Adversarial Patches Exploiting Contextual Reasoning in Object Detection

09/30/2019
by   Aniruddha Saha, et al.
13

The usefulness of spatial context in most fast object detection algorithms that do a single forward pass per image is well known where they utilize context to improve their accuracy. In fact, they must do it to increase the inference speed by processing the image just once. We show that an adversary can attack the model by exploiting contextual reasoning. We develop adversarial attack algorithms that make an object detector blind to a particular category chosen by the adversary even though the patch does not overlap with the missed detections. We also show that limiting the use of contextual reasoning in learning the object detector acts as a form of defense that improves the accuracy of the detector after an attack. We believe defending against our practical adversarial attack algorithms is not easy and needs attention from the research community.

READ FULL TEXT

page 1

page 4

page 5

page 8

page 11

page 12

page 13

page 14

research
06/20/2019

On Physical Adversarial Patches for Object Detection

In this paper, we demonstrate a physical adversarial patch attack agains...
research
04/11/2017

A-Fast-RCNN: Hard Positive Generation via Adversary for Object Detection

How do we learn an object detector that is invariant to occlusions and d...
research
09/30/2021

You Cannot Easily Catch Me: A Low-Detectable Adversarial Patch for Object Detectors

Blind spots or outright deceit can bedevil and deceive machine learning ...
research
05/10/2022

Using Frequency Attention to Make Adversarial Patch Powerful Against Person Detector

Deep neural networks (DNNs) are vulnerable to adversarial attacks. In pa...
research
11/15/2017

Contextual Object Detection with a Few Relevant Neighbors

A natural way to improve the detection of objects is to consider the con...
research
03/18/2022

HDLock: Exploiting Privileged Encoding to Protect Hyperdimensional Computing Models against IP Stealing

Hyperdimensional Computing (HDC) is facing infringement issues due to st...
research
04/26/2021

PatchGuard++: Efficient Provable Attack Detection against Adversarial Patches

An adversarial patch can arbitrarily manipulate image pixels within a re...

Please sign up or login with your details

Forgot password? Click here to reset