With the rapid development of deep learning (DL) algorithms, object detectors have achieved impressive performance. However, deep neural networks are highly vulnerable to adversarial patch attacks, which pose a significant security risk to DL applications in real-world scenarios. Adversarial patch attacks research provides insights into improving the robustness of advanced DL-based object detector models. In this study, we use the advanced object detector YOLO11 as the main model for adversarial patch generation. Based on existing adversarial patch generation methods, we optimize both the model structure and adversarial patch training strategies. These improvements enhance the effectiveness of adversarial patches while mitigating overfitting. We conduct experiments with the generated adversarial patches on multiple datasets, assessing the attack performance across multiple object detector models. Additionally, we compare our adversarial patches with other state-of-the-art adversarial patches. Experimental results show that our adversarial patches significantly reduce the Mean Average Precision (mAP) of advanced object detectors in digital environments. In real-world scenarios, we verify their effectiveness under different conditions. Comparative experiments highlight the competitiveness of our approach. Finally, we assess the applicability of our adversarial patch attack scheme on the YOLOv10 and YOLOv12 models.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ElevPatch: An Adversarial Patch Attack Scheme Based on YOLO11 Object Detector

  • Xiuying Li,
  • Hongwei Liao,
  • Haoze Li,
  • Jianyi Zhang,
  • Xiuyun Wu,
  • E. Jiayan

摘要

With the rapid development of deep learning (DL) algorithms, object detectors have achieved impressive performance. However, deep neural networks are highly vulnerable to adversarial patch attacks, which pose a significant security risk to DL applications in real-world scenarios. Adversarial patch attacks research provides insights into improving the robustness of advanced DL-based object detector models. In this study, we use the advanced object detector YOLO11 as the main model for adversarial patch generation. Based on existing adversarial patch generation methods, we optimize both the model structure and adversarial patch training strategies. These improvements enhance the effectiveness of adversarial patches while mitigating overfitting. We conduct experiments with the generated adversarial patches on multiple datasets, assessing the attack performance across multiple object detector models. Additionally, we compare our adversarial patches with other state-of-the-art adversarial patches. Experimental results show that our adversarial patches significantly reduce the Mean Average Precision (mAP) of advanced object detectors in digital environments. In real-world scenarios, we verify their effectiveness under different conditions. Comparative experiments highlight the competitiveness of our approach. Finally, we assess the applicability of our adversarial patch attack scheme on the YOLOv10 and YOLOv12 models.