Annular cutting-based adversarial patch generation method for multi-view detection
Through the adversarial patch generation method based on ring cropping, the problem of insufficient robustness of the existing technology in the multi-view condition is solved, and efficient attack effect is achieved in multi-view detection scenarios.
Patent Information
- Application Number
- CN202510384218.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-06-13
AI Technical Summary
The prior art has insufficient robustness and adaptability of the adversarial patch when facing multi-view conditions, especially when the camera rotates violently, some adversarial logos may disappear from the rendered image, resulting in an attack failure.
The adversarial patch generation method based on ring cropping is adopted to achieve seamless generation of patch patterns through ring cropping operations, and the patch pattern is optimized in combination with the objective function and the total variation loss to generate an adversarial patch that can effectively deceive the target deep learning model under multi-view conditions.
The robustness and adaptability of adversarial attacks in multi-view detection scenarios is improved. The generated adversarial patches can effectively deceive the target model and maintain efficient attack effects in different environments.
Smart Images

Figure CN120147788A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of adversarial attacks, and specifically relates to an adversarial patch generation method for multi-view detection based on circular cropping. Background Art
[0002] With the wide application of deep learning technology, object detection systems play an increasingly important role in various industries, such as intelligent security, autonomous driving, medical image analysis, etc. However, the security of object detection systems has gradually become the focus of research attention, especially when facing adversarial attacks. Such attacks usually cause the object detection model to make wrong judgments by applying tiny perturbations to the input image, and even misjudge or miss some key targets. The emergence of adversarial attacks has raised great concerns about the security of artificial intelligence systems. Especially in practical applications, the reliability and robustness of the system are severely challenged. Adversarial patches are usually captured by the camera of the detection system. When the camera rotates violently, some patches will not be captured, which may cause the detector to underestimate the threat, and the camera can be placed anywhere in the real scene. The prior art proposed an adversarial T-shirt printed with adversarial patches. People wearing the T-shirt can also avoid the human body detector. The above-mentioned human body detector attack method is only effective when the adversarial patch faces the camera. Obviously, a single adversarial patch on a piece of clothing is difficult to attack detectors from multiple perspectives because the camera can only capture a part of the severely deformed patch. A new Logo transformation pipeline has also been developed in the prior art, which can map 2D patterns of arbitrary shapes onto 3D human meshes and extends the flexibility and application scope of the method through multi-mesh joint training. The proposed 3D adversarial logo can effectively make the marked person "disappear" under multiple angular views. However, when the camera rotates violently, some adversarial logos may disappear from the rendered image, resulting in the failure of the attack, especially when the unseen angle reaches 50 degrees. In addition, after multi-angle training (between -10 and 10 degrees), when attacking with a wider perspective (-50 to 50 degrees), a significant performance degradation is observed as the perspective changes greatly, indicating that the effect of this method is limited under extreme perspectives. Summary of the Invention
[0003] The purpose of the present invention is to provide an adversarial patch generation method for multi-view detection based on circular cropping, which can generate adversarial patches with high effectiveness and concealment in the physical world, effectively deceive the target deep learning model, and at the same time improve the robustness of adversarial attacks under different environments for the complex conditions of different perspectives in the physical environment.
[0004] The technical solution for achieving the purpose of the present invention is as follows:
[0005] An adversarial patch generation method for multi-view detection based on circular cropping, comprising the following steps:
[0006] Step 1: Randomly select a cropping window from the global pattern, and this cropping window determines the initial position of the patch pattern;
[0007] Step 2: Achieve seamless generation of the patch pattern through circular cropping operations. Use the circular cropping method to connect the pattern boundaries to ensure continuity when the cropped area crosses the boundary;
[0008] Step 3: Optimize the patch pattern by combining the objective function and the total variation loss, aiming to maximize the adversarial effect by adjusting the content of the patch pattern;
[0009] Step 4: Divide the real physical deformation of the patch pattern into two steps, the out-of-plane bending of the patch pattern and the pitch rotation of the patch pattern. By mapping each point of the patch pattern from a two-dimensional plane to a parabolic cylinder in three-dimensional space, the local bending and angular changes of the patch pattern are restored to generate an adversarial patch. Input the generated adversarial patch into the corresponding target detector, calculate the corresponding loss function based on the detection result, and continuously adjust the adversarial patch through iterative optimization to obtain an adversarial patch that maximizes the adversarial attack effect.
