Multi-target attention distraction adversarial attack method for aerial target detection

Through the multi-target distraction adversarial attack method, patches for different categories of targets are generated. The classification loss and distraction loss are combined to optimize the patch pixels, which solves the problems of low success rate of single-target attack and impact on detection of other categories in the existing technology, and achieves efficient multi-target attack and low detection bias.

CN120707981AInactive Publication Date: 2025-09-26CHINA SATELLITE MARITIME MEASUREMENT & CONTROL DEPT
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510594445.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-09-26
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing patch-level adversarial attack methods can often only attack one type of target, with a low attack success rate and affect the detection of other types of targets.

Method used

A multi-target distraction adversarial attack method is designed to generate adversarial samples by initializing multiple patches targeting different categories of targets, and then optimize the patch pixels to generate the final adversarial patch by combining classification loss and attention distraction loss.

Benefits of technology

A high success rate of multi-target attack is achieved, while reducing the detection bias of target categories without patches and improving the aggressiveness and category specificity of adversarial patches.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120707981A_ABST
    Figure CN120707981A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-target attention distraction adversarial attack method aiming at aerial target detection, which designs a multi-target patch generation model aiming at remote sensing detection, can generate a plurality of patches aiming at a multi-target category at one time, attacks each patch aiming at a corresponding category, and utilizes a multi-target adversarial patch training mode to realize multi-target adversarial attack. The training efficiency of the adversarial patch is improved; the classification loss and the attention distraction loss are combined, and the attack success rate of the anti-patch is improved by distraction of the model. Compared with other methods, the method has the advantages that the attack success rate is guaranteed, and meanwhile, the detection deviation of the target detector on the category target without the patch can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a multi-target distraction counterattack method for aerial target detection. Background Art

[0002] In recent years, object detection models based on deep neural networks have been a research hotspot in computer vision and have found widespread application in security. However, a growing body of research indicates that neural network-based object detectors are vulnerable to adversarial attacks, a vulnerability that also affects object detection in aerial imagery. By adding even small malicious perturbations to clean samples, deep neural network-based systems can make completely different predictions, potentially posing a serious threat in several security-critical areas. Therefore, the research on new adversarial attack methods provides a data foundation for improving the adversarial robustness of deep neural networks and offers insights into their vulnerability to adversarial examples.

[0003] Common adversarial attacks on target detection can be divided into pixel-level adversarial attacks and patch-level adversarial attacks based on the attack area. Pixel-level adversarial attacks mainly fine-tune the original image through attacks such as iterative gradient descent. The added noise is not specific to a single area, but spreads across the entire image. This attack method aims to preserve the appearance of the original image as much as possible, making the attack less noticeable. Patch-level adversarial attacks refer to adding patches to a region or a type of target in the original image. The patches in this region can affect the detection of the target detection model. These patches can be specific geometric shapes, textures, or colors and are carefully designed to confuse the model. Since patch-level adversarial attacks can be easily extended from the electronic domain to the physical domain, by printing the adversarial patches into stickers or patterns, an end-to-end attack can be achieved in the physical world. Therefore, patch-level adversarial attacks remain the mainstream attack method for adversarial attacks against target detection models.

[0004] Existing classic attack methods can only train one type of patch at a time. These adversarial patches are often universal patches, that is, they attack all categories, which often affects the detection of targets of other categories around them, and the attack success rate is not high. Summary of the Invention

[0005] The purpose of the present invention is to overcome the defects in the prior art and provide a multi-target anti-patch attack with a combined classification loss and attention distraction, which can reduce the detection bias of target detectors for category targets without patch patches while ensuring the success rate of the attack.

[0006] To achieve the above objectives, the present invention designs a multi-target distraction attack method for aerial target detection, the attack method comprising: S1. Initialize multiple patches for different categories of targets to obtain multiple initialized patches for different categories of targets; S2. Obtain the target position mask through patch conversion and perform patching to generate adversarial samples; S3. Input the two types of adversarial samples into the classifier of the detection model to extract the classification loss; S4, extract the model attention map and calculate the attention distraction loss; S5. Update the patch pixels through backpropagation of the total loss to obtain the final adversarial patch; There is no order for steps S3 and S4.

