Black box confrontation attack method for aerial remote sensing target detection scene

By introducing weather disturbances into the aerial remote sensing target detection scenario and optimizing its parameters using differential evolution algorithms, the problem of the adversarial attack methods in the existing technology is difficult to adapt to aerial images and difficult to achieve black box attacks, and efficient and hidden adversarial sample generation is achieved.

CN120032208APending Publication Date: 2025-05-23NAT INNOVATION INST OF DEFENSE TECH PLA ACAD OF MILITARY SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510147748.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing adversarial attack methods are mainly designed for natural image data, which is difficult to adapt to aerial images, and are mostly white box attacks, making them difficult to apply to black box attack scenarios, resulting in poor effectiveness of adversarial samples.

Method used

A black box adversarial attack method for aerial photography remote sensing target detection scenarios is proposed. By introducing weather disturbances as adversarial disturbances, the parameters of weather disturbances are optimized using differential evolution algorithms to improve the concealment and attack success rate of adversarial samples.

Benefits of technology

By utilizing the natural properties of weather disturbances, the concealment of the adversarial samples is improved, and the attack success rate and attack effect of the adversarial samples are improved through the optimization of the differential evolution algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120032208A_ABST
    Figure CN120032208A_ABST
Patent Text Reader

Abstract

The invention, which relates to the technical field of computer vision, discloses a black-box anti-attack method for an aerial remote sensing target detection scene, comprising the following steps: acquiring an aerial remote sensing image target detection model; acquiring a training data set; determining a weather disturbance type and a disturbance variable value interval corresponding to each weather disturbance, selecting a disturbance variable value corresponding to each weather disturbance from the disturbance variable value interval corresponding to each weather disturbance, and obtaining a plurality of countermeasure disturbances; taking the plurality of adversarial disturbances as an initial population, adding the adversarial disturbances into the aerial remote sensing image, obtaining adversarial samples corresponding to the population, taking the plurality of adversarial samples as inputs of an aerial remote sensing image target detection model, and obtaining an aerial remote sensing image target detection result based on the initial population and a target detection result corresponding to the population. And performing population iteration optimization update by using a differential evolution algorithm to obtain final countermeasure disturbance. According to the method, the concealment, the attack success rate and the attack effect of the generated confrontation sample can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer vision technology, and in particular to a black box counterattack method for aerial remote sensing target detection scenarios. Background Art

[0002] With the continuous development of remote sensing technology, the number of images and videos that can be collected by earth observation satellites or aircraft has increased dramatically. How to correctly and efficiently process and utilize these aerial images is currently a key issue of concern.

[0003] In recent years, with the rapid development of deep learning technology, intelligent target detection algorithms based on deep learning have been widely used in the intelligent processing of massive aerial image data acquired from space or air, providing strong support for target recognition, dynamic monitoring, urban planning, change monitoring, forest fire prevention and other fields. However, with the continuous exploration of deep learning, studies have shown that deep learning models that perform well on real clean data are easily deceived by maliciously constructed adversarial samples, resulting in incorrect output results from the trained deep learning models.

[0004] Adversarial samples are usually defined as adding maliciously designed disturbances to clean samples. Usually, such disturbances will not interfere with the judgment of the human eye, but can mislead some trained deep learning models to produce incorrect prediction outputs. In practical applications, although the existence of adversarial samples will bring security threats to the application of deep learning models, it can also be used in scenarios such as anti-reconnaissance and anti-surveillance, as well as for training and testing deep learning models to improve the robustness of the models.

[0005] At present, when evaluating adversarial attack methods, a comprehensive evaluation is usually conducted from three aspects: attack effectiveness, robustness, and the concealment of generated adversarial samples. Effectiveness mainly focuses on evaluating the attack success rate of the adversarial attack method, robustness mainly considers the versatility of the adversarial attack method, and concealment mainly considers the ability of the generated adversarial samples to deceive the detector while deceiving the human eye.

