REVIEW 4 cited by
Robust Adversarial Perturbation on Deep Proposal-based Models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Adversarial noises are useful tools to probe the weakness of deep learning based computer vision algorithms. In this paper, we describe a robust adversarial perturbation (R-AP) method to attack deep proposal-based object detectors and instance segmentation algorithms. Our method focuses on attacking the common component in these algorithms, namely Region Proposal Network (RPN), to universally degrade their performance in a black-box fashion. To do so, we design a loss function that combines a label loss and a novel shape loss, and optimize it with respect to image using a gradient based iterative algorithm. Evaluations are performed on the MS COCO 2014 dataset for the adversarial attacking of 6 state-of-the-art object detectors and 2 instance segmentation algorithms. Experimental results demonstrate the efficacy of the proposed method.
Forward citations
Cited by 4 Pith papers
-
Corrupting Attention: Evasion-Based Adversarial Attacks on Encoder Attention in Detection Transformers
Optimizing a bounded l-infinity perturbation against encoder attention collapses DETR and DINO object detection to near-zero mAP, outperforming prior attacks.
-
NumbOD: A Spatial-Frequency Fusion Attack Against Object Detectors
NumbOD attacks object detectors with a spatial loss that collapses predicted boxes toward the corner and a frequency loss that amplifies high-frequency differences, reducing mAP50 to below 5.5 on all nine tested models.
-
Can't Slow me Down: Learning Robust and Hardware-Adaptive Object Detectors against Latency Attacks for Edge Devices
A background-attentive, hardware-aware adversarial training method restores real-time object detection FPS under latency attacks on edge, desktop, and cloud GPUs.
-
Adversarial Patch Attack for Ship Detection via Localized Augmentation
Localized augmentation, applying transformations only to target ship regions, modestly improves adversarial patch attack success and transferability on YOLOv5 detectors, but results vary by model size.
Discussion (0). Continue with ORCID to comment.