脆弱性与数据稀缺问题,本文提出面向流形的对抗鲁棒训练(ARMOR),在低数据条件下实现流形对抗训练(OMAT)的核心思想。ARMOR基于数据流形——即捕捉数据关键特征的紧凑结构——在训练中学习并强化这些特征。不同于依赖大规模生成模型和对抗训练的OMAT,ARMOR采用数据高效策略:(i) 掩蔽图像背景以保留对象相关特征,(ii) 在对象上注入随机补丁以增强特征鲁棒性。在真实可实现的物理对抗补丁下,通过无查询迁移攻击与防御感知攻击评估。实验表明,ARMOR在保持超过0.90的干净性能的同时,对抗鲁棒性相较最先进防御提升最高0.32。实物打印补丁实验验证了其部署有效性。整体而言,ARMOR将流形学习洞察转化为数据稀缺下的检测器防御方案。

原文摘要 · Abstract (English)

Aerial object detection is increasingly deployed in real-world applications, but models remain vulnerable to physical, universal adversarial patches that cause them to miss objects. Furthermore, defenders face the practical constraint of training data scarcity: aerial imagery is costly to collect and label, so a deployment site typically yields hundreds of images rather than the tens of thousands that adversarial robustness benchmarks assume. To tackle model vulnerability and training data scarcity, we propose Adversarial Robustness with Manifold-Oriented Training (ARMOR), a novel defense that realizes the core insights of on-manifold adversarial training (OMAT) in low-data regimes. ARMOR builds on the insight of OMAT to model the data manifold - the compact structure capturing the data's relevant features - to learn and robustify these features during training. While OMAT relies on the data-intensive operations of training large generative models and adversarial training to achieve this, ARMOR adopts a data-efficient approach that reuses labels the detection task already supplies: ARMOR (i) masks image backgrounds to retain object-relevant features, and (ii) injects randomized patches on objects to improve feature robustness. Our low-data experiments with physically-realizable adversarial patches evaluate both query-free transfer attacks and defense-aware attacks. ARMOR maintains strong clean performance of over 0.90 model confidence, while improving adversarial robustness by up to 0.32 in model confidence over state-of-the-art defenses. Physical experiments with printed patches confirm that these gains survive deployment. Overall, ARMOR translates insights from manifold-based training to defend object detectors amidst training data scarcity.

目标检测对抗鲁棒低数据

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。