[0007] Furthermore, the method of obtaining multiple initialization patches for different categories of targets includes: According to the dataset category, randomly initialize n patches , where each patch is initialized as follows: in, is the initial patch of the model randomly initialized between 0 and 255, i=1, 2,…, n.

[0008] Furthermore, the target position mask is obtained through patch conversion and patching. The method of generating adversarial samples includes: S21, transform the initialized multi-patch PT(∙), and then pass an affine transformation matrix , generate the position mask corresponding to each patch and category serial number , in, is the training patch for category i, , is a set of patch categories, y is the label of each clean sample, and n patches constitute a set of n position masks ; is the Hadamard product, which is the multiplication of elements of corresponding positions of two vectors or matrices of the same dimension, and the result still maintains the same dimension. The transformation includes any combination of random rotation, contrast transformation or scale scaling, so that each transformed patch can be sized adaptively to the target object in the image; S22. Through the patch application module PA(∙), using the category sequence number and position mask, multiple patches are mapped to target objects of each category one by one, and the adversarial samples are obtained as follows: in, For the original clean image, the generated adversarial sample is based on the category sequence number There are two types of adversarial examples: Type 1 is to apply the corresponding patch to only one category of target objects in the clean image, and a set of adversarial samples can be obtained. : Type2 applies different patches to all categories of target objects in the clean image to obtain an adversarial sample. : In order to ensure the aggressiveness and category specificity of the adversarial patches, both types of adversarial samples are fed into the detection model for training.

[0009] Furthermore, the two types of adversarial samples are input into the classifier of the detection model to extract the classification loss. The specific method includes: For the two types of adversarial samples input, the category probability part of the model output result is taken as the multi-target category loss, and two types of classification losses are obtained respectively: in, is the category score confidence of the j-th target of category i, The confidence score for the category of the j-th target, is the category label corresponding to the patch, s is the number of target objects corresponding to each category, S is the total number of targets in an image, s∈S; for type 1 adversarial samples, we only reduce the category probability of the patch corresponding to the category, without paying attention to other categories, and take the average of the probabilities of the same category to obtain For type 2 adversarial samples, we reduce the category probabilities of all categories involved in the image, sum the two, and obtain the final multi-target category loss .

[0010] Furthermore, the attention module is used to extract the model attention map and calculate the attention loss. The specific methods include: S41, the adversarial sample generated in step S22 , put into the Grad-CAM generator of the target network In, use Extract the model's attention and obtain the model attention map AM: S42. Calculate attention loss using model attention map , the attention distraction loss function is as follows: in, is the total pixel value greater than 0 after the extracted model attention map passes through the ReLU activation function, is the area of ​​the detection box, is the area of ​​the patch. The present invention uses the model attention map to calculate the attention distraction loss, which can reduce the network's attention to the adversarial sample and divert the target's attention. Since the adversarial patch is mainly attached to the center area of ​​the target object, the denominator in the formula is the target area excluding the patch. By minimizing , optimize the adversarial patch so that The total pixel value of the salient area is kept as low as possible, while the attention of the non-patch area is increased to distract the aerial detection model from the center of the target.

[0011] Furthermore, the patch pixels are updated through back propagation of the total loss to obtain the final adversarial patch. The specific method includes: S51. Combining the classification loss and the attention distraction loss, the total loss function is as follows: in, is a hyperparameter, is the total variation loss, which optimizes the adversarial patch into a smooth transition image. It can be expressed as: in, For location Adversarial patches at Pixel value, reduce The value of will make the adversarial patch smoother; S52. Minimize the total loss function: By calculating the gradient of the loss and back-propagating it, the adversarial patch is optimized and updated to obtain the final adversarial patch; is a single multi-target adversarial example, is a set of single-target adversarial examples.

[0012] Furthermore, the adversarial patch is located in the central area of ​​the target object.

[0013] Furthermore, the evaluation indicators of the anti-attack method include successful attack rate and other category detection accuracy; The successful attack rate (ASR) includes the ratio of the target object with the patch to be misdetected or missed by the target detection model; The other category detection accuracy OCAP includes the ratio of target objects without patches correctly detected by the target detection model.

