Specific target generation adversarial attack method for aerial remote sensing target detection scene

By generating an adversarial attack method for specific targets for aerial remote sensing target detection scenarios, using robust transformation processing and specific target optimization loss function, an adversarial patch that can achieve effective attacks on aerial remote sensing image object detectors is solved, and the problem of difficulty in realizing and converging in the physical world in the existing technology is solved, and the practical feasibility and effective hidden effect of adversarial patches are achieved.

CN120032207APending Publication Date: 2025-05-23NAT INNOVATION INST OF DEFENSE TECH PLA ACAD OF MILITARY SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510147730.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing target-generating adversarial attack methods are difficult to implement in the physical world, and due to the single perspective of aerial imaging imaging, different categories of targets have high inter-class similarity in imaging, making it difficult to converge.

Method used

It provides a specific target generation and adversarial attack method for aerial remote sensing target detection scenario. By acquiring the aerial remote sensing image target detection model and training data, using robust transformation processing to generate multiple transformation patches, optimize and update adversarial patches, and use specific target optimization loss function to achieve adversarial attacks.

Benefits of technology

It can generate an adversarial patch that can be detected as a specific category of targets by the aerial remote sensing image target detector, and realize an effective adversarial attack on the aerial remote sensing image target detector. The obtained adversarial patch is realistic and feasible, which can effectively enable other targets to avoid detection and identification, and achieve effective hiding of the target.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120032207A_ABST
    Figure CN120032207A_ABST
Patent Text Reader

Abstract

The invention discloses a specific target generation adversarial attack method for an aerial remote sensing target detection scene. The method comprises the following steps: acquiring an aerial remote sensing image target detection model; acquiring a training data set, wherein training data comprises aerial remote sensing images; obtaining an initial adversarial patch, and processing the adversarial patch according to a plurality of preset groups of robustness transformation processing parameters to obtain a plurality of transformation patches corresponding to the adversarial patch; pasting transformation patches on aerial remote sensing images in the training data to obtain a plurality of adversarial samples; and taking the plurality of adversarial samples as the input of an aerial remote sensing image target detection model, optimizing and updating the adversarial patch by using a back propagation mode according to the output of the aerial remote sensing image target detection model and a preset specific target optimization loss function, and obtaining a final adversarial patch. According to the method, the adversarial patch which can be detected as a specific category of target by an aerial remote sensing image target detector can be generated, and adversarial attack on the detector is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer vision technology, and in particular to a specific target generation adversarial attack method for aerial remote sensing target detection scenarios. Background Art

[0002] In recent years, with the rapid development of deep learning technology, intelligent target detection algorithms based on deep learning have been widely used in the intelligent processing of massive aerial image data acquired from space or air, providing strong support for target recognition, dynamic monitoring, urban planning, change monitoring, forest fire prevention and other fields. However, with the continuous exploration of deep learning, studies have shown that deep learning models that perform well on real clean data are easily deceived by maliciously constructed adversarial samples, resulting in incorrect output results from the trained deep learning models.

[0003] Adversarial samples are defined as: maliciously designed disturbances are added to clean samples. Usually, such disturbances will not interfere with the judgment of the human eye, but they can mislead some well-trained deep learning models to produce incorrect prediction outputs. Aerial remote sensing images are generally screened by target detection algorithms due to the large number of targets and sparse targets. Therefore, it is of great research significance to conduct anti-intelligent recognition in the intelligent detection and reasoning stage and use intelligent anti-recognition adversarial technology to conduct adversarial attacks on aerial remote sensing image target detection models.

[0004] At present, adversarial attacks on target detection mainly focus on achieving the "disappearance attack" of existing targets. That is, by optimizing and generating image-related or universal adversarial patches, specific targets in the scene can avoid recognition by the target detection model. These optimized adversarial patches will not cause incorrect judgments when observed by the human eye, but they are enough to cause the target detection model to output completely wrong prediction results.

