跳到主要导航 跳到搜索 跳到主要内容

Adversarial Patch Steganography Enhancement through Localized Style Fusion

投稿的翻译标题: 基于局部风格融合的对抗补丁隐蔽性增强方法
  • Xilong Xie
  • , Tong Guo
  • , Limin Xiao*
  • , Meng Han
  • , Xiangrong Xu
  • , Jin Dong
  • , Liang Wang
  • *此作品的通讯作者
  • Beihang University
  • Beijing Academy of Blockchain and Edge Computing

科研成果: 期刊稿件文章同行评审

摘要

Since the concept of adversarial examples was introduced, various adversarial attack methods targeting deep learning models have raised a series of security issues. Among them, adversarial patches introduce specific patches into input samples to cause deep learning models to produce misleading results, posing significant security risks to current deep learning systems. However, current adversarial patch generation methods still have certain limitations in enhancing the concealment of adversarial patches, as they are prone to being detected by humans due to significant differences from the surrounding environment. In response to this problem, this paper proposes a method for enhancing the concealment of adversarial patches based on local style fusion. The method first searches for the vulnerable regions of the image based on multi-model weighted class activation mapping, and accurately locates the placement of adversarial patches, which improves the aggressiveness of adversarial patches. Then the style migration technique is utilized to compute the style matrix and content matrix of the target image and the adversarial patch. During the adversarial patch generation process, a comprehensive approach takes into account not only classification loss but also style loss, content loss, and boundary loss. By utilizing the cosine distance function, adjustments are made to both the style and content of the generated adversarial patch. This intricate adjustment ensures that the adversarial patch seamlessly blends its style and content with the local image it overlays, effectively integrating it into the surrounding environment. This harmonization guarantees consistency in color and style, ultimately minimizing the visibility of the adversarial patch to the human eye. The ultimate goal is to significantly enhance the concealment of the adversarial patch. In this paper, the generated patches are experimentally evaluated in terms of aggressiveness and covertness, respectively, and the experimental results show that this method can generate adversarial patches with both covertness and aggressiveness, which can realize the attack while being undetectable to human beings.

投稿的翻译标题基于局部风格融合的对抗补丁隐蔽性增强方法
源语言英语
页(从-至)64-76
页数13
期刊Journal of Cyber Security
10
5
DOI
出版状态已出版 - 2025

指纹

探究 '基于局部风格融合的对抗补丁隐蔽性增强方法' 的科研主题。它们共同构成独一无二的指纹。

引用此