[0014] Furthermore, the method for calculating the success attack rate includes: in, For all categories from the DOTA dataset Several categories were manually selected, namely , For category The number of missed targets, that is, how many targets are ignored by the detector (Miss), For category The number of misdetected targets, that is, how many targets are misclassified by the detector (Wrong), For category The number of all targets.

[0015] Furthermore, the calculation method of the other category detection accuracy OCAP includes: in, For all categories of the DOTA dataset There are several categories that are not selected for patching, namely , For category The number of correctly detected targets in For category The number of all targets.

[0016] The advantages and beneficial effects of the present invention are: (1) The present invention designs a multi-target patch generation model for remote sensing detection. It can generate multiple patches for multiple target categories at one time. Each patch attacks only its corresponding category. Multi-patch training can reduce the detection bias of target categories without patches after adding patches.

[0017] (2) This paper proposes a new loss function that combines category loss and model attention to reduce the attention area while improving the non-attention area. The multi-patch joint attack can achieve a high attack success rate of more than 96%.

[0018] (3) This paper designs a new OCAP metric to measure the attack effect of multi-target adversarial patches and their impact on the detection of other categories of targets. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 This is a brief flow chart of the multi-target distraction attack countermeasure method for aerial target detection according to the present invention; Figure 2 This is a detailed flow chart of the multi-target distraction attack countermeasure method for aerial target detection according to the present invention; Figure 3 It is a principle block diagram of a multi-target distraction countermeasure attack system for aerial target detection. DETAILED DESCRIPTION

[0020] The following embodiments are further described in conjunction with the accompanying drawings and examples. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention.

[0021] Example 1: The present invention is a multi-target distraction attack countermeasure method for aerial target detection, such as Figure 1 and Figure 2 As shown, the anti-attack method includes: S1. Initialize multiple patches for different categories of targets to obtain multiple initialized patches for different categories of targets; S2. Obtain the target position mask through patch conversion and perform patching to generate adversarial samples; S3. Input the two types of adversarial samples into the classifier of the detection model to extract the classification loss; S4. Extract the model attention map through the attention module and calculate the attention distraction loss; S5. Update the patch pixels through backpropagation of the total loss to obtain the final adversarial patch; There is no order for steps S3 and S4.

[0022] The present invention designs a multi-target patch generation model for remote sensing detection models. Multiple patches can be generated for multiple target categories at one time. Each patch attacks only its corresponding category. Multi-patch training can reduce the detection bias of target categories without patches after adding patches. At the same time, a new loss function is designed to reduce the attention area and increase the non-attention area through category loss and model attention distraction loss. The combined multi-target patch attack can achieve a higher attack success rate.

[0023] like Figure 3 As shown, this embodiment completes the implementation and testing of the method by constructing a multi-target adversarial attack system based on the attention mechanism. The system includes an initialization module, a patch transformation module, and a multi-target patch application module electrically connected in sequence, as well as an attention module and a loss function module. The attention module and the loss function module are electrically connected to the total loss calculation module. Figure 3A remote sensing detection module is also designed. It can be an actual remote sensing detection device or a computer simulation module. Although it is not a required module of the system of the present invention, it is necessary to complete the performance test to achieve a complete test. The main test process of the system is to randomly initialize patches on the original clean image and transform the patches. The multi-target patch application module analyzes the corresponding remote sensing detection signal characteristics, calculates the attention loss through the attention module, extracts the classification loss through the loss function calculation module, and finally calculates the total loss.

[0024] Preferably, the method for obtaining multiple initialization patches for different categories of targets includes: According to the dataset category, randomly initialize n patches , where each patch is initialized as follows: in, is the initial patch of the model randomly initialized between 0 and 255, i=1, 2,…, n.

[0025] Preferably, the method of obtaining the target position mask by patch conversion and patching to generate the adversarial sample includes: S21, transform the initialized multi-patch PT(∙), and then pass it through an affine transformation matrix , generate the position mask corresponding to each patch and category serial number ; Note that the previous random rotation, contrast transformation or scale scaling is to enhance the data of the patch, and the subsequent affine transformation is used to correspond the patch to the target in the clean image one by one; in, is the training patch for category i, , is a set of patch categories, y is the label of each clean sample, such as the category and coordinates of each target in the image, and n patches constitute a set of n position masks ;symbol is the Hadamard product, that is, the elements of two vectors or matrices of the same dimension are multiplied at corresponding positions, and the result still maintains the same dimension; for the consistency of symbols, this embodiment ( ) The result after PT(∙) conversion is still expressed as ( ), which uses the assignment expression used in computer programs. The transformation includes any combination of random rotation, contrast transformation, or scaling, so that each transformed patch can be sized adaptively to the target object in the image. This embodiment uses both random rotation and scaling, depending on the relative position and size of the patch and the target image.

[0026] S22. Through the patch application module PA(∙), using the category sequence number and position mask, multiple patches are mapped to target objects of each category one by one, and the adversarial samples are obtained as follows: in, is the original clean image, which is the input image data. In this embodiment, the code performs basic image processing on the 1024X1024 3-channel RGB image, and the generated adversarial samples are based on the category sequence number. There are two types of adversarial examples: Type 1 is to apply the corresponding patch to only one category of target objects in the clean image, and a set of adversarial samples can be obtained. : Type2 applies different patches to all categories of target objects in the clean image to obtain an adversarial sample. : In order to ensure the aggressiveness and category specificity of the adversarial patches, both types of adversarial samples are fed into the detection model for training.

[0027] Preferably, the two types of adversarial samples are input into the classifier of the detection model to extract the classification loss. The specific method includes: For the two types of adversarial samples input, the category probability part of the model output result is taken as the multi-target category loss, and two types of classification losses are obtained respectively: in, is the category score confidence of the j-th target of category i, The confidence score for the category of the j-th target, is the category label corresponding to the patch, s is the number of target objects corresponding to each category, S is the total number of targets in an image, s∈S; for type 1 adversarial samples, we only reduce the category probability of the patch corresponding to the category, without paying attention to other categories, and take the average of the probabilities of the same category to obtain For type 2 adversarial samples, we reduce the category probabilities of all categories involved in the image, sum the two, and obtain the final multi-target category loss .

[0028] Preferably, this embodiment extracts the model attention map through the attention module and calculates the attention distraction loss. The specific method includes: S41, the adversarial sample generated in step S22 , put into the Grad-CAM generator of the target network (For details, please refer to [1] Selvaraju, RR, Cogswell, M., Das, A., Vedantam, R., Parikh, D., Batra, D., 2017. Grad–CAM: visual explanations from deep networks via gradient-based localization. In: IEEE International Conference on Computer Vision, ICCV 2017, Venice, Italy, October 22–29, 2017. IEEE ComputerSociety, pp. 618–626, or [2]Wang, J., Liu, A., Yin, Z., Liu, S., Tang,S., Liu, VisionFoundation / IEEE, pp. 8565–8574), using Extract the model's attention and obtain the model attention map AM: S42. Calculate attention loss using model attention map , the attention distraction loss function is as follows: in, is the total pixel value greater than 0 after the extracted model attention map passes through the ReLU activation function, is the area of ​​the detection box, is the area of ​​the patch area. The ReLU function is an activation function that sets the part of the neuron input value that is less than zero to zero and retains the part that is greater than zero, thereby introducing nonlinearity, alleviating the gradient vanishing problem and accelerating the training of the neural network. The present invention uses the model attention map to calculate the attention distraction loss to reduce the network's attention to the adversarial sample and divert the target's attention; and since the adversarial patch is mainly concentrated in the central area of ​​the target object, the denominator in the formula is the target area excluding the patch. By minimizing , optimize the adversarial patch so that The total pixel value of the salient area is kept as low as possible, while the attention of the non-patch area is increased to distract the aerial detection model from the center of the target.

[0029] Preferably, the patch pixels are updated by backpropagation of the total loss to obtain the final adversarial patch. The specific method includes: S51. Combining the classification loss and the attention distraction loss, the total loss function is as follows: in, is a hyperparameter, is the total variation loss, which optimizes the adversarial patch into a smooth transition image. It can be expressed as: in, For location Adversarial patches at Pixel value, reduce The value of will make the adversarial patch smoother; S52. Minimize the total loss function: By calculating the gradient of the loss and back-propagating it, the adversarial patch is optimized and updated to obtain the final adversarial patch; is a multi-target adversarial example, is a set of single-target adversarial examples. Backpropagation is an algorithm in a neural network that uses the chain rule to calculate the gradient of the loss function with respect to model parameters and optimizes the parameters using gradient descent. Simply put, it calculates the gradient and updates the parameters to optimize the patch pixels for optimal attack effectiveness. This is a common method in deep learning and machine learning. This example uses the Adam optimization algorithm, which is also a common (and default) optimization method for adversarial patch training.

[0030] It should be noted that the adversarial patch of the present invention is a patch that requires training and optimization; the adversarial sample is an image sample obtained by attaching the patch to a clean image (a combination of the original image + the adversarial patch). The ultimate goal of the present invention is to obtain an aggressive adversarial patch.

[0031] Preferably, the adversarial patch is located in the central area of ​​the target object.

[0032] Preferably, the evaluation indicators of the anti-attack method include successful attack rate and other category detection accuracy; The successful attack rate (ASR) includes the ratio of the target object with the patch to be misdetected or missed by the target detection model; The other category detection accuracy OCAP includes the ratio of target objects without patches correctly detected by the target detection model.

[0033] Preferably, the method for calculating the successful attack rate includes: in, For all categories from the DOTA dataset Several categories were manually selected, namely , For category The number of missed targets, that is, how many targets are ignored by the detector (Miss), For category The number of misdetected targets, that is, how many targets are misclassified by the detector (Wrong), For category The number of all targets.

[0034] Preferably, in order to quantitatively analyze the impact of patched objects on unpatched objects during detection, that is, to evaluate the category specificity of the adversarial patches we generated, we designed a special evaluation metric for remote sensing detection models based on the Average Precision (AP): Other Category Detection Accuracy (OCAP). For unpatched objects, the calculation method of the Other Category Detection Accuracy (OCAP) includes the following: in, For all categories of the DOTA dataset There are several categories that are not selected for patching, namely , For category The number of correctly detected targets in For category The number of all targets.

[0035] The general calculation method of average precision AP is as follows: in, For category The number of correctly detected targets in For category The number of all targets.

[0036] In this embodiment, the DOTA dataset is selected as training data, which contains 15 common target categories such as airplanes, cars, ships, and ports, and the NWPUVHR-10 dataset and part of the DOTA dataset are selected as test data to verify the effectiveness of the present invention on cross-datasets; YOLOv3 is selected as the white-box attack model for training, and YOLOv2, Faster R-CNN, and Swin Transformer are selected as black-box attack models; and in subsequent embodiments, the method of the present invention is compared with the baseline method of Du et al. and the universal patch generated by the BA-AP method (see reference [3] Du A, Chen B, Chin TJ, et al. Physical adversarial attacks on an aerial imagery object detector [C] / / Proceedings of the IEEE / CVF Winter Conference on Applications of Computer Vision. 2022: 1796-1806, and reference [4] Lian J, Mei S, Zhang S, et al. Benchmarking adversarial patch against aerial detection [J]. IEEE Transactions on Geoscience and Remote Sensing, 2022, 60: 1-16.).

[0037] To facilitate the experimental results, this example selects airplanes, cars, and trucks in the DOTA dataset as multi-category attack targets, and simultaneously generates three adversarial patches for these three categories. Each different patch is tested on yolov3, and the detection results are shown in the following table: Table 1 Attack effect of each patch on the DOTA dataset Table 1 shows that, with the exception of the first patch (patch_0), the attack success rate for each of the other patches exceeded 90%, and the success rate for all three patches simultaneously reached 99%. The low ASR for the first patch may be due to the smaller size of small vehicles compared to large vehicles and aircraft, resulting in patch_0 losing more high-frequency information when scaled down. Since the final loss function is a fusion of multiple objective functions, the Adam optimizer tends to favor an objective that is easily detected, resulting in less pixel optimization for the first patch than for the following two. However, patch_0 has the highest OCAP, reflecting the high detection accuracy of the initially trained YOLOv3 model. While the ASR for the following two patches is excellent, the OCAP for other categories has declined to a certain extent. This suggests that the patches used in our method may still have some impact on the detection of other categories. However, comparing patch_1 and patch_2, patch_2 has higher ASR and OCAP than patch_1. This suggests that patch_2 has a reduced impact on the detection of unpatched objects of other categories.

[0038] Example 2: To verify the experimental effect of the method of the present invention on cross-models, this example compares the method of the present invention with randomly generated patches, a baseline method, and a BA-AP method. These methods are all trained on YOLOv3 and tested on different detection models. The results are shown in Tables 2 and 3.

[0039] Table 2 ASR and OCAP of different methods on different detection models Table 3 AP of different methods on different detection models Method Yolov2 Yolov3 Faster-RCNN Swin-t Random 0.8950 0.8273 0.9033 0.8901 Baseline

[29] 0.3247 0.5023 0.6550 0.8526 BA-AP

[30] 0.0633 0.5924 0.3535 0.8278 Ours 0.0032 0.3226 0.3367 0.8209 As can be seen from Tables 2 and 3, the attack method of the present invention outperforms other methods in terms of ASR, AP, and OCAP. The attack success rate of the present method exceeds 96% on the RCNN-based detection model, although it performs poorly on the Swin-t model. At the same time, compared with the baseline method, the present method effectively improves the detection accuracy of other categories of unpatched objects on the RCNN-based detection model. This also shows that the present method can reduce the impact of patched objects on the detection accuracy of other unpatched categories to a certain extent.

[0040] Example 3: To validate the effectiveness of our method for multi-target patches trained on other datasets, we tested it on the NWPUVHR-10 dataset. Since NWPUVHR-10 lacks large and small vehicle classifications in DOTA, we chose aircraft, ships, and storage tanks as targets. Three patches were retrained. Furthermore, patches were selected from the optimization process for every 100 epochs (0, 100, 200, 300, 400, 500, and 600) for testing.

[0041] Table 4 Comparative attack effects of multiple patches on different datasets As shown in Table 4, the patches in this invention converged quickly during optimization, achieving a high attack success rate after 400-500 rounds of training. This is primarily because the class loss function in this method uses the average class probability of all detected objects, rather than simply the maximum objective score. This not only ensures the attack performance of this method but also improves the optimization efficiency of the adversarial patch. Furthermore, this method can maintain a high attack success rate on other datasets.

[0042] Example 4: This example performs ablation experiments on the YoLoV3 detection model to demonstrate the effectiveness of the method. The experiment uses the traditional classification loss, the classification loss proposed in this invention, the attention loss proposed in this invention, and the objective function used in this invention as loss functions, training one patch at a time. Comparative experiments are performed, and the experimental results are shown in the table.

[0043] Table 5 Loss function ablation experiment As shown in Table 5, compared with the class loss function in the baseline method, the class loss function of the present invention greatly improves the attack performance of the patch. At the same time, the attention loss also plays a certain role in improving the aggressiveness of the patch. Compared with the baseline method Combined with the class loss of the present invention Combination has a higher attack success rate.

[0044] To compare with traditional methods, this example follows the settings in Thys et al. ("Fooling Automated Surveillance Cameras: Adversarial Patches to Attack Person Detection" in Proc. IEEE / CVF Conf. Comput. Vis. Pattern Recognit. Workshops (CVPRW), Jun. 2019, pp. 49–55). α was set to 2.5 to balance the three components of the objective loss. Furthermore, the maximum number of epochs was set to 600. Experiments were conducted on a PyTorch platform using an NVIDIA GeForce RTX3090 graphics processing unit.

[0045] Example 5: The difference from Example 1 is that in this embodiment, the multi-patch transformation PT(∙) only uses the rotation transformation method, mainly considering that the size and proportion of the patch are consistent with the target image.

[0046] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A multi-target distraction attack method for aerial target detection, characterized by: The anti-attack method includes: S1, initialize multiple patches for different categories of targets; S2. Obtain the target position mask through patch conversion and perform patching to generate adversarial samples; S3. Input the two types of adversarial samples into the classifier of the detection model to extract the classification loss; S4, extract the model attention map and calculate the attention distraction loss; S5. Update the patch pixels through backpropagation of the total loss to obtain the final adversarial patch; There is no order for steps S3 and S4.

2. The multi-target distraction attack countermeasure method for aerial target detection according to claim 1 is characterized in that: Methods for obtaining multiple initialization patches for different categories of targets include: According to the dataset category, randomly initialize n patches , where each patch is initialized as follows: in, is the initial patch of the model randomly initialized between 0 and 255, i=1, 2,…, n.

