Related Experiment Videos
Blind object detectors via transferable background adversarial attack
Jiawei Lian1, Shaohui Mei2, Xiaofei Wang2
1School of Electronics and Information, Northwestern Polytechnical University, Xi'an, 710129, China; Department of Electrical and Electronic Engineering, The Hong Kong Polytechnic University, Hong Kong SAR, China.
Summary
This study introduces a novel background adversarial attack framework for deep neural networks (DNNs). The research highlights the critical role of background variations in DNN vulnerabilities, impacting machine vision robustness.
Area of Science:
- Computer Science
- Artificial Intelligence
- Machine Learning
Background:
- Deep neural networks (DNNs) are vulnerable to adversarial perturbations.
- Existing attacks focus on corrupting targeted objects or images.
- Background variations are often overlooked in adversarial attack research.
Purpose of the Study:
- To propose a transferable background adversarial attack framework.
- To demonstrate the effectiveness of background perturbations in both digital and physical domains.
- To reevaluate the robustness and reliability of DNNs against background variations.
Main Methods:
- Developed a transferable background adversarial attack framework.
- Treated background attack as an iterative optimization problem.
- Introduced an ensemble strategy and smooth constraint for enhanced efficacy and transferability.
Main Results:
- Demonstrated the effectiveness of the proposed attack in digital and physical domains.
- Showcased the attack's generalizability across diverse objects and models.
- Validated the significant impact of background variations on DNN performance.
Conclusions:
- Background adversarial attacks are a critical vulnerability for DNNs.
- Human vision differs significantly from machine vision regarding background importance.
- DNN robustness and reliability require reevaluation considering background variations.