Transferable Adversarial Attacks for Object Detection Using Object-Aware Significant Feature Distortion
Xinlong Ding, Jiansheng Chen, Hongwei Yu, Yu Shang, Yining Qin, Huimin Ma
摘要
Transferable black-box adversarial attacks against classifiers by disturbing the intermediate-layer features have been extensively studied in recent years. However, these methods have not yet achieved satisfactory performances when directly applied to object detectors. This is largely because the features of detectors are fundamentally different from that of the classifiers. In this study, we propose a simple but effective method to improve the transferability of adversarial examples for object detectors by leveraging the properties of spatial consistency and limited equivariance of object detectors' features. Specifically, we combine a novel loss function and deliberately designed data augmentation to distort the backbone features of object detectors by suppressing significant features corresponding to objects and amplifying the surrounding vicinal features corresponding to object boundaries. As such the target object and background area on the generated adversarial samples are more likely to be confused by other detectors. Extensive experimental results show that our proposed method achieves state-of-the-art black-box transferability for untargeted attacks on various models, including one/two-stage, CNN/Transformer-based, and anchorfree/anchor-based detectors.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- A²RNet: Adversarial Attack Resilient Network for Robust Infrared and Visible Image FusionJiawei Li, Hongwei Yu, Jiansheng Chen, Xinlong Ding 等AAAI 2025 · 被引用 6 次
- DADet: Safeguarding Image Conditional Diffusion Models Against Adversarial and Backdoor Attacks via Diffusion Anomaly DetectionHongwei Yu, Xinlong Ding, Jiawei Li, Jinlong Wang 等ICCV 2025 · 被引用 4 次
- Kaleidoscopic Background Attack: Disrupting Pose Estimation With Multi-Fold Radial Symmetry TexturesXinlong Ding, Hongwei Yu, Jiawei Li, Feifan Li 等ICCV 2025
- MEDUSA: Motion Elimination in Diffusion Using Spectral AttackHongwei Yu, Daoqing Zha, Xinlong Ding, Jiawei Li 等ICML 2026
它引用的顶会 Paper11
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu 等ICCV 2021 · 被引用 31,683 次
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- FCOS: Fully Convolutional One-Stage Object DetectionZhi Tian, Chunhua Shen, Hao Chen, Tong HeICCV 2019 · 被引用 6,042 次
- CARAFE: Content-Aware ReAssembly of FEaturesJiaqi Wang, Kai Chen, Rui Xu, Ziwei Liu 等ICCV 2019 · 被引用 842 次
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang 等ICLR 2020 · 被引用 765 次
相关 Paper
- Context-Aware Transfer Attacks for Object DetectionZikui Cai, Xinxin Xie, Shasha Li, Mingjun Yin 等AAAI 2022 · 被引用 41 次
- T-SEA: Transfer-Based Self-Ensemble Attack on Object DetectionHao Huang, Ziyan Chen, Huanran Chen, Yongtao Wang 等CVPR 2023
- Blurred-Dilated Method for Adversarial AttacksYang Deng, Weibin Wu, Jianping Zhang, Zibin ZhengNeurIPS 2023 · 被引用 10 次
- Perturbing Across the Feature Hierarchy to Improve Standard and Strict Blackbox Attack TransferabilityNathan Inkawhich, Kevin J. Liang, Binghui Wang, Matthew Inkawhich 等NeurIPS 2020 · 被引用 105 次
- Towards Multiple Black-boxes Attack via Adversarial Example Generation NetworkMingxing Duan, Kenli Li, Lingxi Xie, Qi Tian 等ACM MM 2021 · 被引用 21 次
