Pith. sign in

REVIEW 1 cited by

Transferable Physical Attack against Object Detection with Separable Attention

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2205.09592 v1 pith:777GECKW submitted 2022-05-19 cs.CV

classification cs.CV
keywords attentionattackadversarialmodelstransferabledetectionmethodscamouflage
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Transferable adversarial attack is always in the spotlight since deep learning models have been demonstrated to be vulnerable to adversarial samples. However, existing physical attack methods do not pay enough attention on transferability to unseen models, thus leading to the poor performance of black-box attack.In this paper, we put forward a novel method of generating physically realizable adversarial camouflage to achieve transferable attack against detection models. More specifically, we first introduce multi-scale attention maps based on detection models to capture features of objects with various resolutions. Meanwhile, we adopt a sequence of composite transformations to obtain the averaged attention maps, which could curb model-specific noise in the attention and thus further boost transferability. Unlike the general visualization interpretation methods where model attention should be put on the foreground object as much as possible, we carry out attack on separable attention from the opposite perspective, i.e. suppressing attention of the foreground and enhancing that of the background. Consequently, transferable adversarial camouflage could be yielded efficiently with our novel attention-based loss function. Extensive comparison experiments verify the superiority of our method to state-of-the-art methods.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Evaluating the Adversarial Robustness of Detection Transformers

    cs.CV 2024-12 conditional novelty 5.0 of 10

    DETR object detectors are highly vulnerable to standard adversarial attacks, transfer attacks within the DETR family, and a new attack using intermediate losses cuts accuracy with smaller perturbations.

Pith tools