Article(id=1189585008365921270, tenantId=1146029695717560320, journalId=1146119989267898375, issueId=1189585006872749036, articleNumber=null, orderNo=null, doi=10.7654/j.issn.2097-1974.20250405, pmid=null, cstr=null, oa=null, hot=null, price=null, onlineType=0, articleFormat=0, articleType=null, articleTypeStr=null, receivedDate=1732723200000, receivedDateStr=2024-11-28, revisedDate=1743523200000, revisedDateStr=2025-04-02, acceptedDate=null, acceptedDateStr=null, onlineDate=1761548767414, onlineDateStr=2025-10-27, pubDate=1756051200000, pubDateStr=2025-08-25, doiRegisterDate=null, doiRegisterDateStr=null, onlineIssueDate=1761548767414, onlineIssueDateStr=2025-10-27, onlineJustAcceptDate=null, onlineJustAcceptDateStr=null, onlineFirstDate=null, onlineFirstDateStr=null, sourceXml=null, magXml=null, createTime=1761548767414, creator=13701087609, updateTime=1761548767414, updator=13701087609, issue=Issue{id=1189585006872749036, tenantId=1146029695717560320, journalId=1146119989267898375, year='2025', volume='48', issue='4', pageStart='1', pageEnd='106', issueExtLink='null', onlineDate='null', pubDate='null', beforeIssueId=null, nextIssueId=null, price=null, status=1, issueComplete=1, articleOrder=1, issueType=-1, specialIssue=null, createTime=1761548767059, creator=13701087609, updateTime=1761552469778, updator=13701087609, preIssue=null, nextIssue=null, ext={EN=IssueExt(id=1189600537306718633, tenantId=1146029695717560320, journalId=1146119989267898375, issueId=1189585006872749036, language=EN, specialIssueTitle=, coverIllustrator=null, specialIssueEditor=, specialIssueAbout=), CN=IssueExt(id=1189600537306718634, tenantId=1146029695717560320, journalId=1146119989267898375, issueId=1189585006872749036, language=CN, specialIssueTitle=, coverIllustrator=null, specialIssueEditor=, specialIssueAbout=)}, issueFiles=null}, startPage=38, endPage=44, ext={EN=ArticleExt(id=1189585008667911160, articleId=1189585008365921270, tenantId=1146029695717560320, journalId=1146119989267898375, language=EN, title=Adversarial Patch Attack Based Camouflage And Deception Method, columnId=1189585008235897844, journalTitle=Missiles and Space Vehicles, columnName=Artificial Intelligence Technology, runingTitle=null, highlight=null, articleAbstract=
As artificial intelligence technology developing rapidly, the intelligence level of unmanned systems is much increasing. Specially, intelligent reconnaissance technology is more mature and widely used. To solve the above problems, an adversarial patch attack based camouflage and deception method is proposed. Convolutional neural network is used to build a classifier as the attack object, and a novel patch generation method and loss function are designed to attack target samples, which effectively maps the attacked target samples to the specified wrong target category. A directed evaluation method and wealthy experiments are provided to verify the advancement and effectiveness of this method.
, correspAuthors=null, authorNote=null, correspAuthorsNote=null, copyrightStatement=null, copyrightOwner=null, extLink=null, articleAbsUrl=null, sourceXml=null, magXml=null, pdfUrl=null, pdf=null, pdfFileSize=null, pdfExtLink=null, richHtmlUrl=null, mobilePdfUrl=null, reviewReport=null, pdfFirstPage=null, abstractGraph=null, abstractGraphContent=null, abstractVideo=null, citation=null, cebUrl=null, magXmlContent=null, mapNumber=null, authorCompany=null, fund=null, authors=null, authorsList=Wei YANG, Shengjia LI, Zihang SHAO, Hu HUANG, Benchang ZHENG), CN=ArticleExt(id=1189585197684220176, articleId=1189585008365921270, tenantId=1146029695717560320, journalId=1146119989267898375, language=CN, title=基于补丁对抗攻击的伪装欺骗技术研究, columnId=1189585008399475703, journalTitle=导弹与航天运载技术(中英文), columnName=人工智能技术专栏, runingTitle=null, highlight=null, articleAbstract=
随着人工智能技术的飞速发展,无人化系统的智能水平日益提高,其中智能侦察技术较为成熟且应用广泛,面向智能侦察的伪装欺骗技术研究迫在眉睫。针对上述问题,提出了一种基于补丁对抗攻击的伪装欺骗方法,采用卷积神经网络构建分类器作为攻击对象,通过设计全新的补丁生成方式和损失函数,完成目标样本的补丁攻击,能够有效地将攻击的目标样本映射到指定的错误目标类别上,并提供了针对性的评价方法及丰富的试验,验证了该方法的先进性与有效性。
, correspAuthors=null, authorNote=null, correspAuthorsNote=null, copyrightStatement=null, copyrightOwner=null, extLink=null, articleAbsUrl=null, sourceXml=Y/cazxIxmS5GHrSNMuCUog==, magXml=J8o9P5HiXGKBJOYHmRXk9g==, pdfUrl=null, pdf=VQAQByXhMQqJvoNUnWyAqg==, pdfFileSize=2502295, pdfExtLink=null, richHtmlUrl=null, mobilePdfUrl=null, reviewReport=null, pdfFirstPage=null, abstractGraph=wWqfQgFkfDbMF/3CoaF0dA==, abstractGraphContent=null, abstractVideo=null, citation=null, cebUrl=null, magXmlContent=eGkPngxzpb9cDbf+ok1eeA==, mapNumber=null, authorCompany=null, fund=null, authors=
