University of Leicester
Browse

GLH: From Global to Local Gradient Attacks with High-frequency Momentum Guidance for Object Detection

Download (6.27 MB)
journal contribution
posted on 2023-04-14, 09:21 authored by Y Chen, H Yang, X Wang, Q Wang, Huiyu Zhou

 The adversarial attack is crucial to improving the robustness of deep learning models; they help improve the interpretability of deep learning and also increase the security of the models in real-world applications. However, existing attack algorithms mainly focus on image classification tasks, and they lack research targeting object detection. Adversarial attacks against image classification are global-based with no focus on the intrinsic features of the image. In other words, they generate perturbations that cover the whole image, and each added perturbation is quantitative and undifferentiated. In contrast, we propose a global-to-local adversarial attack based on object detection, which destroys important perceptual features of the object. More specifically, we differentially extract gradient features as a proportion of perturbation additions to generate adversarial samples, as the magnitude of the gradient is highly correlated with the model’s point of interest. In addition, we reduce unnecessary perturbations by dynamically suppressing excessive perturbations to generate high-quality adversarial samples. After that, we improve the effectiveness of the attack using the high-frequency feature gradient as a motivation to guide the next gradient attack. Numerous experiments and evaluations have demonstrated the effectiveness and superior performance of our from global to Local gradient attacks with high-frequency momentum guidance (GLH), which is more effective than previous attacks. Our generated adversarial samples also have excellent black-box attack ability. 

Funding

This research is supported in part by the National Natural Science Foundation (62202118, 62162008), and in part by Top Technology Talent Project from Guizhou Education Department (Qianjiao ji [2022]073) and Technology Projects (ZK[2022]-108), Innovation and Entrepreneurship Project for Overseas Educated Talents in Guizhou Province (2022)-04,Natural Science Special Research Fund of Guizhou University (No. 2021-24), Guizhou University Cultivation Project (No. 2021-55).

History

Citation

Chen, Y., Yang, H., Wang, X., Wang, Q. and Zhou, H., 2023. GLH: From Global to Local Gradient Attacks with High-Frequency Momentum Guidance for Object Detection. Entropy, 25(3), p.461.

Author affiliation

School of Informatics

Version

  • VoR (Version of Record)

Published in

Entropy

Volume

25

Issue

3

Pagination

461

Publisher

MDPI

issn

1099-4300

Acceptance date

2023-03-04

Copyright date

2023

Available date

2023-03-06

Language

en

Usage metrics

    University of Leicester Publications

    Categories

    No categories selected

    Licence

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC