AdvLogo: Adversarial Patch Attack against Object Detectors based on Diffusion Models

📅 2024-09-11
🏛️ arXiv.org
📈 Citations: 1
Influential: 0
📄 PDF
🤖 AI Summary
To address the challenge of balancing attack efficacy and visual quality in adversarial patch attacks against object detectors, this paper proposes the first diffusion model-based, semantics-guided adversarial patch generation framework. Departing from the semantic subspace hypothesis, our method jointly perturbs the latent representation and unconditional embedding at the final denoising step. We further introduce Fourier-domain optimization to mitigate distribution shift and enhance perceptual naturalness. Evaluated on COCO and PASCAL VOC, our approach achieves over 85% black-box and gray-box attack success rates against mainstream detectors—including YOLOv5 and Faster R-CNN—while maintaining high visual fidelity: PSNR > 32 dB and LPIPS < 0.15. These results significantly outperform existing state-of-the-art methods, demonstrating superior trade-offs between attack effectiveness and imperceptibility.

Technology Category

Application Category

📝 Abstract
With the rapid development of deep learning, object detectors have demonstrated impressive performance; however, vulnerabilities still exist in certain scenarios. Current research exploring the vulnerabilities using adversarial patches often struggles to balance the trade-off between attack effectiveness and visual quality. To address this problem, we propose a novel framework of patch attack from semantic perspective, which we refer to as AdvLogo. Based on the hypothesis that every semantic space contains an adversarial subspace where images can cause detectors to fail in recognizing objects, we leverage the semantic understanding of the diffusion denoising process and drive the process to adversarial subareas by perturbing the latent and unconditional embeddings at the last timestep. To mitigate the distribution shift that exposes a negative impact on image quality, we apply perturbation to the latent in frequency domain with the Fourier Transform. Experimental results demonstrate that AdvLogo achieves strong attack performance while maintaining high visual quality.
Problem

Research questions and friction points this paper is trying to address.

Addresses vulnerabilities in object detectors using adversarial patches.
Balances attack effectiveness and visual quality in adversarial attacks.
Proposes AdvLogo framework leveraging semantic understanding for robust attacks.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Semantic-based adversarial patch attack framework
Diffusion models for adversarial subspace exploration
Frequency domain perturbation using Fourier Transform
🔎 Similar Papers
No similar papers found.
B
Boming Miao
Department of Statistics, Beijing Normal University
Chunxiao Li
Chunxiao Li
University of Science and Technology of China
User BehaviorFintechFinancial InclusionPlatform Economy
Y
Yao Zhu
Department of Automation, Tsinghua University
W
Weixiang Sun
Department of Mathematics, Northeastern University
Z
Zizhe Wang
Department of Automation, Tsinghua University
Xiaoyi Wang
Xiaoyi Wang
Beihang University
RoboticsSpace RobotNonlinear ControlOptimization
Chuanlong Xie
Chuanlong Xie
Beijing Normal University