[0010] Preferably, step 1 includes the following steps:
[0011] Step 1.1: Generate a global pattern τ, and then randomly crop a local area from the global pattern τ as the patch pattern to meet the adversarial requirements of the target detector;
[0012] During the process of generating the adversarial patch, the patch pattern is generated by randomly selecting a position from the global pattern τ and cropping a region of a fixed size. This process can be expressed by the following formula:
[0013]
[0014] where τ is the global pattern, is the patch pattern, and Crop rand (·) is a random cropping operation that can generate diverse local patches within the global pattern;
[0015] Step 1.2: On this basis, the attack objective function can be expressed as:
[0016]
[0017] where L obj represents the attack objective function, Denote the expectation with respect to I and M. Let f(·) denote the function for measuring the object detection model, M(·) denote the rendering function, and I denote the clean image.
[0018] Preferably, step 2 includes the following steps:
[0019] Step 2.1: Regard the global pattern τ as a two-dimensional torus, that is, assume that the upper and lower boundaries and the left and right boundaries of the pattern are connected to each other, so as to achieve seamless circular cropping. Each patch pattern cropped from the global pattern τ is generated by a circular cropping operation. The objective function of the adversarial patch is defined as:
[0020]
[0021] where L adv denotes the adversarial loss, denotes the expectation, f(·) denotes the function for measuring the object detection model, M(·) denotes the rendering function, I denotes the clean image, Crop toro (·) denotes the cropping function, and τ local denotes the input pattern;
[0022] Step 2.2: Set the size of the input pattern τ local to H×W, where H represents the height of the image and W represents the width of the image. The implementation process of circular cropping can be divided into the following steps:
[0023] First, randomly select a starting point (i, j) in the global pattern τ, where i ∈ [0, H - 1] and j ∈ [0, W - 1]. This point serves as the upper left corner of the cropping window, determining the initial position of the cropping;
[0024] Next, according to the starting position and the size of the cropping area, extract the patch pattern from the pattern The patch pattern The calculation of each pixel value in is given by the following formula:
[0025]
[0026] where (u, v) represents the relative coordinates within the patch pattern, and (i + u) mod H and (j + v) mod W perform modulo operations on the indices in the vertical and horizontal directions respectively to achieve circular cropping.
[0027] Preferably, step 3 specifically includes the following steps:
[0028] Step 3.1: When the cropping window exceeds the boundary of the global pattern τ, the exceeded part continues to obtain pixel values from the other side of the global pattern τ, so as to ensure that the cropped patch pattern It is seamlessly connected throughout the area. During the optimization process, first, through the objective function L obj optimize the patch pattern to maximize the adversarial effect;
[0029] Step 3.2: To enhance the smoothness and detail retention of the generated texture during the optimization process, the total variation loss is introduced, and its formula is as follows:
[0030]
[0031] In the formula, L tv represents the total variation loss, τ i,j represents the pixel coordinates (i, j), τ i+1,j represents the pixel coordinates (i + 1, j), τ i,j+1 represents the pixel coordinates (i, j + 1), τ i,j -τ i,j+1 represents the pixel difference;
[0032] Then the total loss function can be written as:
[0033] L = L obj + αL tv
[0034] In the formula, L represents the total loss function, and α represents the hyperparameter.
[0035] Preferably, step 4 specifically includes the following steps:
[0036] Step 4.1: In adversarial patch generation, EOT makes the generated adversarial patch maintain the attack effect after undergoing a series of predefined spatial transformations. The series of spatial transformations includes rotation, scaling, translation, and brightness adjustment;
[0037] Step 4.2: The transformation that occurs when rendering the patch pattern onto the target image is divided into two steps: off-plane bending of the patch pattern and pitch rotation of the patch pattern. The formula is as follows:
[0038]
[0039] In the formula, x′ represents the new coordinate value after transformation, a represents the hyperparameter, x represents the initial coordinate value, and ln(·) represents the natural logarithm function;
[0040] Step 4.3: Generate an adversarial patch in step 4.2 that can be used to attack the corresponding target detector. The target detector detects the adversarial patch and calculates the corresponding loss function based on the detection result. Continuously adjust the adversarial patch through iterative optimization to obtain an adversarial patch that can maximize the adversarial attack effect and fit the characteristics of the target detector.
