A Security Study of Multimodel Artificial Intelligence System: Adaptive Retention Attack for Object Detection System with Multifocus Image Fusion Model

IF 6.8 Q1 AUTOMATION & CONTROL SYSTEMS Advanced intelligent systems (Weinheim an der Bergstrasse, Germany) Pub Date : 2024-06-19 DOI:10.1002/aisy.202300771
Xueshuai Gao, Xin Jin, Shengfa Miao, Qian Jiang, Yunyun Dong, Wei Zhou, Shaowen Yao
{"title":"A Security Study of Multimodel Artificial Intelligence System: Adaptive Retention Attack for Object Detection System with Multifocus Image Fusion Model","authors":"Xueshuai Gao,&nbsp;Xin Jin,&nbsp;Shengfa Miao,&nbsp;Qian Jiang,&nbsp;Yunyun Dong,&nbsp;Wei Zhou,&nbsp;Shaowen Yao","doi":"10.1002/aisy.202300771","DOIUrl":null,"url":null,"abstract":"<p>Image preprocessing models are usually employed as the preceding operations of high-level vision tasks to improve the performance. The adversarial attack technology makes both these models face severe challenges. Prior research is focused solely on attacking single object detection models, without considering the impact of the preprocessing models (multifocus image fusion) on adversarial perturbations within the object detection system. Multifocus image fusion models work in conjunction with the object detection models to enhance the quality of the images and improve the capability of object detection system. Herein, the problem of attacking object detection system that utilizes multifocus image fusion as its preprocessing models is addressed. To retain the attack capabilities of adversarial samples against as many perturbations as possible, new attack method called adaptive retention attack (ARA) is proposed. Additionally, adversarial perturbations concentration mechanism and image selection mechanism, which, respectively, enhance the transferability and attack capability of ARA-generated adversarial samples. Extensive experiments have demonstrated the feasibility of the ARA. The results confirm that the ARA method can successfully bypass multifocus image fusion models to attack the object detection model.</p>","PeriodicalId":93858,"journal":{"name":"Advanced intelligent systems (Weinheim an der Bergstrasse, Germany)","volume":"6 7","pages":""},"PeriodicalIF":6.8000,"publicationDate":"2024-06-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/aisy.202300771","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Advanced intelligent systems (Weinheim an der Bergstrasse, Germany)","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/aisy.202300771","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"AUTOMATION & CONTROL SYSTEMS","Score":null,"Total":0}
引用次数: 0

Abstract

Image preprocessing models are usually employed as the preceding operations of high-level vision tasks to improve the performance. The adversarial attack technology makes both these models face severe challenges. Prior research is focused solely on attacking single object detection models, without considering the impact of the preprocessing models (multifocus image fusion) on adversarial perturbations within the object detection system. Multifocus image fusion models work in conjunction with the object detection models to enhance the quality of the images and improve the capability of object detection system. Herein, the problem of attacking object detection system that utilizes multifocus image fusion as its preprocessing models is addressed. To retain the attack capabilities of adversarial samples against as many perturbations as possible, new attack method called adaptive retention attack (ARA) is proposed. Additionally, adversarial perturbations concentration mechanism and image selection mechanism, which, respectively, enhance the transferability and attack capability of ARA-generated adversarial samples. Extensive experiments have demonstrated the feasibility of the ARA. The results confirm that the ARA method can successfully bypass multifocus image fusion models to attack the object detection model.

Abstract Image

查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
多模型人工智能系统的安全性研究:采用多焦点图像融合模型的物体检测系统的自适应保留攻击
图像预处理模型通常被用作高级视觉任务的前置操作,以提高性能。对抗攻击技术使这两种模型都面临严峻挑战。之前的研究只关注攻击单一物体检测模型,而没有考虑预处理模型(多焦点图像融合)对物体检测系统内对抗性扰动的影响。多焦图像融合模型与物体检测模型协同工作,可提高图像质量,改善物体检测系统的能力。在此,我们探讨了利用多焦点图像融合作为预处理模型的物体检测系统的攻击问题。为了尽可能多地保留对抗样本的攻击能力,本文提出了一种新的攻击方法,即自适应保留攻击(ARA)。此外,还提出了对抗扰动集中机制和图像选择机制,它们分别增强了 ARA 生成的对抗样本的可转移性和攻击能力。大量实验证明了 ARA 的可行性。实验结果证实,ARA方法可以成功绕过多焦点图像融合模型,攻击物体检测模型。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
CiteScore
1.30
自引率
0.00%
发文量
0
审稿时长
4 weeks
期刊最新文献
Masthead A Flexible, Architected Soft Robotic Actuator for Motorized Extensional Motion Design and Optimization of a Magnetic Field Generator for Magnetic Particle Imaging with Soft Magnetic Materials High-Performance Textile-Based Capacitive Strain Sensors via Enhanced Vapor Phase Polymerization of Pyrrole and Their Application to Machine Learning-Assisted Hand Gesture Recognition Optimized Magnetically Docked Ingestible Capsules for Non-Invasive Refilling of Implantable Devices
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1