arXiv · 2012.13692
Sparse Adversarial Attack to Object Detection
Abstract
Adversarial examples have gained tons of attention in recent years. Many adversarial attacks have been proposed to attack image classifiers, but few work shift attention to object detectors. In this paper, we propose Sparse Adversarial Attack (SAA) which enables adversaries to perform effective evasion attack on detectors with bounded \emph{l$_{0}$} norm perturbation. We select the fragile position of the image and designed evasion loss function for the task. Experiment results on YOLOv4 and FasterRCNN reveal the effectiveness of our method. In addition, our SAA shows great transferability across different detectors in the black-box attack setting. Codes are available at \emph{https://github.com/THUrssq/Tianchi04}.
Explore related subjects
Keep this discovery
Jiayu Bao. 2020-12-26. Sparse Adversarial Attack to Object Detection. https://arxiv.org/abs/2012.13692
Cite the original work for its findings. Save a collection to share your selection of sources.