[0041] Beneficial effects: Compared with the prior art, the present invention has the following advantages:
[0042] 1. Through the joint design of the circular cropping mechanism and the optimization objective, the method of the present invention uses circular cropping to ensure boundary continuity, combines the objective function with the total variation loss optimization, randomly crops from the overall pattern during iteration and updates the global pattern parameters according to the attack objective function, and generates adversarial textures with edge continuity.
[0043] 2. By adopting non-planar sticker conversion, the adversarial patch is mapped from a two-dimensional plane to the geometry of a three-dimensional space to adapt to the curved surface characteristics in the actual physical scene. Further, through the constraint of the total variation loss, the smoothness and detail retention of the adversarial patch texture are enhanced.
[0044] 3. The adversarial patches generated by the present invention can effectively improve the attack effect on the target model in the multi-view detection scenario, enhance the robustness and adaptability of the adversarial attack, and have important significance for the security evaluation of deep learning models. Description of the Drawings
[0045] Figure 1 It is a flowchart of the adversarial patch generation method of the present invention;
[0046] Figure 2 It is an overall framework diagram of the adversarial patch generation of the present invention;
[0047] Figure 3 It is a display diagram of the circular cropping effect of the present invention;
[0048] Figure 4 It is an effect diagram of non-planar sticker conversion of the present invention. Detailed Embodiments
[0049] To better understand the present invention, the content of the present invention will be further described below with reference to the drawings.
[0050] Combined with Figure 1 , the adversarial patch generation method for multi-view detection based on circular cropping of the present invention includes the following steps:
[0051] Step 1. Randomly select a cropping window from the global pattern, and this cropping window determines the initial position of the patch pattern, which specifically includes the following steps:
[0052] Step 1.1. Generate the global pattern τ by randomly initializing in the pixel space, that is, randomly sample pixel values from the uniform distribution U(0,1) to generate a relatively large global pattern τ, and then randomly crop a local area from the global pattern τ as the patch pattern To meet the adversarial requirements of a specific object detector (in this embodiment, the object detection model YOLOv3tiny pedestrian detection is used). The design of the global pattern τ is regarded as the complete structure of the adversarial texture, while the small patch patterns obtained by random cropping are used to simulate the local features in the actual usage scenario.
[0053] During the generation of adversarial patches, the patch patterns used are generated by randomly selecting a position from the global pattern τ and cropping a region of a fixed size. This process can be expressed by the following formula:
[0054]
[0055] where τ is the global pattern, is the patch pattern, and Crop rand (·) is the random cropping operation, which can generate diverse patch patterns within the global pattern.
[0056] Step 1.2. On this basis, the attack objective function (the loss function obtained by attacking a specific object detection model) can be expressed as:
[0057]
[0058] where L obj represents the attack objective function, represents the expectation with respect to I, M, f(·) represents the function for measuring the object detection model, M(·) represents the rendering function, I represents the clean image, and Step 1.2 iteratively optimizes the patch pattern through the loss function.
[0059] Step 2. Achieve the seamless generation of the patch pattern through the toroidal cropping operation. Use the toroidal cropping method to connect the boundaries of the global pattern to ensure the continuity when the cropped area crosses the boundary. The specific steps are as follows:
[0060] Step 2.1. Regard the global pattern τ as a two-dimensional torus, that is, assume that the upper and lower boundaries and the left and right boundaries of the pattern are connected to each other, so as to achieve seamless circular cropping. Each time the patch pattern cropped from the global pattern τ is generated by the toroidal cropping operation, as Figure 3 shown. During the optimization process, the objective function of the adversarial patch is defined as:
[0061]
[0062] where L adv represents the adversarial loss, denote expectation, f(·) denote the function for measuring the object detection model, M(·) denote the rendering function, I denote the clean image, Crop toro (·) denote the cropping function, τ local denote the input pattern.
[0063] Step 2.2. Input the pattern τ local (In the circular cropping, the patch pattern is obtained by local pattern completion) is set to be of size H×W, where H denotes the height of the image and W denotes the width of the image. The implementation process of the circular cropping can be divided into the following steps:
[0064] First, randomly select a starting point (i, j) in the global pattern τ, where i ∈ [0, H - 1] and j ∈ [0, W - 1]. This point serves as the upper left corner of the cropping window, determining the initial position of the cropping.