[0006] In existing adversarial attack methods, in order to improve the concealment of adversarial perturbations, various metric functions (such as Lp norm constraints) are usually used to limit the size of the generated perturbations. However, the existing adversarial attack methods are mainly designed for natural image data taken on the ground. Natural images have the characteristics of short shooting distance and obvious imaging color contrast. In contrast, aerial images look smoother visually and the background color tends to be monotonous because of the long shooting distance. Therefore, even if the perturbation intensity is limited, when the adversarial attack method designed for natural image data is directly used for aerial images, the generated adversarial samples are still easily noticed by the human eye.

[0007] In addition, adversarial attacks can be divided into white-box attacks and black-box attacks, depending on whether the structure and parameters of the model to be attacked are known. White-box attacks refer to known information such as the structure and parameters of the model, and adversarial samples can be constructed by analyzing the model structure for adversarial attacks. Black-box attacks refer to unknown information such as the structure and parameters of the model, but the model can be accessed and queried. The existing adversarial attack methods are mainly white-box attack methods based on gradient optimization. However, in practical applications, the internal structure and parameter information of the model to be attacked are usually unknown, which makes the existing adversarial attack methods based on gradient optimization difficult to apply, and the effectiveness of the generated adversarial samples is poor. Summary of the invention

[0008] In order to solve some or all of the technical problems existing in the above-mentioned prior art, the present invention provides a black box counterattack method for aerial remote sensing target detection scenarios.

[0009] The technical solution of the present invention is as follows:

[0010] A black box adversarial attack method for an aerial remote sensing target detection scenario is provided, the method comprising:

[0011] Obtain the target detection model for aerial remote sensing images;

[0012] Acquire a training data set, where the training data includes an aerial remote sensing image containing a specified target;

[0013] Determine the weather disturbance type and the disturbance variable value interval corresponding to each weather disturbance, select the disturbance variable value corresponding to each weather disturbance from the disturbance variable value interval corresponding to each weather disturbance, obtain an adversarial disturbance including various weather disturbances and their corresponding disturbance variable values, and obtain multiple adversarial disturbances;

[0014] Multiple adversarial perturbations are used as initial populations, and the adversarial perturbations in the populations are respectively added to the aerial remote sensing images of the training data to obtain multiple adversarial samples corresponding to the multiple adversarial perturbations in the population. The multiple adversarial samples are respectively used as inputs of the aerial remote sensing image target detection model to obtain the target detection results output by the aerial remote sensing image target detection model. Based on the target detection results output by the aerial remote sensing image target detection model corresponding to the initial population and the obtained population, a differential evolution algorithm is used to iteratively optimize and update the population to obtain the final adversarial perturbation.

[0015] In some optional implementations, the training data set is obtained in the following manner:

[0016] Select multiple aerial remote sensing images from a specified image data set, input the selected multiple aerial remote sensing images into the aerial remote sensing image target detection model for target detection, obtain the detection results output by the aerial remote sensing image target detection model, and use the aerial remote sensing images in which the specified targets are detected as training data according to the detection results output by the aerial remote sensing image target detection model;

[0017] Repeat the previous step until a preset amount of training data is obtained to form a training data set.

[0018] In some optional implementations, the aerial remote sensing images are selected from the image data set by random selection.

[0019] In some optional embodiments, the weather disturbance types include: snow, fog, solar flare, and shadow.

[0020] In some optional implementations, the target detection result output by the aerial remote sensing image target detection model includes: a target detection box and its corresponding confidence level.

[0021] In some optional implementations, the target detection results output by the aerial remote sensing image target detection model based on the initial population and the obtained population are updated by iterative optimization of the population using a differential evolution algorithm to obtain the final adversarial disturbance, including:

[0022] Step 401, calculating the fitness function value corresponding to each adversarial disturbance in the initial population according to the target detection result output by the aerial remote sensing image target detection model corresponding to the initial population;

[0023] Step 402, determine whether the preset termination condition is met, if not, proceed to the next step, if yes, proceed to step 406;

[0024] Step 403, based on the current population and the fitness function, performing population mutation, crossover and selection operations to obtain an intermediate population including multiple adversarial disturbances;

[0025] Step 404, selecting multiple adversarial perturbations from the current population and the intermediate population as a new generation population, and obtaining adversarial samples corresponding to each adversarial perturbation in the new generation population;

[0026] Step 405, using the multiple adversarial samples as inputs of the aerial remote sensing image target detection model, obtaining target detection results output by the aerial remote sensing image target detection model, calculating the fitness function value corresponding to each adversarial perturbation in the new generation population according to the target detection results output by the aerial remote sensing image target detection model, and returning to step 402;

[0027] Step 406: Select the adversarial disturbance with the smallest corresponding fitness function value in the current population as the final adversarial disturbance and output it.