[0005] In addition to the above-mentioned adversarial attack methods, there are also studies that propose specific target generative adversarial attacks. The purpose of specific target generative adversarial attacks is to make the deployed target detection model detect and identify targets that do not exist in the scene. However, the specific target generative adversarial attacks on target detection models are still in their infancy and difficult to implement in the physical world. In addition, due to the single-view characteristics of aerial imaging, different categories of targets have high inter-class similarity in imaging, which makes it difficult for existing specific target generative adversarial attacks to converge. Summary of the invention

[0006] In order to solve some or all of the technical problems existing in the above-mentioned prior art, the present invention provides a specific target generation adversarial attack method for aerial remote sensing target detection scenarios.

[0007] The technical solution of the present invention is as follows:

[0008] A method for generating adversarial attacks on specific targets for aerial remote sensing target detection scenarios is provided, the method comprising:

[0009] Obtain the target detection model for aerial remote sensing images;

[0010] Obtain a training data set, the training data including aerial remote sensing images;

[0011] Obtaining an initial adversarial patch, processing the adversarial patch respectively according to a plurality of preset sets of robust transformation processing parameters, and obtaining a plurality of transformation patches corresponding to the adversarial patch;

[0012] Paste the transformed patches on the aerial remote sensing images in the training data to obtain multiple adversarial samples;

[0013] Multiple adversarial samples are used as input of the aerial remote sensing image target detection model. According to the output of the aerial remote sensing image target detection model and the preset specific target optimization loss function, the adversarial patch is optimized and updated using the back propagation method to obtain the final adversarial patch. The specific target optimization loss function includes: a non-target adversarial attack loss function and a target adversarial attack loss function. The non-target adversarial attack loss function is used to enable the aerial remote sensing image target detection model to recognize the patch as a target that does not exist originally, and the target adversarial attack loss function is used to enable the aerial remote sensing image target detection model to recognize the patch as a target of a specific category.

[0014] In some optional implementations, the robust transformation processing includes: angle rotation processing, size scaling processing, brightness adjustment, and contrast adjustment.

[0015] In some optional embodiments, each group of robust transformation processing parameters includes at least one parameter of robust transformation processing.

[0016] In some optional implementations, the non-target adversarial attack loss function is expressed as:

[0017]

[0018] in, It represents the confidence score corresponding to the patch in the adversarial sample input to the aerial remote sensing image target detection model, and M represents the number of patches detected and identified in the adversarial sample input to the aerial remote sensing image target detection model.

[0019] In some alternative embodiments, the target adversarial attack loss function includes: a cross-entropy loss function and a maximum target class probability loss function. The cross-entropy loss function is used to make the class probability vector corresponding to the patch output by the aerial remote sensing image target detection model approach a preset class probability vector, and the maximum target class probability loss function is used to make the class corresponding to the maximum value in the class probability vector corresponding to the patch output by the aerial remote sensing image target detection model be a preset class.

[0020] In some alternative embodiments, the cross-entropy loss function is expressed as:

[0021]

[0022] Wherein, represents the preset class probability vector, represents the class probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, represents and is the cross-entropy of.

[0023] In some alternative embodiments, the maximum target class probability loss function is expressed as:

[0024]

[0025] Wherein, represents the maximum value in the class probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, represents the probability value corresponding to a specific class in the class probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model.

[0026] In some alternative embodiments, the specific target optimization loss function is expressed as:

[0027]

[0028] Wherein, α, β, and γ represent weight coefficients.

[0029] In some alternative embodiments, inputting multiple adversarial samples as the input of the aerial remote sensing image target detection model, and according to the output of the aerial remote sensing image target detection model and a preset specific target optimization loss function, optimizing and updating the adversarial patch by using the backpropagation method to obtain the final adversarial patch includes the following steps:

[0030] Step 501, inputting multiple adversarial samples into the aerial remote sensing image target detection model respectively to obtain the position, confidence, and class information corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model;

[0031] Step 502, calculating a specific target optimization loss function according to the position, confidence and category information corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, as well as the set category probability vector and the specific category;

[0032] Step 503, determine whether the preset stop condition is met, if so, use the current adversarial patch as the final adversarial patch and end the optimization update process, if not, use the specific target optimization loss function to optimize and update the adversarial patch and continue to step 504;

[0033] Step 504, based on the optimized and updated adversarial patch, the adversarial patch is processed respectively according to a plurality of preset groups of robust transformation processing parameters to obtain a plurality of transformation patches corresponding to the adversarial patch;

[0034] Step 505 , paste the transformed patches on the aerial remote sensing images in the training data respectively to obtain multiple adversarial samples, and return to step 501 .

