论文标题

不起眼的gan生成的对抗斑块的可行性反对对象检测

Feasibility of Inconspicuous GAN-generated Adversarial Patches against Object Detection

论文作者

Pavlitskaya, Svetlana, Codău, Bianca-Marina, Zöllner, J. Marius

论文摘要

对抗斑块产生的标准方法会导致嘈杂的明显模式,这很容易被人类识别。最近的研究提出了几种使用生成对抗网络(GAN)生成自然斑块的方法,但在对象检测用例中只评估了其中的一些方法。此外,技术的状态主要集中于通过直接与补丁重叠的输入中抑制单个大边界框。补丁附近的抑制对象是一项不同的,更复杂的任务。在这项工作中,我们评估了现有的方法,以生成不起眼的补丁。我们已经为不同的计算机视觉任务而开发的适应方法,该方法与Yolov3和可可数据集的对象检测用例。我们已经评估了两种生成自然主义斑块的方法:通过将斑块的产生纳入GAN训练过程中以及使用预验证的GAN。在这两种情况下,我们都评估了性能和自然主义斑块外观之间的权衡。我们的实验表明,使用预先训练的GAN有助于获得逼真的斑块,同时保留类似于常规的对抗斑块的性能。

Standard approaches for adversarial patch generation lead to noisy conspicuous patterns, which are easily recognizable by humans. Recent research has proposed several approaches to generate naturalistic patches using generative adversarial networks (GANs), yet only a few of them were evaluated on the object detection use case. Moreover, the state of the art mostly focuses on suppressing a single large bounding box in input by overlapping it with the patch directly. Suppressing objects near the patch is a different, more complex task. In this work, we have evaluated the existing approaches to generate inconspicuous patches. We have adapted methods, originally developed for different computer vision tasks, to the object detection use case with YOLOv3 and the COCO dataset. We have evaluated two approaches to generate naturalistic patches: by incorporating patch generation into the GAN training process and by using the pretrained GAN. For both cases, we have assessed a trade-off between performance and naturalistic patch appearance. Our experiments have shown, that using a pre-trained GAN helps to gain realistic-looking patches while preserving the performance similar to conventional adversarial patches.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源