[0028] In some optional implementations, the fitness function is expressed as:

[0029] f(ε)=length(p(ε) obj -S 0 );

[0030] Among them, f(ε) represents the fitness function value corresponding to the adversarial disturbance ε in the population, and p(ε) obj represents the confidence vector of the target detection box output by the aerial remote sensing image target detection model corresponding to the adversarial sample corresponding to the adversarial perturbation ε, S 0 Represents the set confidence threshold, and length represents the number of confidence scores in the confidence vector that are greater than the confidence threshold.

[0031] In some optional embodiments, the termination condition is set to that there is at least one adversarial disturbance whose corresponding fitness function value is less than a set value.

[0032] In some optional embodiments, the target is one of an aircraft, a ship and a vehicle.

[0033] The main advantages of the technical solution of the present invention are as follows:

[0034] The black-box adversarial attack method for aerial remote sensing target detection scenarios of the present invention generates adversarial samples by introducing weather as adversarial perturbations, and can utilize the natural properties of weather to improve the concealment of the generated adversarial samples. At the same time, the parameters of weather perturbations are optimized and solved by using a differential evolution algorithm, which can achieve rapid solution of the parameters of weather perturbations and improve the attack success rate and attack effect of the generated adversarial samples. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The drawings described herein are used to provide a further understanding of the embodiments of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0036] Figure 1 A flowchart of a black box counterattack method for aerial remote sensing target detection scenarios provided by an embodiment of the present invention;

[0037] Figure 2 A schematic diagram of the disturbance generation principle provided by an embodiment of the present invention;

[0038] Figure 3 An adversarial sample with a target of an airplane is provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the specific embodiments of the present invention and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0040] The technical solution provided by the embodiments of the present invention is described in detail below with reference to the accompanying drawings.

[0041] refer to Figure 1-2 The embodiment of the present invention provides a black box counterattack method for aerial remote sensing target detection scenarios, the method comprising the following steps 1-4:

[0042] Step 1: Obtain an aerial remote sensing image target detection model;

[0043] In the embodiment of the present invention, if there is currently an aerial remote sensing image target detection model, then an aerial remote sensing image target detection model is arbitrarily selected from the existing aerial remote sensing image target detection models.

[0044] In an embodiment of the present invention, if there is no aerial remote sensing image target detection model at present, considering that the existing target detection can be divided into a single-stage and a two-stage series, the single-stage target detection mainly includes the YOLO series neural network, and the two-stage target detection is represented by the Faster R-CNN neural network. Therefore, a trained YOLO series neural network or Faster R-CNN neural network is selected as the aerial remote sensing image target detection model, and the YOLO series neural network includes YOLOv2, YOLOv3, and YOLOv4 neural networks.

[0045] Step 2, obtaining a training data set, the training data including an aerial remote sensing image containing a specified target;

[0046] In an embodiment of the present invention, the training data set includes a plurality of training data, and the training data includes an aerial remote sensing image containing a designated target.

[0047] In the embodiment of the present invention, the designated target is set according to actual needs, such as an airplane, a ship, or a vehicle.

[0048] Furthermore, in an embodiment of the present invention, a training data set is obtained by using an existing known image data set, and the training data set is obtained specifically by the following method:

[0049] Step 201, selecting a plurality of aerial remote sensing images from a specified image data set, respectively inputting the selected plurality of aerial remote sensing images into an aerial remote sensing image target detection model for target detection, obtaining detection results output by the aerial remote sensing image target detection model, and using the aerial remote sensing images in which the specified targets are detected as training data according to the detection results output by the aerial remote sensing image target detection model;

[0050] Step 202, repeat step 201 until a preset amount of training data is obtained to form a training data set.