[0035] In some optional implementations, the adversarial patch is optimized and updated using the following formula:

[0036]

[0037] Among them, P t+1 represents the adversarial patch at the t+1th optimization update, P t denotes the adversarial patch at the tth optimization update, Δ[·] denotes the optimizer, η denotes the learning rate, L denotes the target-specific optimization loss function, and P denotes the adversarial patch.

[0038] The main advantages of the technical solution of the present invention are as follows:

[0039] The specific target generation adversarial attack method for aerial remote sensing target detection scenarios of the present invention can generate adversarial patches that can be detected as specific category targets by aerial remote sensing image target detectors, can achieve effective adversarial attacks on aerial remote sensing image target detectors, and the obtained adversarial patches are practical and feasible. By utilizing the obtained adversarial patches, other targets can be effectively prevented from detection and recognition by aerial remote sensing image target detectors, thereby achieving effective hiding of targets. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The drawings described herein are used to provide a further understanding of the embodiments of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0041] Figure 1A flowchart of a method for generating a counterattack against a specific target in an aerial remote sensing target detection scenario provided by an embodiment of the present invention;

[0042] Figure 2 A schematic diagram of the generation principle of an adversarial patch provided by an embodiment of the present invention;

[0043] Figure 3 A schematic diagram of an adversarial patch with a target category of an aircraft provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the specific embodiments of the present invention and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0045] The technical solution provided by the embodiments of the present invention is described in detail below with reference to the accompanying drawings.

[0046] refer to Figure 1-2 The embodiment of the present invention provides a method for generating a specific target adversarial attack for an aerial remote sensing target detection scenario, the method comprising the following steps 1 to 5:

[0047] Step 1: Obtain an aerial remote sensing image target detection model;

[0048] In the embodiment of the present invention, if an aerial remote sensing image target detection model currently exists, the corresponding aerial remote sensing image target detection model is directly acquired.

[0049] In an embodiment of the present invention, if there is no aerial remote sensing image target detection model at present, considering that the existing target detection can be divided into a single-stage and a two-stage series, the single-stage target detection mainly includes the YOLO series neural network, and the two-stage target detection is represented by the Faster R-CNN neural network. Therefore, the YOLO series neural network or the Faster R-CNN neural network is selected as the aerial remote sensing image target detection model, and the YOLO series neural network includes the YOLOv3, YOLOv4 and YOLOv5 series neural networks.

[0050] Furthermore, in an embodiment of the present invention, a corresponding neural network is selected according to the structure, parameters and weights of the actual aerial remote sensing image target detection model to be attacked, and the structure, parameters and weights of the neural network are determined.

[0051] Step 2: Obtain a training data set, where the training data includes aerial remote sensing images.

[0052] In the embodiment of the present invention, a training data set is obtained from an existing known image data set.

[0053] Specifically, in an embodiment of the present invention, multiple aerial remote sensing images are selected from the existing DOTA-v1.0 dataset, RSOD dataset or NWPUVHR-10 dataset as multiple training data, and then a training data set including multiple training data is obtained.

[0054] Among them, the DOTA-v1.0 dataset is a large-scale dataset containing 2,806 images, including 15 common target categories including aircraft collected from different sensors and platforms. Since the image sizes in the DOTA-v1.0 dataset are in different ranges, when choosing to obtain a training data set from the DOTA-v1.0 dataset, all images are divided into sub-images of 608x608 pixels so that the adversarial patches can be optimized and updated in a consistent format later.