[0065] Then, according to the starting position and the size of the cropping area, extract the patch pattern from the global pattern τ The calculation of each pixel value in the patch is given by the following formula:
[0066]
[0067] where (u, v) denote the relative coordinates within the patch pattern, and (i + u) mod H and (j + v) mod W perform modulo operations on the indices in the vertical and horizontal directions respectively to achieve circular cropping. In this way, no matter where the cropping window is located, it can ensure that the cropped patch is continuous at the boundary, avoiding problems such as sudden changes or breaks in pixel values. This property of circular cropping ensures the seamless nature of the cropping area, making the generated patch pattern have higher spatial consistency.
[0068] Step 3. Optimize the patch pattern by combining the objective function and the total variation loss with the aim of maximizing the adversarial effect by adjusting the content of the patch pattern, which specifically includes the following steps:
[0069] Step 3.1. When the cropping window exceeds the boundary of the pattern, the exceeding part continues to obtain pixel values from the other side of the pattern, thus ensuring that the cropped patch pattern is seamlessly connected throughout the area. During the optimization process, first optimize the patch pattern obj by attacking the objective function L with the aim of maximizing the adversarial effect.
[0070] Step 3.2. To enhance the patch pattern During the optimization process, to generate smoothness and detail retention of the texture, the total variation loss (TV Loss) is introduced, and its formula is as follows:
[0071]
[0072] In the formula, L tv represents the total variation loss, τ i,j represents the pixel coordinates (i, j), τ i+1,j represents the pixel coordinates (i + 1, j), τ i,j+1 represents the pixel coordinates (i, j + 1), τ i,j −τ i,j+1 represents the pixel difference;
[0073] Then the total loss function can be written as:
[0074] L = L obj + αL tv
[0075] In the formula, L represents the total loss function, and α represents the hyperparameter.
[0076] Step 4: Divide the true physical deformation of the patch pattern into two steps, the out-of-plane bending of the patch pattern and the pitch rotation of the patch pattern. By mapping each point of the patch pattern from a two-dimensional plane to a parabolic cylinder in three-dimensional space, the local bending and angular changes of the patch pattern can be restored more precisely, generating an adversarial patch. Input the generated adversarial patch into the corresponding target detector, calculate the corresponding loss function based on the detection result, and continuously adjust the adversarial patch through iterative optimization to obtain an adversarial patch that maximizes the adversarial attack effect. Specifically, it includes the following steps:
[0077] Step 4.1: In the generation of the adversarial patch, EOT (Expectation Over Transformation) makes the generated adversarial patch still maintain the attack effect after undergoing a series of random transformations (such as rotation, scaling, translation, and brightness adjustment, etc.). During the optimization process, a set of transformation parameters is randomly sampled in each iteration. The adversarial patch is transformed and then superimposed on the target image, and after non-planar transformation, it is input into the detector to calculate the loss function.
[0078] Step 4.2: Divide the transformation that occurs when rendering the patch pattern to the target image into two steps: the out-of-plane bending of the patch pattern and the pitch rotation of the patch pattern. The formula is as follows:
[0079]
[0080] Wherein, x' represents the new coordinate value after transformation, a represents the hyperparameter, x represents the initial coordinate value, and ln(·) represents the natural logarithm function. Through out-of-plane bending and pitching rotation, physical deformation can be better simulated.
[0081] Figure 4 This conversion is illustrated by simulating the conversion of a non-planar sticker (patch pattern) as a parabolic transformation in 3D space. When dealing with complex three-dimensional surfaces, the existing EOT has the limitation that it cannot accurately simulate the geometric deformation of an object. EOT only relies on the random transformation of planar texture mapping and is difficult to effectively capture the out-of-plane bending and local angular changes of the sticker on the surface. In step 4.2 of this embodiment, a non-planar sticker conversion method is adopted, which can more accurately simulate the geometric deformation of the sticker (patch pattern) on the three-dimensional surface.