[0051] In an embodiment of the present invention, the image dataset includes: at least one of a DOTA-v1.0 dataset, an RSOD dataset, and a NWPU VHR-10 dataset.

[0052] Among the multiple image datasets mentioned above, the DOTA-v1.0 dataset is a large-scale dataset containing 2,806 images, including 15 common target categories including aircraft collected from different sensors and platforms. However, since the image sizes in the DOTA-v1.0 dataset are in different ranges, when choosing to obtain training data from the DOTA-v1.0 dataset, all images in the dataset are divided into sub-images of 608x608 pixels so that the selected training data has a consistent format.

[0053] In the embodiment of the present invention, when selecting the aerial remote sensing image from the image data set, a random selection method is adopted.

[0054] Step 3, determining the weather disturbance type and the disturbance variable value interval corresponding to each weather disturbance, selecting the disturbance variable value corresponding to each weather disturbance from the disturbance variable value interval corresponding to each weather disturbance, obtaining an adversarial disturbance including various weather disturbances and their corresponding disturbance variable values, and obtaining multiple adversarial disturbances;

[0055] In actual environments, the quality of imaging images is easily affected by weather factors such as snow, fog, and rain, resulting in large differences in images under different weather conditions. However, due to the natural properties of the weather, it will not be noticed by the human eye. For this reason, in an embodiment of the present invention, by introducing weather disturbance as an optimization variable, the generated adversarial samples can be made less noticeable, thereby improving the concealment of the adversarial samples.

[0056] In the embodiment of the present invention, the countermeasure disturbance includes various weather disturbances and their corresponding disturbance variable values, which can be specifically expressed as (θ 1 ,θ 2 ,...,θ m ), where θ m It represents the disturbance variable value corresponding to the mth weather disturbance, and m represents the number of weather disturbance types.

[0057] In the embodiment of the present invention, the weather disturbance types include: snow, fog, solar flare and shadow.

[0058] Although rainfall is a common weather condition, for aerial image data, the rainfall process cannot be observed from an aerial bird's-eye view, and puddles formed by rainwater gathering on the ground are visually close to solar flares. Therefore, in an embodiment of the present invention, rainfall is not considered as a weather disturbance type.

[0059] In an embodiment of the present invention, a disturbance variable value corresponding to each weather disturbance is selected from the disturbance variable value interval corresponding to each weather disturbance to obtain an adversarial disturbance including various weather disturbances and their corresponding disturbance variable values. This process is repeated multiple times to obtain multiple adversarial disturbances.

[0060] In the embodiment of the present invention, the number of countermeasure disturbances is determined according to actual needs.

[0061] Step 4: Use multiple adversarial perturbations as initial populations, add the adversarial perturbations in the populations to the aerial remote sensing images of the training data, obtain multiple adversarial samples corresponding to the multiple adversarial perturbations in the population, use the multiple adversarial samples as inputs to the aerial remote sensing image target detection model, obtain the target detection results output by the aerial remote sensing image target detection model, and use the differential evolution algorithm to iteratively optimize and update the population based on the target detection results output by the aerial remote sensing image target detection model corresponding to the initial population and the obtained population, and obtain the final adversarial perturbation.

[0062] In the embodiment of the present invention, an adversarial disturbance is regarded as an individual in a population, and an initial population including multiple adversarial disturbances obtained in step 3 is obtained.

[0063] In the embodiment of the present invention, since the adversarial perturbation includes various weather perturbations and their corresponding perturbation variable values, in order to facilitate adding the adversarial perturbation to the aerial remote sensing image, when adding the adversarial perturbation to the aerial remote sensing image, the Automold package built on OpenCV is used to implement it. Automold is an open source Python library specifically used to enhance images to simulate various real-world scenes.

[0064] Furthermore, in an embodiment of the present invention, when the Automold package built based on OpenCV is used to implement the addition of weather disturbances in aerial remote sensing images, the disturbance variables corresponding to various weather disturbances and the disturbance variable value ranges are shown in Table 1 below.