[0055] Step 3, obtaining an initial adversarial patch, processing the adversarial patch respectively according to multiple sets of preset robust transformation processing parameters, and obtaining multiple transformation patches corresponding to the adversarial patch;

[0056] In this embodiment of the present invention, the initial adversarial patch is obtained by:

[0057] Determine the initial size of the adversarial patch based on empirical values;

[0058] Based on the determined initial size of the adversarial patch, a random pixel between [0, 1] is generated at each pixel to obtain the initial adversarial patch.

[0059] Furthermore, considering that in the real physical world, due to the influence of complex environmental factors such as the distance, angle, ambient lighting, and contrast of the aerial photography equipment, in order to ensure that the adversarial patch optimized in the digital space is also effective in the physical world, it is necessary to consider the influence of the actual environment during the optimization process of the adversarial patch to improve the robustness of the adversarial patch to the complex environment. Specifically, in an embodiment of the present invention, by performing robust transformation processing on the adversarial patch, obtaining multiple transformation patches corresponding to the adversarial patch, and optimizing and updating the adversarial patch based on the obtained adversarial patch and its corresponding multiple transformation patches, the robustness of the adversarial patch to the complex environment can be significantly improved.

[0060] In the embodiment of the present invention, the robust transformation processing includes: angle rotation processing, size scaling processing, brightness adjustment and contrast adjustment.

[0061] Among them, angle rotation processing means rotating the adversarial patch, and size scaling processing means reducing or enlarging the adversarial patch. Angle rotation processing and size scaling processing are used to consider the influence of the distance and angle of the aerial photography equipment on the aerial remote sensing image. Brightness adjustment and contrast adjustment are achieved by adding random noise to the adversarial patch. Brightness adjustment and contrast adjustment are used to consider the influence of ambient lighting and contrast on the aerial remote sensing image.

[0062] Furthermore, in the embodiment of the present invention, when performing optimization update of the adversarial patch, the brightness adjustment range is set to [-0.1, 0.1], the contrast adjustment range is set to [0.8, 1.2], and the corresponding random noise factor is 0.1.

[0063] In the embodiment of the present invention, the scaling factor of the size scaling process is specifically set according to the actual situation, for example, it is set to [0.5, 2].

[0064] In the embodiment of the present invention, since the target may appear at any angle in the scene under the aerial photography perspective, the angle range of the angle rotation processing is set to [-180, 180].

[0065] Furthermore, in an embodiment of the present invention, the transformation patch is obtained by performing one or multiple robust transformation processes on the adversarial patch. To this end, each group of robust transformation processing parameters includes at least one robust transformation processing parameter.

[0066] In the embodiment of the present invention, in order to better simulate the complex environment, various robust transformation processing parameters can also be determined through experiments according to the actual layout position of the aerial remote sensing image target detection model and the actual specified specific target type.

[0067] Step 4, paste the transformed patches on the aerial remote sensing images in the training data to obtain multiple adversarial samples;

[0068] It should be noted that when pasting a patch on an aerial remote sensing image, the pasting position of the patch does not overlap with other existing target positions on the aerial remote sensing image.

[0069] In the embodiment of the present invention, the pasting position of the patch on the aerial remote sensing image can be randomly determined, as long as the pasting position of the patch does not overlap with other existing target positions on the aerial remote sensing image.

[0070] In the embodiments of the present invention, based on the multiple transformed patches obtained in the above step 3, one transformed patch can be pasted on one aerial remote sensing image respectively to obtain one adversarial sample corresponding to each transformed patch; or, for each transformed patch, the current transformed patch can be pasted on multiple different aerial remote sensing images to obtain multiple adversarial samples corresponding to each transformed patch.

[0071] Step 5: Use the multiple adversarial samples as the input of the aerial remote sensing image object detection model. According to the output of the aerial remote sensing image object detection model and the preset specific target optimization loss function, optimize and update the adversarial patch by using the backpropagation method to obtain the final adversarial patch.

[0072] In the embodiments of the present invention, the specific target optimization loss function includes: a non-target adversarial attack loss function and a target adversarial attack loss function. Among them, the non-target adversarial attack loss function is used to enable the aerial remote sensing image object detection model to recognize the patch as a target that originally does not exist, and the target adversarial attack loss function is used to enable the aerial remote sensing image object detection model to recognize the patch as a specific category target.

