RAdam-TOG: A Global Perturbation Adversarial Attack Scheme for Object Detectors
摘要
Currently, AI-based object detectors are highly susceptible to adversarial attacks. Among these attacks, Targeted Adversarial Objectness Gradient Attack (TOG) has demonstrated significant effectiveness against object detectors. We propose a novel adversarial attack scheme based on TOG, named RAdam-TOG. This method combines the Rectified Adaptive Moment Estimation algorithm with the Fast Sign Descent Method based on the TOG, effectively resolving the problems associated with TOG and further enhancing the attack performance. We conducted extensive experiments using the RAdam-TOG method on various object detectors, including YOLOv8. The experimental results show that our method reduces the Mean Average Precision (mAP) of the YOLOv8 detector to 1.8%, achieving a 2.1% greater reduction in accuracy compared to the TOG baseline. Moreover, RAdam-TOG exhibits superior attack performance across multiple object detectors. Finally, for the RAdam-TOG scheme, a dual denoising defense method combining bilateral filtering and convolutional denoising autoencoder is designed. Experimental results show that it can effectively filter out perturbations in adversarial examples, and can increase the mAP of the adversarial example from 2.6 to 70.