Adversarial Patch Attack for Ship Detection via Localized Augmentation

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Liu, Chun, Ding, Panpan, Zheng, Zheng, Wang, Hailong, Zhu, Bingqian, Xu, Tao, Han, Zhigang, Wang, Jiayao
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918132590837760
author Liu, Chun
Ding, Panpan
Zheng, Zheng
Wang, Hailong
Zhu, Bingqian
Xu, Tao
Han, Zhigang
Wang, Jiayao
author_facet Liu, Chun
Ding, Panpan
Zheng, Zheng
Wang, Hailong
Zhu, Bingqian
Xu, Tao
Han, Zhigang
Wang, Jiayao
contents Current ship detection techniques based on remote sensing imagery primarily rely on the object detection capabilities of deep neural networks (DNNs). However, DNNs are vulnerable to adversarial patch attacks, which can lead to misclassification by the detection model or complete evasion of the targets. Numerous studies have demonstrated that data transformation-based methods can improve the transferability of adversarial examples. However, excessive augmentation of image backgrounds or irrelevant regions may introduce unnecessary interference, resulting in false detections of the object detection model. These errors are not caused by the adversarial patches themselves but rather by the over-augmentation of background and non-target areas. This paper proposes a localized augmentation method that applies augmentation only to the target regions, avoiding any influence on non-target areas. By reducing background interference, this approach enables the loss function to focus more directly on the impact of the adversarial patch on the detection model, thereby improving the attack success rate. Experiments conducted on the HRSC2016 dataset demonstrate that the proposed method effectively increases the success rate of adversarial patch attacks and enhances their transferability.
format Preprint
id arxiv_https___arxiv_org_abs_2508_21472
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarial Patch Attack for Ship Detection via Localized Augmentation
Liu, Chun
Ding, Panpan
Zheng, Zheng
Wang, Hailong
Zhu, Bingqian
Xu, Tao
Han, Zhigang
Wang, Jiayao
Computer Vision and Pattern Recognition
Current ship detection techniques based on remote sensing imagery primarily rely on the object detection capabilities of deep neural networks (DNNs). However, DNNs are vulnerable to adversarial patch attacks, which can lead to misclassification by the detection model or complete evasion of the targets. Numerous studies have demonstrated that data transformation-based methods can improve the transferability of adversarial examples. However, excessive augmentation of image backgrounds or irrelevant regions may introduce unnecessary interference, resulting in false detections of the object detection model. These errors are not caused by the adversarial patches themselves but rather by the over-augmentation of background and non-target areas. This paper proposes a localized augmentation method that applies augmentation only to the target regions, avoiding any influence on non-target areas. By reducing background interference, this approach enables the loss function to focus more directly on the impact of the adversarial patch on the detection model, thereby improving the attack success rate. Experiments conducted on the HRSC2016 dataset demonstrate that the proposed method effectively increases the success rate of adversarial patch attacks and enhances their transferability.
title Adversarial Patch Attack for Ship Detection via Localized Augmentation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2508.21472