A CMA-ES-Based Adversarial Attack Against Black-Box Object Detectors

L. Y.U. Haoran*, T. A.N. Yu'an*, X. U.E. Yuan*, W. A.N.G. Yajie*, X. U.E. Jingfeng*

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

7 引用 (Scopus)

摘要

Object detection is one of the essential tasks of computer vision. Object detectors based on the deep neural network have been used more and more widely in safe-sensitive applications, like face recognition, video surveillance, autonomous driving, and other tasks. It has been proved that object detectors are vulnerable to adversarial attacks. We propose a novel black-box attack method, which can successfully attack regression-based and region-based object detectors. We introduce methods to reduce search dimensions, reduce the dimension of optimization problems and reduce the number of queries by using the Covariance matrix adaptation Evolution strategy (CMA-ES) as the primary method to generate adversarial examples. Our method only adds adversarial perturbations in the object box to achieve a precise attack. Our proposed attack can hide the specified object with an attack success rate of 86% and an average number of queries of 5, 124, and hide all objects with a success rate of 74% and an average number of queries of 6, 154. Our work illustrates the effectiveness of the CMA-ES method to generate adversarial examples and proves the vulnerability of the object detectors against the adversarial attacks.

源语言英语
页(从-至)406-412
页数7
期刊Chinese Journal of Electronics
30
3
DOI
出版状态已出版 - 5月 2021

指纹

探究 'A CMA-ES-Based Adversarial Attack Against Black-Box Object Detectors' 的科研主题。它们共同构成独一无二的指纹。

引用此

Haoran, L. Y. U., Yu'an, T. A. N., Yuan, X. U. E., Yajie, W. A. N. G., & Jingfeng, X. U. E. (2021). A CMA-ES-Based Adversarial Attack Against Black-Box Object Detectors. Chinese Journal of Electronics, 30(3), 406-412. https://doi.org/10.1049/cje.2021.03.003