D-UAP: Initially Diversified Universal Adversarial Patch Generation Method
With the rapid development of adversarial example technologies, the concept of adversarial patches has been proposed, which can successfully transfer adversarial attacks to the real world and fool intelligent object detection systems. However, the real-world environment is complex and changeable, an...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2023-07-01
|
Series: | Electronics |
Subjects: | |
Online Access: | https://www.mdpi.com/2079-9292/12/14/3080 |
_version_ | 1797589558573924352 |
---|---|
author | Lei Sun Xiaoqin Wang Youhuan Yang Xiuqing Mao |
author_facet | Lei Sun Xiaoqin Wang Youhuan Yang Xiuqing Mao |
author_sort | Lei Sun |
collection | DOAJ |
description | With the rapid development of adversarial example technologies, the concept of adversarial patches has been proposed, which can successfully transfer adversarial attacks to the real world and fool intelligent object detection systems. However, the real-world environment is complex and changeable, and the adversarial patch attack technology is susceptible to real-world factors, resulting in a decrease in the success rate of attack. Existing adversarial-patch-generation algorithms have a single direction of patch initialization and do not fully consider the impact of initial diversification on its upper limit of adversarial patch attack. Therefore, this paper proposes an initial diversified adversarial patch generation technology to improve the effect of adversarial patch attacks on the underlying algorithms in the real world. The method uses YOLOv4 as the attack model, and the experimental results show that the attack effect of the adversarial-patch-attack method proposed in this paper is higher than the baseline 8.46%, and it also has a stronger attack effect and fewer training rounds. |
first_indexed | 2024-03-11T01:08:18Z |
format | Article |
id | doaj.art-eda79f8516534912b651b007204dde2d |
institution | Directory Open Access Journal |
issn | 2079-9292 |
language | English |
last_indexed | 2024-03-11T01:08:18Z |
publishDate | 2023-07-01 |
publisher | MDPI AG |
record_format | Article |
series | Electronics |
spelling | doaj.art-eda79f8516534912b651b007204dde2d2023-11-18T19:05:33ZengMDPI AGElectronics2079-92922023-07-011214308010.3390/electronics12143080D-UAP: Initially Diversified Universal Adversarial Patch Generation MethodLei Sun0Xiaoqin Wang1Youhuan Yang2Xiuqing Mao3Three Academy, PLA Information Engineering University, Zhengzhou 450000, ChinaThree Academy, PLA Information Engineering University, Zhengzhou 450000, ChinaSoftware Institute, Zhengzhou University, Zhengzhou 450000, ChinaThree Academy, PLA Information Engineering University, Zhengzhou 450000, ChinaWith the rapid development of adversarial example technologies, the concept of adversarial patches has been proposed, which can successfully transfer adversarial attacks to the real world and fool intelligent object detection systems. However, the real-world environment is complex and changeable, and the adversarial patch attack technology is susceptible to real-world factors, resulting in a decrease in the success rate of attack. Existing adversarial-patch-generation algorithms have a single direction of patch initialization and do not fully consider the impact of initial diversification on its upper limit of adversarial patch attack. Therefore, this paper proposes an initial diversified adversarial patch generation technology to improve the effect of adversarial patch attacks on the underlying algorithms in the real world. The method uses YOLOv4 as the attack model, and the experimental results show that the attack effect of the adversarial-patch-attack method proposed in this paper is higher than the baseline 8.46%, and it also has a stronger attack effect and fewer training rounds.https://www.mdpi.com/2079-9292/12/14/3080object detectionYOLOv4adversarial attackadversarial patchoutput diversification initialization |
spellingShingle | Lei Sun Xiaoqin Wang Youhuan Yang Xiuqing Mao D-UAP: Initially Diversified Universal Adversarial Patch Generation Method Electronics object detection YOLOv4 adversarial attack adversarial patch output diversification initialization |
title | D-UAP: Initially Diversified Universal Adversarial Patch Generation Method |
title_full | D-UAP: Initially Diversified Universal Adversarial Patch Generation Method |
title_fullStr | D-UAP: Initially Diversified Universal Adversarial Patch Generation Method |
title_full_unstemmed | D-UAP: Initially Diversified Universal Adversarial Patch Generation Method |
title_short | D-UAP: Initially Diversified Universal Adversarial Patch Generation Method |
title_sort | d uap initially diversified universal adversarial patch generation method |
topic | object detection YOLOv4 adversarial attack adversarial patch output diversification initialization |
url | https://www.mdpi.com/2079-9292/12/14/3080 |
work_keys_str_mv | AT leisun duapinitiallydiversifieduniversaladversarialpatchgenerationmethod AT xiaoqinwang duapinitiallydiversifieduniversaladversarialpatchgenerationmethod AT youhuanyang duapinitiallydiversifieduniversaladversarialpatchgenerationmethod AT xiuqingmao duapinitiallydiversifieduniversaladversarialpatchgenerationmethod |