基于多尺度均衡正则的对抗补丁攻击方法
DOI:
CSTR:
作者:
作者单位:

1.中国航空研究院 北京 100086;2.厦门大学人工智能学院 厦门 361005

作者简介:

通讯作者:

中图分类号:

TP391.41;TN06

基金项目:


Multi-scale balanced regularization method for adversarial patch attacks
Author:
Affiliation:

1.Chinese Aeronautical Establishment,Beijing 100086, China;2. Institute of Artificial Intelligence, Xiamen University,Xiamen 361005,China

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    目标检测模型在对抗补丁攻击下表现出显著脆弱性,严重威胁其在自动驾驶与安防等场景中的应用安全。现有基于迁移的黑盒攻击方法虽取得一定进展,但普遍存在跨模型迁移性不足以及在多尺度检测头间抑制不均衡的问题。针对这一挑战,本文提出一种基于多尺度均衡正则的对抗补丁攻击方法(MSBR)。该方法在补丁训练过程中显式约束不同尺度检测头置信度输出的方差,从而实现对各尺度目标的一致性抑制,有效缓解了尺度抑制不均的现象,显著提升了对抗补丁的跨模型迁移能力。在多个主流目标检测器上的实验结果表明,所提方法在保持攻击成功率的同时,黑盒迁移性能优于现有代表性方法(如T-SEA),验证了MSBR在提升补丁攻击实用性方面的有效性。本文的研究为面向复杂检测结构的对抗补丁攻击提供了新的思路。

    Abstract:

    Object detection models are markedly vulnerable to adversarial patches, posing serious safety risks to applications such as autonomous driving and security surveillance. Although transfer-based black-box attacks have made progress, they often suffer from poor cross-model transferability and uneven suppression across multi-scale detection heads. To address these issues, we propose MSBR for adversarial patch attacks. During patch training, MSBR explicitly regularizes the variance of confidence outputs across different detection scales, thereby enforcing consistent suppression of targets at multiple scales, mitigating scale-wise imbalance, and substantially improving cross-model transferability. Experiments on several mainstream detectors show that our method maintains strong attack success rates while outperforming representative approaches (e.g.T-SEA) in black-box transfer performance, demonstrating the practical effectiveness of MSBR. This work provides a new perspective for designing adversarial patch attacks against complex multi-scale detection architectures.

    参考文献
    相似文献
    引证文献
引用本文

谢家乐,赵宇熙,曾念寅,王若.基于多尺度均衡正则的对抗补丁攻击方法[J].电子测量技术,2025,48(24):89-96

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:
  • 录用日期:
  • 在线发布日期: 2026-02-04
  • 出版日期:
文章二维码

重要通知公告

①《电子测量技术》期刊收款账户变更公告
×
《电子测量技术》
关于防范虚假编辑部邮件的郑重公告