[0065] Table 1 Disturbance variables corresponding to weather disturbances and the range of disturbance variables

[0066] Weather disturbances Disturbance Variable Value range Numeric Types Snow snow_coeff [0,0.3] Float fog fog_coeff [0,0.3] Float Solar flares Position coordinates [x,y] [0,1] Float shadow Dimensions [3,8] Int

[0067] In an embodiment of the present invention, each adversarial perturbation in the population has a corresponding adversarial sample, and when the adversarial perturbation is added to an aerial remote sensing image of a training data, different adversarial perturbations are added to aerial remote sensing images of different training data.

[0068] Furthermore, in an embodiment of the present invention, the target detection result output by the aerial remote sensing image target detection model includes: a target detection frame and its corresponding confidence level.

[0069] Further, in an embodiment of the present invention, based on the target detection results output by the aerial remote sensing image target detection model corresponding to the initial population and the obtained population, a differential evolution algorithm is used to perform iterative optimization and update of the population to obtain the final adversarial disturbance, including the following steps 401-406:

[0070] Step 401, calculating the fitness function value corresponding to each adversarial disturbance in the initial population according to the target detection result output by the aerial remote sensing image target detection model corresponding to the initial population;

[0071] In the embodiment of the present invention, the fitness function is expressed as:

[0072] f(ε)=length(p(ε) obj -S 0 );

[0073] Among them, f(ε) represents the fitness function value corresponding to the adversarial disturbance ε in the population, and p(ε) obj represents the confidence vector of the target detection box output by the aerial remote sensing image target detection model corresponding to the adversarial sample corresponding to the adversarial perturbation ε, S 0 Represents the set confidence threshold, and length represents the number of confidence scores in the confidence vector that are greater than the confidence threshold.

[0074] Among them, p(ε) obj Expressed as It represents the confidence of the nth target detection box output by the aerial remote sensing image target detection model corresponding to the adversarial sample corresponding to the adversarial perturbation ε.

[0075] In an embodiment of the present invention, based on the fitness function set above, the fitness function value corresponding to each adversarial disturbance in the initial population is calculated according to the target detection result output by the aerial remote sensing image target detection model.

[0076] Step 402, determine whether the preset termination condition is met, if not, proceed to the next step, if yes, proceed to step 406;

[0077] In the embodiment of the present invention, the termination condition is specifically set according to the actual situation.

[0078] When the current target detector is working, the final prediction result will apply a preset confidence threshold to filter out redundant detection results with low confidence, and finally exclude detection frames with high mutual overlap through a non-maximum suppression mechanism. The purpose of the adversarial perturbation to be generated by the embodiment of the present invention is to make the confidence value of the target in the aerial remote sensing image detected and identified by the target detector lower than the confidence threshold after adding the adversarial perturbation, so that the target cannot be detected and identified by the target detector, thereby achieving the "camouflage" and "invisibility" effect of the target. To this end, the termination condition can be set to the fitness function value corresponding to at least one adversarial perturbation being less than the set value.

[0079] Step 403, based on the current population and the fitness function, performing population mutation, crossover and selection operations to obtain an intermediate population including multiple adversarial disturbances;

[0080] In an embodiment of the present invention, based on the current population and the fitness function, population mutation, crossover and selection operations are performed to obtain an intermediate population including multiple adversarial disturbances, including the following steps:

[0081] Based on the current population, perform mutation operations to obtain multiple mutant individuals;

[0082] According to the current population and its corresponding mutant individuals, a crossover operation is performed to obtain the offspring population corresponding to the current population;

[0083] According to the current population and its corresponding offspring population, the selection operation is performed with the goal of minimizing the fitness function value corresponding to the individual to obtain the intermediate population.

[0084] Among them, the obtained intermediate population is the next generation population of the current population.

[0085] Specifically, set the current population to:

[0086]

[0087] Among them, P t represents the current population, that is, the tth generation population, P t (i) represents the population P t The i-th individual in represents the range of individual variable values, N represents the total number of individuals in the population, and T represents the total number of iterations.