[0082] In step 4.3, generate an adversarial patch that can be used to attack the corresponding target detector YOLOv3tiny in step 4.2, assist the YOLOv3tiny detector to detect it, calculate the corresponding loss function based on the detection result, then calculate the gradient of the loss function with respect to the patch pixel value through backpropagation, and use the Adam optimizer to update the gradient of the patch pattern, so as to gradually adjust the patch parameters to enhance the attack effect. Stop when the preset maximum number of iterations is reached, and output the final adversarial patch. By iteratively optimizing and continuously adjusting the adversarial patch, an adversarial patch that can maximize the adversarial attack effect and fit the detection characteristics of the YOLOv3tiny detector is obtained.
[0083] In the experiment in the digital world, the INRIA dataset was used to analyze the attack effect of these adversarial textures in the digital environment by evaluating their impact on the target detection model.
[0084] In the experiment, adversarial textures were created for multiple object detection models and their attack effects were evaluated. Evaluation metrics: In the experiment, to evaluate the impact of adversarial patches on the performance of object detection models, the standard evaluation metric in the field of object detection, Mean Average Precision (mAP), was adopted. mAP combines the precision and recall of the model at different detection thresholds and is an important indicator for measuring the overall performance of object detection tasks. These baseline models include YOLOv2, YOLOv3, Faster RCNN, and YOLOv4tiny, which are representative algorithms widely used in the current field of object detection. These detectors were all pre-trained on the MS COCO dataset in advance. During the optimization process, the Adam optimizer was selected for parameter optimization. Its learning rate was set to 0.001, and the β1 and β2 parameters were set to 0.9 and 0.999 respectively, which were used to control the exponential weighted average of the first and second moment estimates. To avoid numerical instability, the correction term ε used the default value of 1e-8.
[0085] To comprehensively evaluate the generation methods of adversarial textures, a variety of comparison methods were designed, including RCA, Toroidal Cropping Attack (TCA) (the method of this embodiment), AdvPatch, and AdvTshirt. Among them, the RCA method generated a large pattern with an initial pixel size of 300×300 and randomly cropped 150×150 patches for training during the optimization process. The TCA method generated an initial pattern of the same size of 300×300 and cropped out a 150×150 local pattern for optimization through the toroidal cropping technique. The AdvPatch and AdvTshirt methods adopted different processing methods and generated adversarial textures with repeating patterns through tiling processing.
[0086] Table 1. Results of Comparative Experiments
[0087]
[0088]
[0089] The TCA of this embodiment uses the circular cropping technique to ensure the continuity and geometric structure of the adversarial pattern during the optimization process. This method effectively avoids the loss of key pixel points, making the generated adversarial texture more robust from different perspectives. The attack effect of TCA on YOLOv2 reaches 55.4%, which is the best among AdvPatchFlat, UPCFlat, and RCA. On the YOLOv3 model, the mAP of TCA is 60.83%, lower than 76.24% of AdvPatchFlat, 84.69% of UPCFlat, and 72.45% of RCA. For the fasterRCNN model, the mAP of TCA is 69.49%, lower than 77.25% of AdvPatchFlat, 88.23% of UPCFlat, and 77.48% of RCA. While maintaining the texture continuity, TCA can achieve a relatively efficient attack effect. The experimental results further confirm that TCA can effectively generate adversarial patches under multi-perspective conditions in the digital environment. The experimental data show that TCA can provide a more efficient attack effect while maintaining the texture continuity, and the experimental results further verify that TCA can effectively generate adversarial patches under multi-perspective conditions in the digital environment.
Claims
1. A method for generating adversarial patches for multi-view detection based on ring cropping, characterized in that: The following steps are involved: Step 1: Randomly select a cropping window from the global pattern, which determines the initial position of the patch pattern; Step 2: A seamless generation of the patch pattern is achieved through a circular cropping operation, and the pattern boundary is connected using the circular cropping method to ensure that the cropping area maintains continuity when crossing the boundary; Step 3: Optimize the patch pattern by combining the objective function with the total variation loss, aiming to maximize the adversarial effect by adjusting the content of the patch pattern; Step 4: Divide the real physical deformation of the patch pattern into two steps: the off-plane bending of the patch pattern and the pitch rotation of the patch pattern. By mapping each point of the patch pattern from a two-dimensional plane to a parabola in three-dimensional space, the local bending and angle change of the patch pattern are restored to generate an adversarial patch. The generated adversarial patch is input into the corresponding target detector, and the corresponding loss function is calculated based on the detection result. The adversarial patch is continuously adjusted through iterative optimization to obtain an adversarial patch that maximizes the adversarial attack effect.
