D-UAP: Initially Diversified Universal Adversarial Patch Generation Method

With the rapid development of adversarial example technologies, the concept of adversarial patches has been proposed, which can successfully transfer adversarial attacks to the real world and fool intelligent object detection systems. However, the real-world environment is complex and changeable, an...

Full description

Bibliographic Details
Main Authors: Lei Sun, Xiaoqin Wang, Youhuan Yang, Xiuqing Mao
Format: Article
Language:English
Published: MDPI AG 2023-07-01
Series:Electronics
Subjects:
Online Access:https://www.mdpi.com/2079-9292/12/14/3080
_version_ 1797589558573924352
author Lei Sun
Xiaoqin Wang
Youhuan Yang
Xiuqing Mao
author_facet Lei Sun
Xiaoqin Wang
Youhuan Yang
Xiuqing Mao
author_sort Lei Sun
collection DOAJ
description With the rapid development of adversarial example technologies, the concept of adversarial patches has been proposed, which can successfully transfer adversarial attacks to the real world and fool intelligent object detection systems. However, the real-world environment is complex and changeable, and the adversarial patch attack technology is susceptible to real-world factors, resulting in a decrease in the success rate of attack. Existing adversarial-patch-generation algorithms have a single direction of patch initialization and do not fully consider the impact of initial diversification on its upper limit of adversarial patch attack. Therefore, this paper proposes an initial diversified adversarial patch generation technology to improve the effect of adversarial patch attacks on the underlying algorithms in the real world. The method uses YOLOv4 as the attack model, and the experimental results show that the attack effect of the adversarial-patch-attack method proposed in this paper is higher than the baseline 8.46%, and it also has a stronger attack effect and fewer training rounds.
first_indexed 2024-03-11T01:08:18Z
format Article
id doaj.art-eda79f8516534912b651b007204dde2d
institution Directory Open Access Journal
issn 2079-9292
language English
last_indexed 2024-03-11T01:08:18Z
publishDate 2023-07-01
publisher MDPI AG
record_format Article
series Electronics
spelling doaj.art-eda79f8516534912b651b007204dde2d2023-11-18T19:05:33ZengMDPI AGElectronics2079-92922023-07-011214308010.3390/electronics12143080D-UAP: Initially Diversified Universal Adversarial Patch Generation MethodLei Sun0Xiaoqin Wang1Youhuan Yang2Xiuqing Mao3Three Academy, PLA Information Engineering University, Zhengzhou 450000, ChinaThree Academy, PLA Information Engineering University, Zhengzhou 450000, ChinaSoftware Institute, Zhengzhou University, Zhengzhou 450000, ChinaThree Academy, PLA Information Engineering University, Zhengzhou 450000, ChinaWith the rapid development of adversarial example technologies, the concept of adversarial patches has been proposed, which can successfully transfer adversarial attacks to the real world and fool intelligent object detection systems. However, the real-world environment is complex and changeable, and the adversarial patch attack technology is susceptible to real-world factors, resulting in a decrease in the success rate of attack. Existing adversarial-patch-generation algorithms have a single direction of patch initialization and do not fully consider the impact of initial diversification on its upper limit of adversarial patch attack. Therefore, this paper proposes an initial diversified adversarial patch generation technology to improve the effect of adversarial patch attacks on the underlying algorithms in the real world. The method uses YOLOv4 as the attack model, and the experimental results show that the attack effect of the adversarial-patch-attack method proposed in this paper is higher than the baseline 8.46%, and it also has a stronger attack effect and fewer training rounds.https://www.mdpi.com/2079-9292/12/14/3080object detectionYOLOv4adversarial attackadversarial patchoutput diversification initialization
spellingShingle Lei Sun
Xiaoqin Wang
Youhuan Yang
Xiuqing Mao
D-UAP: Initially Diversified Universal Adversarial Patch Generation Method
Electronics
object detection
YOLOv4
adversarial attack
adversarial patch
output diversification initialization
title D-UAP: Initially Diversified Universal Adversarial Patch Generation Method
title_full D-UAP: Initially Diversified Universal Adversarial Patch Generation Method
title_fullStr D-UAP: Initially Diversified Universal Adversarial Patch Generation Method
title_full_unstemmed D-UAP: Initially Diversified Universal Adversarial Patch Generation Method
title_short D-UAP: Initially Diversified Universal Adversarial Patch Generation Method
title_sort d uap initially diversified universal adversarial patch generation method
topic object detection
YOLOv4
adversarial attack
adversarial patch
output diversification initialization
url https://www.mdpi.com/2079-9292/12/14/3080
work_keys_str_mv AT leisun duapinitiallydiversifieduniversaladversarialpatchgenerationmethod
AT xiaoqinwang duapinitiallydiversifieduniversaladversarialpatchgenerationmethod
AT youhuanyang duapinitiallydiversifieduniversaladversarialpatchgenerationmethod
AT xiuqingmao duapinitiallydiversifieduniversaladversarialpatchgenerationmethod