[0073] When the aerial remote sensing image object detection model detects an image, it will simultaneously predict and output the position, confidence, and category information of the targets in the image. Only when the confidence score corresponding to a target is greater than the set confidence threshold can the aerial remote sensing image object detection model detect and recognize the target. For this reason, in the embodiments of the present invention, a non-target adversarial attack loss function is constructed, and the adversarial patch is optimized by using the non-target adversarial attack loss function to increase the confidence score corresponding to the patch as much as possible, so that the aerial remote sensing image object detection model can recognize the patch in the image as a target that originally does not exist.

[0074] Further, in the embodiments of the present invention, the non-target adversarial attack loss function is expressed as:

[0075]

[0076] Wherein, represents the confidence score corresponding to the patch in the adversarial sample input to the aerial remote sensing image object detection model, and M represents the number of patches in the adversarial sample input to the aerial remote sensing image object detection model that are detected and recognized.

[0077] In the embodiments of the present invention, by minimizing the above non-target adversarial attack loss function it is possible to continuously increase the confidence score corresponding to the patch, so as to realize that the aerial remote sensing image object detection model recognizes the patch as a target that originally does not exist.

[0078] Furthermore, since the aerial remote sensing image target detection model will simultaneously predict and output the position, confidence and category information of the target in the image when detecting the image, and the category information is the category probability vector of all categories, the aerial remote sensing image target detection model will use the category corresponding to the maximum value in the category probability vector as the category of the detected target. To this end, in an embodiment of the present invention, a target adversarial attack loss function is constructed, and the adversarial patch is optimized by using the target adversarial attack loss function, so that the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model is as close as possible to the set category probability vector, and the category corresponding to the maximum value in the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model is the set category, so that the aerial remote sensing image target detection model recognizes the patch in the image as a specific category target.

[0079] In an embodiment of the present invention, the target adversarial attack loss function includes: a cross entropy loss function and a maximum target category probability loss function, wherein the cross entropy loss function is used to realize that the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model is as close as possible to the set category probability vector, and the maximum target category probability loss function is used to realize that the category corresponding to the maximum value in the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model is the set category.

[0080] Furthermore, in an embodiment of the present invention, the cross entropy loss function is expressed as:

[0081]

[0082] in, represents the set category probability vector, Represents the category probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, express and The cross entropy of M represents the number of patches detected and identified in the adversarial samples input to the aerial remote sensing image target detection model.

[0083] in, Expressed as Expressed as Represents the set category probability vector The probability of the Kth category in , Represents the category probability vector output by the aerial remote sensing image target detection model The probability of the Kth category in , where K represents the number of categories.

[0084] Cross-entropy is usually used to measure the difference between two probability distributions. For this reason, in an embodiment of the present invention, cross-entropy is used to measure the difference between the category probability vector output by the aerial remote sensing image target detection model and the set category probability vector. By minimizing the above-mentioned cross-entropy loss function, the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model can be made close to the set category probability vector, thereby enabling the aerial remote sensing image target detection model to identify the patch as a specific category target.

[0085] Furthermore, in an embodiment of the present invention, the maximum target category probability loss function is expressed as:

[0086]

[0087] in, Represents the maximum value of the category probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, that is, the category probability vector The maximum value in Represents the probability value corresponding to a specific category in the category probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, that is, the category probability vector The probability value corresponding to a specific category in , M represents the number of patches detected and identified in the adversarial sample input to the aerial remote sensing image target detection model.

[0088] In an embodiment of the present invention, by minimizing the above-mentioned maximum target category probability loss function, the category corresponding to the maximum value in the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model can be made the set category, thereby enabling the aerial remote sensing image target detection model to identify the patch as a specific category target.

[0089] Further, in an embodiment of the present invention, based on the non-target adversarial attack loss function, the cross entropy loss function and the maximum target category probability loss function defined above, the specific target optimization loss function is expressed as:

[0090]

[0091] Among them, α, β and γ represent weight coefficients, and the weight coefficients are in the range of [0,1]. The specific values ​​are set according to actual needs.