3. The multi-target distraction attack method for aerial target detection according to claim 1 is characterized in that: The method of obtaining the target position mask and patching it through patch conversion to generate adversarial samples includes: S21, transform the initialized multi-patch PT(∙), and then pass the affine transformation matrix , generate the position mask corresponding to each patch and category serial number , in, is the training patch for category i, , is a set of patch categories, y is the label of each clean sample, and n patches constitute a set of n position masks ;symbol is the Hadamard product, and the transformation includes any combination of random rotation, contrast transformation or scale scaling; S22. Through the patch application module PA(∙), using the category sequence number and position mask, multiple patches are mapped to target objects of each category one by one, and the adversarial samples are obtained as follows: in, For the original clean image information, the generated adversarial sample is based on the category sequence number There are two types of adversarial examples: Type 1 is to apply the corresponding patch to only one category of target objects in the clean image, and a set of adversarial samples can be obtained. : Type2 applies different patches to all categories of target objects in the clean image to obtain an adversarial sample. : Both types of adversarial examples are fed into the detection model for training.

4. The multi-target distraction attack countermeasure method for aerial target detection according to claim 1 is characterized in that: Input two types of adversarial samples into the classifier of the detection model to extract the classification loss. The specific method includes: For the two types of adversarial samples input, the category probability part of the model output result is taken as the multi-target category loss, and two types of classification losses are obtained respectively: in, Set the category score of the j-th target in category i, and the confidence is the confidence score of the category of the j-th target, is the category label corresponding to the patch, s is the number of target objects corresponding to each category, S is the total number of targets in an image, s∈S, is the single target category loss, is the multi-target category loss.

5. The multi-target distraction attack countermeasure method for aerial target detection according to claim 1, characterized in that: Extract the model attention map and calculate the attention loss. The specific methods include: S41, the adversarial sample generated in step S22 , put into the Grad-CAM generator of the target network In, use Extract the model's attention and obtain the model attention map AM: S42. Calculate attention loss using model attention map , the attention distraction loss function is as follows: in, is the total pixel value greater than 0 after the extracted model attention map passes through the ReLU activation function, is the area of ​​the detection box, is the area of ​​the patch.

6. The multi-target distraction attack method for aerial target detection according to claim 1 is characterized in that: By backpropagating the total loss, the patch pixels are updated to obtain the final adversarial patch. The specific methods include: S51. Combining the classification loss and the attention distraction loss, the total loss function is as follows: in, is a hyperparameter, is the total variation loss, which optimizes the adversarial patch into a smooth transition image. Expressed as: in, For location Adversarial patches at Pixel value; S52. Minimize the total loss function: By calculating the gradient of the loss and back-propagating it, the adversarial patch is optimized and updated to obtain the final adversarial patch; is a single multi-target adversarial example, is a set of single-target adversarial examples.

7. The multi-target distraction attack countermeasure method for aerial target detection according to claim 1, characterized in that: The adversarial patch is located in the central area of ​​the target object.

8. The multi-target distraction attack countermeasure method for aerial target detection according to claim 1, characterized in that: Evaluation indicators of the anti-attack method include successful attack rate and other category detection accuracy; The successful attack rate (ASR) includes the ratio of the target object with the patch to be misdetected or missed by the target detection model; The other category detection accuracy OCAP includes the ratio of target objects without patches correctly detected by the target detection model.

9. The multi-target distraction attack countermeasure method for aerial target detection according to claim 8, characterized in that: The calculation method of the successful attack rate includes: in, For all categories from the DOTA dataset Several categories were manually selected, namely , For category The number of missed targets, that is, how many targets are ignored by the detector (Miss), For category The number of misdetected targets, that is, how many targets are misclassified by the detector (Wrong), For category The number of all targets.

10. The multi-target distraction attack countermeasure method for aerial target detection according to claim 8, characterized in that: The calculation method of the other category detection accuracy OCAP includes: in, For all categories of the DOTA dataset There are several categories that are not selected for patching, namely , For category The number of correctly detected targets in For category The number of all targets.

Citation Information

Cited By

  • Adversarial patch generation method and device based on feature fragmentation, equipment and storage medium

    CN122453954A