期刊文献+

基于PSO的路牌识别模型黑盒对抗攻击方法 被引量:14

Black-box Adversarial Attack Against Road Sign Recognition Model via PSO
下载PDF
导出
摘要 随着深度学习在计算机视觉领域的广泛应用,人脸认证、车牌识别、路牌识别等也随之呈现商业化应用趋势.因此,针对深度学习模型的安全性研究至关重要.已有的研究发现:深度学习模型易受精心制作的包含微小扰动的对抗样本攻击,输出完全错误的识别结果.针对深度模型的对抗攻击是致命的,但同时也能帮助研究人员发现模型漏洞,并采取进一步改进措施.基于该思想,针对自动驾驶场景中的基于深度学习的路牌识别模型,提出一种基于粒子群优化的黑盒物理攻击方法(black-box physical attack via PSO,简称BPA-PSO).BPA-PSO在未知模型结构的前提下,不仅可以实现对深度模型的黑盒攻击,还能使得实际物理场景中的路牌识别模型失效.通过在电子空间的数字图像场景、物理空间的实验室及户外路况等场景下的大量实验,验证了所提出的BPA-PSO算法的攻击有效性,可发现模型漏洞,进一步提高深度学习的应用安全性.最后,对BPA-PSO算法存在的问题进行分析,对未来的研究可能面临的挑战进行了展望. With the wider application of deep learning in the field of computer vision, face authentication, license plate recognition, and road sign recognition have also presented commercial application trends. Therefore, research on the security of deep learning models is of great importance. Previous studies have found that deep learning models are vulnerable to carefully crafted adversarial examples that contains small perturbations, leading completely incorrect recognition results. Adversarial attacks against deep learning models are fatal, but they can also help researchers find vulnerabilities of models and make further improvements. Motivated by that, this study proposes a black box physical attack method based on particle swarm optimization(BPA-PSO) for deep learning road sign recognition model in scenario of autonomous vehicles. Under the premise of unknown model structure, BPA-PSO can not only realize the black box attack on deep learning models, but also invalidate the road sign recognition models in the physical scenario. The attack effectiveness of BPA-PSO algorithm is verified through a large number of experiments in the digital images of electronic space, laboratory environment, and outdoor road conditions. Besides, the abilities of discovering models’ vulnerabilities and further improving the application security of deep learning are also demonstrated. Finally, the problems existing in the BPA-PSO algorithm are analyzed and possible challenges of future research are proposed.
作者 陈晋音 陈治清 郑海斌 沈诗婧 苏蒙蒙 CHEN Jin-Yin;CHEN Zhi-Qing;ZHENG Hai-Bin;SHEN Shi-Jing;SU Meng-Meng(School of Information Engineering,Zhejiang University of Technology,Hangzhou 310023,China)
出处 《软件学报》 EI CSCD 北大核心 2020年第9期2785-2801,共17页 Journal of Software
基金 浙江省自然科学基金(LY19F020025) 国家重点研发计划(2018AAA0100800) 宁波市“科技创新2025”重大专项(2018B10063) 浙江省认知医疗工程技术研究中心(2018KFJJ07)
关键词 自动驾驶 对抗性攻击 路牌识别 黑盒物理攻击 粒子群优化 autopilot adversarial attack road recognition black-box physical attack particle swarm optimization
  • 相关文献

参考文献7

二级参考文献181

  • 1陆声链,林士敏.基于距离的孤立点检测及其应用[J].计算机与数字工程,2004,32(5):94-97. 被引量:23
  • 2陈杉,于鸿洋.基于MPEG压缩域的运动对象检测方法[J].信号处理,2004,20(6):628-631. 被引量:3
  • 3叶玉芬,郭宝龙,马佳.基于视觉差的误差扩散半色调算法[J].计算机工程,2006,32(16):195-197. 被引量:13
  • 4戴汝为 周登勇.智能控制与适应性.第三届全球智能控制与自动化大会(WCICA'2000)[M].合肥:-,2000.11-17.
  • 5Knox K T. Evolution of Error Diffusion [J]. Journal of Electronic Imaging, 1999, 8(4) : 422-429.
  • 6Ulichney R. Digital halftoning [M]. Cambridge: MIT Press,1987.
  • 7Velho L, Gomes J. Digital Halftoning with Space Filling Curves [C]//Computer Graphics. New York: ACM, 1991: 81-90.
  • 8Shiau J, Fan Z. A Set of Easily Implementable Coefficients in Error Diffusion with Reduced Worm Artifacts [C]// Proceedings of SPIE. Bellingham: Society of Photo-Optical Instrumentation Engineers, 1996: 222-225.
  • 9Eschbach R, Knox K T. Error-diffusion Algorithm with Edge Enhancement [J] . Journal of the Optical Society of America, 1991, 8(12) : 1844-1850.
  • 10Ostromoukhov V. A Simple and Efficient Error-Diffusion Algorithm [C]//Computer Graphics. New York: ACM, 2001 : 567-572.

共引文献1022

同被引文献69

引证文献14

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部