Recent investigations demonstrate that adversarial patches can be utilized to manipulate the result of object detection models. However, the conspicuous patterns on these patches may draw more attention and raise suspicions among humans. Moreover, existing works have primarily focused on enhancing the efficacy of attacks in the physical domain, rather than seeking to optimize their stealth attributes and transferability potential. To address these issues, we introduce a dual-perception-based attack framework that generates an adversarial patch known as the More Vivid Patch (MVPatch). The framework consists of a model-perception degradation method and a human-perception improvement method. To derive the MVPatch, we formulate an iterative process that simultaneously constrains the efficacy of multiple object detectors and refines the visual correlation between the generated adversarial patch and a realistic image. Our method employs a model-perception-based approach that reduces the object confidence scores of several object detectors to boost the transferability of adversarial patches. Further, within the human-perception-based framework, we put forward a lightweight technique for visual similarity measurement that facilitates the development of inconspicuous and natural adversarial patches and eliminates the reliance on additional generative models. Additionally, we introduce the naturalness score and transferability score as metrics for an unbiased assessment of various adversarial patches' natural appearance and transferability capacity. Extensive experiments demonstrate that the proposed MVPatch algorithm achieves superior attack transferability compared to similar algorithms in both digital and physical domains while also exhibiting a more natural appearance. These findings emphasize the remarkable stealthiness and transferability of the proposed MVPatch attack algorithm.
翻译:近期研究表明,对抗性补丁可用于操控目标检测模型的输出结果。然而,这些补丁上引人注目的图案可能引起更多关注并引发人类怀疑。此外,现有研究主要侧重于提升物理域的攻击效能,而非优化其隐蔽属性与迁移潜力。为解决上述问题,我们提出一种基于双感知的攻击框架,可生成名为"更具生动性补丁"(MVPatch)的对抗性补丁。该框架包含模型感知退化方法与人类感知改进方法。通过构建迭代过程,我们同时约束多个目标检测器的效能并优化生成的对抗性补丁与真实图像之间的视觉相关性,从而获得MVPatch。我们的方法采用基于模型感知的技术,降低多个目标检测器的目标置信度分数,以增强对抗性补丁的迁移性。进一步地,在基于人类感知的框架中,我们提出一种轻量级视觉相似度度量技术,有助于开发不显眼且自然的对抗性补丁,并消除对额外生成模型的依赖。此外,我们引入自然度分数与迁移性分数作为评估指标,用于公正衡量各类对抗性补丁的自然外观与迁移能力。大量实验表明,所提出的MVPatch算法在数字域与物理域中均实现了优于同类算法的攻击迁移性,同时展现出更自然的外观。这些发现充分凸显了所提出的MVPatch攻击算法卓越的隐蔽性与迁移性。