English  |  正體中文  |  简体中文  |  全文筆數/總筆數 : 78937/78937 (100%)
造訪人次 : 39423781      線上人數 : 586
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
搜尋範圍 查詢小技巧:
  • 您可在西文檢索詞彙前後加上"雙引號",以獲取較精準的檢索結果
  • 若欲以作者姓名搜尋,建議至進階搜尋限定作者欄位,可獲得較完整資料
  • 進階搜尋


    請使用永久網址來引用或連結此文件: http://ir.lib.ncu.edu.tw/handle/987654321/92474


    題名: 基於擴散模型的自然對抗補丁生成;Diffusion to Confusion: Naturalistic Adversarial Patch Generation Based on Diffusion Model for Object Detector
    作者: 林碩彥;Lin, Shuo-Yen
    貢獻者: 資訊工程學系
    關鍵詞: 擴散模型;對抗補丁;對抗攻擊;物件偵測;攻擊物件偵測器;深度生成模型;Diffusion Model;Adversarial Patch;Adversarial Attack;Object Detection;Attack Object Detector;Deep Generative Model
    日期: 2023-07-11
    上傳時間: 2023-10-04 16:02:35 (UTC+8)
    出版者: 國立中央大學
    摘要: 為了保障個人隱私資料免受不法份子惡意使用物件偵測器進行監控,近年來已經有許多物理對抗補丁生成方法被提出。然而,這些方法往往需要進行大量的超參數調整,並且必須在達到足夠的攻擊效果同時不被他人察覺。因此,生成外觀令人滿意的補丁圖像仍然是一個具有挑戰性的問題。為了解決這個問題,本研究提出了一種基於擴散模型(Diffusion Model)的新型自然對抗補丁生成方法。通過在自然圖像上預訓練的擴散模型中採樣最佳圖像,我們可以穩健地製作出高品質且外觀自然的對抗補丁,而避免其他深度生成模型所遇到的嚴重模式崩潰問題。據我們所知,本研究是第一個針對物件偵測器提出基於擴散模型的物理對抗性補丁生成方法。此外,通過廣泛的定量、定性和主觀實驗,我們發現相比於其他最先進的補丁生成方法,我們的方法可以有效地生成品質更好、更自然的對抗補丁,同時實現出色的攻擊性能;Numerous physical adversarial patch generation methods have been proposed to protect personal privacy from malicious monitoring using object detectors. However, these methods often fall short of generating satisfactory patch images in terms of both stealthiness and attack performance without extensive hyperparameter tuning. To address this issue, we propose a novel naturalistic adversarial patch generation method based on diffusion models (DM). By sampling the optimal image from a DM model pre-trained on natural images, we can craft high-quality and naturalistic physical adversarial patches in a stable manner, without suffering from the serious mode collapse problems that plague other deep generative models. To the best of our knowledge, we are the first to propose a DM-based naturalistic adversarial patch generation method for object detectors. Extensive quantitative, qualitative, and subjective experiments demonstrate that our approach is effective in generating better-quality and more naturalistic adversarial patches while achieving acceptable attack performance compared to other state-of-the-art patch generation methods. Additionally, we show various generation trade-offs under different conditions
    顯示於類別:[資訊工程研究所] 博碩士論文

    文件中的檔案:

    檔案 描述 大小格式瀏覽次數
    index.html0KbHTML38檢視/開啟


    在NCUIR中所有的資料項目都受到原著作權保護.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明