一个本地对抗性攻击与一个最大集成区域稀疏性战略为3D对象.
Ling Zhao1, Xun Lv1, Lili Zhu2
1Department of School of Geosciences and Info-Physics, Central South University, Changsha 410083, China.
Journal of imaging
|January 24, 2025
概括
研究人员开发了一种新的3D对抗性攻击方法 (MARS),该方法在对象检测模型中使用最小的,集中的伪装. 这种隐蔽的方法显著提高了物理环境中的攻击效率,带来了新的安全风险.
科学领域:
- 计算机视觉 计算机视觉
- 人工智能的人工智能
- 网络安全 网络安全
背景情况:
- 用于对象检测的深度神经网络容易受到敌对攻击.
- 现有的3D对抗性攻击 (3D-AE) 在现实场景中通常是显而易见且无效的,原因是由于大量分散的修改.
研究的目的:
- 为对象检测模型开发一种微妙而高效的3D对抗性攻击方法.
- 为了应对最大限度地提高攻击效率的挑战,使用最小的和集中的伪装.
主要方法:
- 提出了由最大聚合区域稀疏性 (MARS) 策略驱动的本地3D攻击方法.
- 利用聚合和稀疏度规范化用于集中和隐蔽的伪装.
- 采用神经染用于多角度增强数据以识别通用关键决策区域.
主要成果:
- 在使用CARLA数据集的YOLOv3和v5网络上实现了1.724的平均攻击效率,比基线方法提高了134%.
- 证明MARS攻击方法在不同的视角上既是隐蔽的,也是积极的.
- 展示了强大的攻击可转移性,与纹理优化方法相结合时,平均精度降低了0.488和0.662.
结论:
- 马尔斯战略在3D对抗性攻击方面取得了重大进展,提高了隐形性和有效性.
- 该方法突出了对现实世界物体检测系统的潜在安全风险.
- 这项研究为开发更强大的防御机制来应对复杂的敌对攻击提供了基础.
相关概念视频
Elastic Collisions: Introduction
12.1K
An elastic collision is one that conserves both internal kinetic energy and momentum. Internal kinetic energy is the sum of the kinetic energies of the objects in a system. Truly elastic collisions can only be achieved with subatomic particles, such as electrons striking nuclei. Macroscopic collisions can be very nearly, but not quite, elastic, as some kinetic energy is always converted into other forms of energy such as heat transfer due to friction and sound. An example of a nearly...
12.1K
Elastic Collisions: Case Study
17.1K
Elastic collision of a system demands conservation of both momentum and kinetic energy. To solve problems involving one-dimensional elastic collisions between two objects, the equations for conservation of momentum and conservation of internal kinetic energy can be used. For the two objects, the sum of momentum before the collision equals the total momentum after the collision. An elastic collision conserves internal kinetic energy, and so the sum of kinetic energies before the collision equals...
17.1K
Collisions in Multiple Dimensions: Introduction
6.3K
It is far more common for collisions to occur in two dimensions; that is, the initial velocity vectors are neither parallel nor antiparallel to each other. Let's see what complications arise from this. The first idea is that momentum is a vector. Like all vectors, it can be expressed as a sum of perpendicular components (usually, though not always, an x-component and a y-component, and a z-component if necessary). Thus, when the statement of conservation of momentum is written for a...
6.3K
Collisions in Multiple Dimensions: Problem Solving
4.5K
In multiple dimensions, the conservation of momentum applies in each direction independently. Hence, to solve collisions in multiple dimensions, we should write down the momentum conservation in each direction separately. To help understand collisions in multiple dimensions, consider an example.
A small car of mass 1,200 kg traveling east at 60 km/h collides at an intersection with a truck of mass 3,000 kg traveling due north at 40 km/h. The two vehicles are locked together. What is the...
A small car of mass 1,200 kg traveling east at 60 km/h collides at an intersection with a truck of mass 3,000 kg traveling due north at 40 km/h. The two vehicles are locked together. What is the...
4.5K
Unsymmetric Loading of Thin-Walled Members: Problem Solving
669
The shear center of a channel section with uniform thickness, height, and width, is determined by computing the shear force in the member and calculating the moments of inertia of the sections.
To compute the shear forces, find the shear flow at a specific distance from the endpoint using the vertical shear and the moment of inertia values. The total shear force on the flange is calculated by integrating the shear flow from one end of the flange to the other.
Next, calculate the moments of...
To compute the shear forces, find the shear flow at a specific distance from the endpoint using the vertical shear and the moment of inertia values. The total shear force on the flange is calculated by integrating the shear flow from one end of the flange to the other.
Next, calculate the moments of...
669
Area Computation by the Alternative Coordinate Method
866
The alternative coordinate method, also known as the Shoelace Formula, is a technique for determining the area of a traverse using Cartesian coordinates. This method relies on the sequential arrangement of x and y coordinates for each point of the shape, ensuring accuracy and ease of application.In this approach, each corner's x and y coordinates are listed as fractions, with the x-coordinate as the numerator and the y-coordinate as the denominator. These coordinates are arranged sequentially...
866