[0092] Furthermore, in an embodiment of the present invention, multiple adversarial samples are used as inputs of an aerial remote sensing image target detection model, a loss function is optimized according to the output of the aerial remote sensing image target detection model and a preset specific target, and the adversarial patch is optimized and updated using a back propagation method to obtain a final adversarial patch, further comprising the following steps:

[0093] Step 501, inputting a plurality of adversarial samples into the aerial remote sensing image target detection model respectively, and obtaining the position, confidence and category information corresponding to the patch in the adversarial samples output by the aerial remote sensing image target detection model;

[0094] Step 502, calculating a specific target optimization loss function according to the position, confidence and category information corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, as well as the set category probability vector and the specific category;

[0095] Step 503, determine whether the preset stop condition is met, if so, use the current adversarial patch as the final adversarial patch and end the optimization update process, if not, use the specific target optimization loss function to optimize and update the adversarial patch and continue to step 504;

[0096] Step 504, based on the optimized and updated adversarial patch, the adversarial patch is processed respectively according to a plurality of preset groups of robust transformation processing parameters to obtain a plurality of transformation patches corresponding to the adversarial patch;

[0097] Step 505 , paste the transformed patches on the aerial remote sensing images in the training data respectively to obtain multiple adversarial samples, and return to step 501 .

[0098] refer to Figure 3 , Figure 3 A schematic diagram of an adversarial patch with a target category of an aircraft provided in an embodiment of the present invention.

[0099] Furthermore, in an embodiment of the present invention, the stopping condition of the optimization update process is set according to actual conditions, for example, it is set to when the number of optimization updates reaches a set number, or it is set to when two consecutive loss function values ​​are both less than a preset threshold and the difference between the two is less than a preset difference.

[0100] Furthermore, in an embodiment of the present invention, a gradient descent method is used to optimize and update the adversarial patch.

[0101] Specifically, in the embodiment of the present invention, the following formula is used to optimize and update the anti-patch:

[0102]

[0103] Among them, P t+1 represents the adversarial patch at the t+1th optimization update, P t represents the adversarial patch at the tth optimization update, Δ[·] represents the optimizer, η represents the learning rate, L represents the specific target optimization loss function, and P represents the adversarial patch. The optimizer is set according to the actual situation, such as Adam, SGD, etc. The learning rate is pre-set to control the speed of the adversarial patch optimization update.

[0104] Furthermore, in the embodiment of the present invention, the method may further include:

[0105] Referring to the pasting position and method of the adversarial patch on the aerial remote sensing image, the final adversarial patch is placed in the real world to carry out adversarial attack.

[0106] The specific target generation adversarial attack method for aerial remote sensing target detection scenarios provided by an embodiment of the present invention can generate adversarial patches that can be detected as specific category targets by aerial remote sensing image target detectors, and can achieve effective adversarial attacks on aerial remote sensing image target detectors. The obtained adversarial patches are practical and feasible. By utilizing the obtained adversarial patches, other targets can be effectively prevented from detection and recognition by aerial remote sensing image target detectors, thereby achieving effective hiding of targets.

[0107] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In addition, "front", "back", "left", "right", "upper" and "lower" in this article are all referenced to the placement state shown in the accompanying drawings.

[0108] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A specific target generation adversarial attack method for aerial remote sensing target detection scenarios, characterized in that: include: Obtain the target detection model for aerial remote sensing images; Obtain a training data set, the training data including aerial remote sensing images; Obtaining an initial adversarial patch, processing the adversarial patch respectively according to a plurality of preset sets of robust transformation processing parameters, and obtaining a plurality of transformation patches corresponding to the adversarial patch; Paste the transformed patches on the aerial remote sensing images in the training data to obtain multiple adversarial samples; Multiple adversarial samples are used as input of the aerial remote sensing image target detection model. According to the output of the aerial remote sensing image target detection model and the preset specific target optimization loss function, the adversarial patch is optimized and updated using the back propagation method to obtain the final adversarial patch. The specific target optimization loss function includes: a non-target adversarial attack loss function and a target adversarial attack loss function. The non-target adversarial attack loss function is used to enable the aerial remote sensing image target detection model to recognize the patch as a target that does not exist originally, and the target adversarial attack loss function is used to enable the aerial remote sensing image target detection model to recognize the patch as a target of a specific category.

