Adversarial attack algorithm for traffic sign recognition - Publikacja - MOST Wiedzy

Wyszukiwarka

Adversarial attack algorithm for traffic sign recognition

Abstrakt

Deep learning suffers from the threat of adversarial attacks, and its defense methods have become a research hotspot. In all applications of deep learning, intelligent driving is an important and promising one, facing serious threat of adversarial attack in the meanwhile. To address the adversarial attack, this paper takes the traffic sign recognition as a typical object, for it is the core function of intelligent driving. Considering that the black box attack does not need to know the internal characteristics of the model, it can have more practical value. However, the existing black box attack algorithm has high visit time and low efficiency in attacking sample generation. In this regard, the SimBA algorithm with high efficiency is selected and improved according to the characteristics of traffic signs, named the L-SimBA algorithm. According to the graphic characteristics of traffic signs that are already known, L-SimBA algorithm limits the search subspace consciously and specifies the set of search directions, and that is the core idea of it. By this way, L-SimBA algorithm can generate adversarial samples faster. Experimental comparison shows that in the field of traffic sign recognition, L-SimBA algorithm is better than SimBA algorithm. On the premise of obtaining similar quality adversarial attack samples, the success rate of adversarial measures gets higher, and the number of model visits reduces considerably, thus the attack efficiency of the algorithm improves greatly

Cytowania

  • 2

    CrossRef

  • 0

    Web of Science

  • 3

    Scopus

Autorzy (5)

Cytuj jako

Pełna treść

pełna treść publikacji nie jest dostępna w portalu

Słowa kluczowe

Informacje szczegółowe

Kategoria:
Publikacja w czasopiśmie
Typ:
artykuły w czasopismach
Opublikowano w:
MULTIMEDIA TOOLS AND APPLICATIONS
ISSN: 1380-7501
Język:
angielski
Rok wydania:
2022
Opis bibliograficzny:
Wang J., Shi L., Zhao Y., Zhang H., Szczerbicki E.: Adversarial attack algorithm for traffic sign recognition// MULTIMEDIA TOOLS AND APPLICATIONS -, (2022),
DOI:
Cyfrowy identyfikator dokumentu elektronicznego (otwiera się w nowej karcie) 10.1007/s11042-022-14067-5
Źródła finansowania:
  • COST_FREE
Weryfikacja:
Politechnika Gdańska

wyświetlono 60 razy

Publikacje, które mogą cię zainteresować

Meta Tagi