Reinforcement Learning-based Adversarial Attacks on Object Detectors using Reward Shaping
Zhenbo Shi, Wei Yang, Zhenbo Xu, Zhidong Yu, Liusheng Huang
摘要
In the field of object detector attacks, previous methods primarily rely on fixed gradient optimization or patch-based cover techniques, often leading to suboptimal attack performance and excessive distortions. To address these limitations, we propose a novel attack method, Interactive Reinforcement-based Sparse Attack (IRSA), which employs Reinforcement Learning (RL) to discover the vulnerabilities of object detectors and systematically generate erroneous results. Specifically, we formulate the process of seeking optimal margins for adversarial examples as a Markov Decision Process (MDP). We tackle the RL convergence difficulty through innovative reward functions and a composite optimization method for effective and efficient policy training. Moreover, the perturbations generated by IRSA are more subtle and difficult to detect while requiring less computational effort. Our method also demonstrates strong generalization capabilities against various object detectors. In summary, IRSA is a refined, efficient, and scalable interactive, iterative, end-to-end algorithm.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Amnesia as a Catalyst for Enhancing Black Box Pixel Attacks in Image Classification and Object DetectionDongsu Song, Daehwa Ko, Jay Hoon JungNeurIPS 2024 · 被引用 2 次
- Query-efficient Attack for Black-box Image Inpainting Forensics via Reinforcement LearningXianbo Mo, Shunquan Tan, Bin Li, Jiwu HuangAAAI 2025 · 被引用 5 次
- BadRL: Sparse Targeted Backdoor Attack against Reinforcement LearningJing Cui, Yufei Han, Yuzhe Ma, Jianbin Jiao 等AAAI 2024 · 被引用 31 次
- Who Is the Strongest Enemy? Towards Optimal and Efficient Evasion Attacks in Deep RLYanchao Sun, Ruijie Zheng, Yongyuan Liang, Furong HuangICLR 2022 · 被引用 82 次
- Natural Black-Box Adversarial Examples against Deep Reinforcement LearningMengran Yu, Shiliang SunAAAI 2022 · 被引用 15 次