[0088] The mutation operation is expressed as:

[0089] P M (i) = P t (r 1 )+F(P t (r 2 )-Pt (r 3 ))r 1 ≠r 2 ≠r 3 ≠i;

[0090] Among them, P M (i) represents individual P t (i) The corresponding variant individual, F represents the mutation factor, P t (r 1 ), P t (r 2 ) and P t (r 3 ) represent the population P t The rth 1 Individual, 2 Individuals and r 3 Individuals, r 1 、r 2 and r 3 Represents individual indexes that satisfy the mutual inequality constraint.

[0091] The crossover operation is expressed as:

[0092]

[0093] Among them, P C (i) represents the population P t The corresponding offspring population P C The i-th individual in N individuals P C (i) (i = 1, 2, ..., N) constitutes the offspring population P C , C r represents the mutation probability, and rand represents random sampling from the interval [0,1].

[0094] The selection operation is represented as:

[0095]

[0096] Among them, P t+1 (i) represents the t+1 generation population P t+1 The i-th individual in f(P t (i)) represents individual P t (i) The corresponding fitness function value, f(P C (i)) represents individual P C (i) A corresponding fitness function value, which is calculated according to the fitness function set above.

[0097] It should be noted that the above individuals also represent resistance to disturbances.

[0098] Step 404, selecting multiple adversarial perturbations from the current population and the intermediate population as a new generation population, and obtaining adversarial samples corresponding to each adversarial perturbation in the new generation population;

[0099] In the embodiment of the present invention, a preset number of adversarial disturbances with the smallest fitness function values ​​are selected from the current population and the intermediate population as individuals in the population to form a new generation of population.

[0100] In the embodiment of the present invention, the number of individuals in different generations of populations is the same, that is, the number of countermeasures is the same. In this case, the preset number is the same as the number of countermeasures in the initial population.

[0101] In an embodiment of the present invention, one adversarial perturbation in the new generation population is added to an aerial remote sensing image of training data to obtain multiple adversarial samples corresponding to multiple adversarial perturbations in the new generation population.

[0102] In an embodiment of the present invention, when adding an adversarial perturbation to an aerial remote sensing image of one training data, different adversarial perturbations are added to aerial remote sensing images of different training data.

[0103] Step 405, using the multiple adversarial samples as inputs of the aerial remote sensing image target detection model, obtaining target detection results output by the aerial remote sensing image target detection model, calculating the fitness function value corresponding to each adversarial perturbation in the new generation population according to the target detection results output by the aerial remote sensing image target detection model, and returning to step 402;

[0104] In the embodiment of the present invention, the fitness function value is calculated according to the fitness function set above.

[0105] Step 406: Select the adversarial disturbance with the smallest corresponding fitness function value in the current population as the final adversarial disturbance and output it.

[0106] In an embodiment of the present invention, when the termination condition is met, the adversarial disturbance with the smallest corresponding fitness function value in the current population is selected as the final adversarial disturbance and output.

[0107] Specifically, based on the fitness function defined above, the smaller the obtained fitness function value is, the better the adversarial attack effect against the disturbance is.

[0108] In the embodiment of the present invention, by adopting the above-mentioned differential evolution algorithm to perform optimization update against disturbance, there is no need to use the gradient information of the objective function, and it has strong global search capability, good robustness, high efficiency and easy implementation.

[0109] refer to Figure 3 Furthermore, in an embodiment of the present invention, the method further includes:

[0110] Add the final adversarial perturbation to the aerial remote sensing image to obtain adversarial samples.

[0111] The black-box adversarial attack method for aerial remote sensing target detection scenarios provided by the embodiment of the present invention generates adversarial samples by introducing weather as adversarial perturbations, and can utilize the natural properties of weather to improve the concealment of the generated adversarial samples; at the same time, the parameters of weather perturbations are optimized and solved by using a differential evolution algorithm, which can achieve rapid solution of the parameters of weather perturbations and improve the attack success rate and attack effect of the generated adversarial samples.

[0112] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In addition, "front", "back", "left", "right", "upper" and "lower" in this article are all referenced to the placement state shown in the accompanying drawings.