2. The method for generating adversarial patches for multi-view detection based on circular cropping according to claim 1, characterized in that: The step 1 comprises the following steps: Step 1.1: Generate a global pattern τ, and then randomly cut out local areas from the global pattern τ as patch patterns. To meet the adversarial requirements of target detectors; The patch pattern used in the process of generating adversarial patches It is generated by randomly selecting a position from the global pattern τ and cropping a fixed-size region, which can be expressed as follows: Where τ is the global pattern, For patch patterns, Crop rand (·) is a random cropping operation that can generate diverse local patches within the global pattern; Step 1.2: On this basis, the attack target function can be expressed as: Among them, L obj represents the attack target function, represents the expectation about I,M, f(·) represents the function of measuring the target detection model, M(·) represents the rendering function, and I represents the clean image.
3. The method for generating adversarial patches for multi-view detection based on circular cropping according to claim 2, characterized in that: The step 2 comprises the following steps: Step 2.1: Consider the global pattern τ as a two-dimensional torus, that is, assume that the upper and lower boundaries and the left and right boundaries of the pattern are interconnected, so as to achieve seamless cyclic cutting. Each time the patch pattern cut from the global pattern τ is generated by a ring cropping operation, and the objective function of the adversarial patch is defined as: Among them, L adv Represents resistance to loss, represents the expectation, f(·) represents the function of measuring the target detection model, M(·) represents the rendering function, I represents the clean image, and Crop toro (·) represents the clipping function, τ local Represents the input pattern; Step 2.2: Input pattern τ local The size is set to H×W, H represents the height of the image, W represents the width of the image, and the implementation process of circular cropping can be divided into the following steps: First, a starting point (i, j) is randomly selected in the global pattern τ, where i∈[0,H-1] and j∈[0,W-1]. This point is used as the upper left corner of the cropping window to determine the initial position of the cropping. Next, extract the patch pattern from the pattern based on the starting position and the size of the cropped area Patch pattern The calculation of each pixel value in is given by the following formula: Among them, (u, v) represents the relative coordinates within the patch pattern, (i+u)modH and (j+v)modW perform modulo operations on the indexes in the vertical and horizontal directions respectively to achieve circular cropping.
4. The method for generating adversarial patches for multi-view detection based on circular cropping according to claim 1, characterized in that: The step 3 specifically comprises the following steps: Step 3.1: When the cropping window exceeds the boundary of the global pattern τ, the exceeding part will continue to obtain pixel values from the other side of the global pattern τ, thereby ensuring that the cropped patch pattern The whole area is seamlessly connected. During the optimization process, the objective function L obj Patch pattern Optimize to maximize the adversarial effect; Step 3.2: In order to enhance the smoothness and detail retention of the generated texture during the optimization process, the total variation loss is introduced, and its formula is as follows: Where, L tv represents the total variation loss, τ i,j represents the pixel coordinate (i, j), τ i+1,j represents the pixel coordinate (i+1,j), τ i,j+1 represents the pixel coordinate (i, j+1), τ i,j -τ i,j+1 Represents pixel difference; Then the total loss function can be written as: L=L obj +αL tv Where L represents the total loss function and α represents the hyperparameter.
5. The method for generating adversarial patches for multi-view detection based on circular cropping according to claim 1, characterized in that: The step 4 specifically comprises the following steps: Step 4.1, in the generation of adversarial patches, EOT predefines a series of spatial transformations so that the generated adversarial patches can still maintain the attack effect after undergoing these transformations, and the series of spatial transformations include rotation, scaling, translation and brightness adjustment; Step 4.2: The transformation that occurs when rendering the patch pattern to the target image is divided into two steps: the off-plane bending of the patch pattern and the pitch rotation of the patch pattern. The formula is as follows: In the formula, x ′ represents the new coordinate value after transformation, a represents the hyperparameter, x represents the initial coordinate value, and ln(·) represents the natural logarithm function; In step 4.3 and step 4.2, an adversarial patch that can be used to attack the corresponding target detector is generated. The target detector detects the adversarial patch and calculates the corresponding loss function based on the detection result. The adversarial patch is continuously adjusted through iterative optimization to obtain an adversarial patch that can maximize the adversarial attack effect and fit the characteristics of the target detector.