2. The specific target generation adversarial attack method for aerial remote sensing target detection scenarios according to claim 1 is characterized in that: Robust transformation processing includes: angle rotation processing, size scaling processing, brightness adjustment and contrast adjustment.

3. The specific target generation adversarial attack method for aerial remote sensing target detection scenarios according to claim 2 is characterized in that: Each set of robust transform process parameters includes at least one parameter of robust transform process.

4. The method for generating adversarial attacks on specific targets for aerial remote sensing target detection scenarios according to claim 1, characterized in that: The non-targeted adversarial attack loss function is expressed as: in, It represents the confidence score corresponding to the patch in the adversarial sample input to the aerial remote sensing image target detection model, and M represents the number of patches detected and identified in the adversarial sample input to the aerial remote sensing image target detection model.

5. The method for generating adversarial attacks on specific targets for aerial remote sensing target detection scenarios according to claim 4 is characterized in that: The target adversarial attack loss function includes: a cross entropy loss function and a maximum target category probability loss function. The cross entropy loss function is used to realize that the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model approaches the set category probability vector. The maximum target category probability loss function is used to realize that the category corresponding to the maximum value in the category probability vector corresponding to the patch output by the aerial remote sensing image target detection model is the set category.

6. The method for generating adversarial attacks on specific targets for aerial remote sensing target detection scenarios according to claim 5, characterized in that: The cross entropy loss function is expressed as: in, represents the set category probability vector, Represents the category probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, express and The cross entropy of .

7. The method for generating adversarial attacks on specific targets for aerial remote sensing target detection scenarios according to claim 6 is characterized in that: The maximum target category probability loss function is expressed as: in, Represents the maximum value of the category probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, Represents the probability value corresponding to a specific category in the category probability vector corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model.

8. The method for generating adversarial attacks on specific targets for aerial remote sensing target detection scenarios according to claim 7, characterized in that: The specific objective optimization loss function is expressed as: Among them, α, β and γ represent weight coefficients.

9. The specific target generation adversarial attack method for aerial remote sensing target detection scenarios according to any one of claims 1 to 8, characterized in that: The method uses multiple adversarial samples as inputs of the aerial remote sensing image target detection model, optimizes the loss function according to the output of the aerial remote sensing image target detection model and a preset specific target, optimizes and updates the adversarial patch by back propagation, and obtains the final adversarial patch, including the following steps: Step 501, inputting a plurality of adversarial samples into the aerial remote sensing image target detection model respectively, and obtaining the position, confidence and category information corresponding to the patch in the adversarial samples output by the aerial remote sensing image target detection model; Step 502, calculating a specific target optimization loss function according to the position, confidence and category information corresponding to the patch in the adversarial sample output by the aerial remote sensing image target detection model, as well as the set category probability vector and the specific category; Step 503, determine whether the preset stop condition is met, if so, use the current adversarial patch as the final adversarial patch and end the optimization update process, if not, use the specific target optimization loss function to optimize and update the adversarial patch and continue to step 504; Step 504, based on the optimized and updated adversarial patch, the adversarial patch is processed respectively according to a plurality of preset groups of robust transformation processing parameters to obtain a plurality of transformation patches corresponding to the adversarial patch; Step 505 , paste the transformed patches on the aerial remote sensing images in the training data respectively to obtain multiple adversarial samples, and return to step 501 .

10. The method for generating adversarial attacks on specific targets for aerial remote sensing target detection scenarios according to claim 9, characterized in that: The adversarial patch is optimized and updated using the following formula: Among them, P t+1 represents the adversarial patch at the t+1th optimization update, P t denotes the adversarial patch at the tth optimization update, Δ[·] denotes the optimizer, η denotes the learning rate, L denotes the target-specific optimization loss function, and P denotes the adversarial patch.