跳到主要导航 跳到搜索 跳到主要内容

Harnessing Perceptual Adversarial Patches for Crowd Counting

  • Shunchang Liu
  • , Jiakai Wang
  • , Aishan Liu*
  • , Yingwei Li
  • , Yijie Gao
  • , Xianglong Liu
  • , Dacheng Tao
  • *此作品的通讯作者
  • Beihang University
  • Zhongguancun Laboratory
  • Johns Hopkins University
  • JD Explore Academy
  • The University of Sydney

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Crowd counting, which has been widely adopted for estimating the number of people in safety-critical scenes, is shown to be vulnerable to adversarial examples in the physical world (e.g., adversarial patches). Though harmful, adversarial examples are also valuable for evaluating and better understanding model robustness. However, existing adversarial example generation methods for crowd counting lack strong transferability among different black-box models, which limits their practicability for real-world systems. Motivated by the fact that attacking transferability is positively correlated to the model-invariant characteristics, this paper proposes the Perceptual Adversarial Patch (PAP) generation framework to tailor the adversarial perturbations for crowd counting scenes using the model-shared perceptual features. Specifically, we handcraft an adaptive crowd density weighting approach to capture the invariant scale perception features across various models and utilize the density guided attention to capture the model-shared position perception. Both of them are demonstrated to improve the attacking transferability of our adversarial patches. Extensive experiments show that our PAP could achieve state-of-the-art attacking performance in both the digital and physical world, and outperform previous proposals by large margins (at most +685.7 MAE and +699.5 MSE). Besides, we empirically demonstrate that adversarial training with our PAP can benefit the performance of vanilla models in alleviating several practical challenges in crowd counting scenarios, including generalization across datasets (up to-376.0 MAE and-354.9 MSE) and robustness towards complex backgrounds (up to-10.3 MAE and-16.4 MSE).

源语言英语
主期刊名CCS 2022 - Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
出版商Association for Computing Machinery
2055-2069
页数15
ISBN(电子版)9781450394505
DOI
出版状态已出版 - 7 11月 2022
活动28th ACM SIGSAC Conference on Computer and Communications Security, CCS 2022 - Hybrid, Los Angeles, 美国
期限: 7 11月 202211 11月 2022

丛书

姓名Proceedings of the ACM Conference on Computer and Communications Security
ISSN(印刷版)1543-7221

会议

会议28th ACM SIGSAC Conference on Computer and Communications Security, CCS 2022
国家/地区美国
Hybrid, Los Angeles
时期7/11/2211/11/22

学术指纹

探究 'Harnessing Perceptual Adversarial Patches for Crowd Counting' 的科研主题。它们共同构成独一无二的学术指纹。

引用此