[0113] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A black box adversarial attack method for aerial remote sensing target detection scenarios, characterized in that: The method comprises: Obtaining aerial remote sensing image target detection model; Acquire a training data set, where the training data includes an aerial remote sensing image containing a specified target; Determine the weather disturbance type and the disturbance variable value interval corresponding to each weather disturbance, select the disturbance variable value corresponding to each weather disturbance from the disturbance variable value interval corresponding to each weather disturbance, obtain an adversarial disturbance including various weather disturbances and their corresponding disturbance variable values, and obtain multiple adversarial disturbances; Multiple adversarial perturbations are used as initial populations, and the adversarial perturbations in the populations are respectively added to the aerial remote sensing images of the training data to obtain multiple adversarial samples corresponding to the multiple adversarial perturbations in the population. The multiple adversarial samples are respectively used as inputs of the aerial remote sensing image target detection model to obtain the target detection results output by the aerial remote sensing image target detection model. Based on the target detection results output by the aerial remote sensing image target detection model corresponding to the initial population and the obtained population, a differential evolution algorithm is used to iteratively optimize and update the population to obtain the final adversarial perturbation.

2. The black box counterattack method for aerial remote sensing target detection scenarios according to claim 1 is characterized in that: Get the training data set by: Select multiple aerial remote sensing images from a specified image data set, input the selected multiple aerial remote sensing images into the aerial remote sensing image target detection model for target detection, obtain the detection results output by the aerial remote sensing image target detection model, and use the aerial remote sensing images in which the specified targets are detected as training data according to the detection results output by the aerial remote sensing image target detection model; Repeat the previous step until a preset amount of training data is obtained to form a training data set.

3. The black box counterattack method for aerial remote sensing target detection scenarios according to claim 2 is characterized in that: Aerial remote sensing images are selected from the image dataset by random selection.

4. The black box counterattack method for aerial remote sensing target detection scenarios according to claim 1 is characterized in that: Weather disturbance types include: snow, fog, solar flares, and shadows.

5. The black box counterattack method for aerial remote sensing target detection scenarios according to claim 1 is characterized in that: The target detection results output by the aerial remote sensing image target detection model include: target detection box and its corresponding confidence.

6. The black box counterattack method for aerial remote sensing target detection scenarios according to claim 5 is characterized in that: The target detection results output by the aerial remote sensing image target detection model based on the initial population and the obtained population are updated by using a differential evolution algorithm to iteratively optimize the population and obtain the final adversarial disturbance, including: Step 401, calculating the fitness function value corresponding to each adversarial disturbance in the initial population according to the target detection result output by the aerial remote sensing image target detection model corresponding to the initial population; Step 402, determine whether the preset termination condition is met, if not, proceed to the next step, if yes, proceed to step 406; Step 403, based on the current population and the fitness function, performing population mutation, crossover and selection operations to obtain an intermediate population including multiple adversarial disturbances; Step 404, selecting multiple adversarial perturbations from the current population and the intermediate population as a new generation population, and obtaining adversarial samples corresponding to each adversarial perturbation in the new generation population; Step 405, using the multiple adversarial samples as inputs of the aerial remote sensing image target detection model, obtaining target detection results output by the aerial remote sensing image target detection model, calculating the fitness function value corresponding to each adversarial perturbation in the new generation population according to the target detection results output by the aerial remote sensing image target detection model, and returning to step 402; Step 406: Select the adversarial disturbance with the smallest corresponding fitness function value in the current population as the final adversarial disturbance and output it.

7. The black box counterattack method for aerial remote sensing target detection scenarios according to claim 6 is characterized in that: The fitness function is expressed as: f(ε)=length(p(ε) obj -S0); Among them, f(ε) represents the fitness function value corresponding to the adversarial disturbance ε in the population, and p(ε) obj It represents the confidence vector of the target detection box output by the aerial remote sensing image target detection model corresponding to the adversarial sample corresponding to the adversarial perturbation ε, S0 represents the set confidence threshold, and length represents the number of confidence scores in the confidence vector greater than the confidence threshold.

8. The black box counterattack method for aerial remote sensing target detection scenarios according to claim 7 is characterized in that: The termination condition is set to that there is at least one adversarial disturbance whose corresponding fitness function value is less than the set value.

9. The black box adversarial attack method for aerial remote sensing target detection scenarios according to any one of claims 1 to 8, characterized in that: The target is one of an aircraft, a ship and a vehicle.