Localized augmentation, applying transformations only to target ship regions, modestly improves adversarial patch attack success and transferability on YOLOv5 detectors, but results vary by model size.
Robust Adversarial Perturbation on Deep Proposal-based Models
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Adversarial noises are useful tools to probe the weakness of deep learning based computer vision algorithms. In this paper, we describe a robust adversarial perturbation (R-AP) method to attack deep proposal-based object detectors and instance segmentation algorithms. Our method focuses on attacking the common component in these algorithms, namely Region Proposal Network (RPN), to universally degrade their performance in a black-box fashion. To do so, we design a loss function that combines a label loss and a novel shape loss, and optimize it with respect to image using a gradient based iterative algorithm. Evaluations are performed on the MS COCO 2014 dataset for the adversarial attacking of 6 state-of-the-art object detectors and 2 instance segmentation algorithms. Experimental results demonstrate the efficacy of the proposed method.
citation-role summary
citation-polarity summary
fields
cs.CV 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
support 1representative citing papers
citing papers explorer
-
Adversarial Patch Attack for Ship Detection via Localized Augmentation
Localized augmentation, applying transformations only to target ship regions, modestly improves adversarial patch attack success and transferability on YOLOv5 detectors, but results vary by model size.