HARP: Let Object Detector Undergo Hyperplasia to Counter Adversarial Patches
Junzhe Cai, Shuiyan Chen, Heng Li, Beihao Xia, Zimin Mao, Wei Yuan
摘要
Adversarial patches can mislead object detectors to produce erroneous predictions. To defend against adversarial patches, one can take two types of protections on the model side, including modifying the detector itself (e.g., adversarial training) or attaching a new model in front of the detector. However, the former often deteriorates clean performance of detectors, and the latter may have high deployment costs caused by too many training parameters. Inspired by the phenomenon of "bone hyperplasia" in human bodies, we present a novel model-side adversarial patch defense, called HARP (Hyperplasia based Adversarial Patch defense). Just as bone hyperplasia can enhance bone strength and skeletal stability, the hyperostosia of detectors can also help to resist adversarial patches. Following this idea, HARP chooses to improve adversarial robustness by "growing" lightweight CNN modules (i.e., hyperplasia modules) on the pre-trained object detectors. We conduct extensive experiments on the PASCAL VOC and COCO datasets to compare HARP with the data-side defense JPEG and the model-side defenses adversarial training, SAC and FNC. Experimental results show that HARP provides excellent defense against adversarial patches while maintaining clean performance, outperforming the compared defense methods. Under PGD-based adaptive attacks, HARP surpasses the recently proposed defense method SAC by 12.5% in mean average precision (mAP) on PASCAL VOC, and 13.2% on COCO dataset. In addition, experiments confirm that the increase in model inference time caused by HARP is almost negligible.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- KDAT: Inherent Adversarial Robustness via Knowledge Distillation with Adversarial Tuning for Object Detection ModelsYarin Yerushalmi Levi, Edita Grolman, Idan Yankelev, Amit Giloni 等AAAI 2025 · 被引用 3 次
- Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch DetectionJiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa 等CVPR 2022 · 被引用 99 次
- Fight Fire with Fire: Combating Adversarial Patch Attacks using Pattern-randomized Defensive PatchesJianan Feng, Jiachun Li, Changqing Miao, Jianjun Huang 等S&P 2025
- DetectorGuard: Provably Securing Object Detectors against Localized Patch Hiding AttacksChong Xiang, Prateek MittalCCS 2021 · 被引用 58 次
- I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object DetectorsZijin Lin, Yue Zhao, Kai Chen, Jinwen HeCCS 2024 · 被引用 4 次