杨 威(1981—),男,研究员,主要研究方向为智能与仿真系统、对抗博弈技术。
李晟嘉(1995—),男,工程师,主要研究方向为深度学习、图像感知、人工智能安全对抗技术。
邵子航(1999—),男,工程师,主要研究方向为强化学习、人工智能安全对抗技术。
黄 虎(1986—),男,研究员,主要研究方向为智能博弈对抗、仿真建模、人工智能安全对抗技术。
郑本昌(1986—),男,高级工程师,主要研究方向为强化学习、多智能体博弈、人工智能安全对抗技术。
, authorsList=杨威, 李晟嘉, 邵子航, 黄虎, 郑本昌)}, authors=[Author(id=1190013540632199318, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, orderNo=0, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1190013540720279704, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013540632199318, language=EN, stringName=Wei YANG, firstName=Wei, middleName=null, lastName=YANG, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1190013540812554393, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013540632199318, language=CN, stringName=杨威, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=中国运载火箭技术研究院研究发展中心,北京,100076, bio={"content":"
杨 威(1981—),男,研究员,主要研究方向为智能与仿真系统、对抗博弈技术。
"}, bioImg=null, bioContent=
杨 威(1981—),男,研究员,主要研究方向为智能与仿真系统、对抗博弈技术。
, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1190013540531536018, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, xref=null, ext=[AuthorCompanyExt(id=1190013540544118931, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076), AuthorCompanyExt(id=1190013540560896148, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=中国运载火箭技术研究院研究发展中心,北京,100076)])]), Author(id=1190013540896440475, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, orderNo=1, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1190013540988715165, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013540896440475, language=EN, stringName=Shengjia LI, firstName=Shengjia, middleName=null, lastName=LI, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1190013541051629726, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013540896440475, language=CN, stringName=李晟嘉, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=中国运载火箭技术研究院研究发展中心,北京,100076, bio={"content":"
李晟嘉(1995—),男,工程师,主要研究方向为深度学习、图像感知、人工智能安全对抗技术。
"}, bioImg=null, bioContent=
李晟嘉(1995—),男,工程师,主要研究方向为深度学习、图像感知、人工智能安全对抗技术。
, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1190013540531536018, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, xref=null, ext=[AuthorCompanyExt(id=1190013540544118931, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076), AuthorCompanyExt(id=1190013540560896148, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=中国运载火箭技术研究院研究发展中心,北京,100076)])]), Author(id=1190013541127127200, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, orderNo=2, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1190013541198430370, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013541127127200, language=EN, stringName=Zihang SHAO, firstName=Zihang, middleName=null, lastName=SHAO, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1190013541290705059, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013541127127200, language=CN, stringName=邵子航, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=中国运载火箭技术研究院研究发展中心,北京,100076, bio={"content":"
邵子航(1999—),男,工程师,主要研究方向为强化学习、人工智能安全对抗技术。
"}, bioImg=null, bioContent=
邵子航(1999—),男,工程师,主要研究方向为强化学习、人工智能安全对抗技术。
, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1190013540531536018, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, xref=null, ext=[AuthorCompanyExt(id=1190013540544118931, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076), AuthorCompanyExt(id=1190013540560896148, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=中国运载火箭技术研究院研究发展中心,北京,100076)])]), Author(id=1190013541399756965, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, orderNo=3, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1190013541479448743, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013541399756965, language=EN, stringName=Hu HUANG, firstName=Hu, middleName=null, lastName=HUANG, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1190013541575917736, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013541399756965, language=CN, stringName=黄虎, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=中国运载火箭技术研究院研究发展中心,北京,100076, bio={"content":"
黄 虎(1986—),男,研究员,主要研究方向为智能博弈对抗、仿真建模、人工智能安全对抗技术。
"}, bioImg=null, bioContent=
黄 虎(1986—),男,研究员,主要研究方向为智能博弈对抗、仿真建模、人工智能安全对抗技术。
, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1190013540531536018, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, xref=null, ext=[AuthorCompanyExt(id=1190013540544118931, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076), AuthorCompanyExt(id=1190013540560896148, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=中国运载火箭技术研究院研究发展中心,北京,100076)])]), Author(id=1190013541651415210, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, orderNo=4, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1190013541731106988, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013541651415210, language=EN, stringName=Benchang ZHENG, firstName=Benchang, middleName=null, lastName=ZHENG, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1190013541819187373, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, authorId=1190013541651415210, language=CN, stringName=郑本昌, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=null, address=中国运载火箭技术研究院研究发展中心,北京,100076, bio={"content":"
郑本昌(1986—),男,高级工程师,主要研究方向为强化学习、多智能体博弈、人工智能安全对抗技术。
"}, bioImg=null, bioContent=
郑本昌(1986—),男,高级工程师,主要研究方向为强化学习、多智能体博弈、人工智能安全对抗技术。
, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1190013540531536018, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, xref=null, ext=[AuthorCompanyExt(id=1190013540544118931, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076), AuthorCompanyExt(id=1190013540560896148, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=中国运载火箭技术研究院研究发展中心,北京,100076)])])], keywords=[Keyword(id=1190013541978570926, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, orderNo=1, keyword=artificial intelligence), Keyword(id=1190013542079234223, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, orderNo=2, keyword=intelligent reconnaissance), Keyword(id=1190013542142148784, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, orderNo=3, keyword=camouflage and deception), Keyword(id=1190013542213451953, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, orderNo=4, keyword=patch attack), Keyword(id=1190013542318309554, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, orderNo=5, keyword=adversarial examples), Keyword(id=1190013542460915891, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, orderNo=1, keyword=人工智能), Keyword(id=1190013542540607668, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, orderNo=2, keyword=智能侦察), Keyword(id=1190013542607716533, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, orderNo=3, keyword=伪装欺骗), Keyword(id=1190013542695796918, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, orderNo=4, keyword=补丁攻击), Keyword(id=1190013542767100087, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, orderNo=5, keyword=对抗样本)], refs=[Reference(id=1190013545313042642, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[1], rfOrder=0, authorNames=DONG Y, LIAO F, PANG T, journalName=Boosting adversarial attacks with momentum, refType=null, unstructuredReference=
DONG Y,
LIAO F,
PANG T, et al.
Boosting adversarial attacks with momentum[C]. Salt Lake City: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR),
2018., articleTitle=null, refAbstract=null), Reference(id=1190013545401123027, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2023, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[2], rfOrder=1, authorNames=LU D, WANG Z, WANG T, journalName=Set-level guidance attack: boosting adversarial transferability of vision-language pre-training models, refType=null, unstructuredReference=
LU D,
WANG Z,
WANG T, et al.
Set-level guidance attack: boosting adversarial transferability of vision-language pre-training models[C]. Paris: Proceedings of the IEEE/CVF International Conference on Computer Vision,
2023., articleTitle=null, refAbstract=null), Reference(id=1190013545468231892, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2023, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[3], rfOrder=2, authorNames=ZHU P, OSADA G, KATAOKA H, journalName=Frequency-aware GAN for adversarial manipulation generation, refType=null, unstructuredReference=
ZHU P,
OSADA G,
KATAOKA H, et al.
Frequency-aware GAN for adversarial manipulation generation[C]. Paris: Proceedings of the IEEE/CVF International Conference on Computer Vision,
2023., articleTitle=null, refAbstract=null), Reference(id=1190013545543729365, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2023, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[4], rfOrder=3, authorNames=REZA M F, RAHMATI A, WU T, journalName=Cgba: curvature-aware geometric black-box attack, refType=null, unstructuredReference=
REZA M F,
RAHMATI A,
WU T, et al.
Cgba: curvature-aware geometric black-box attack[C]. Paris: Proceedings of the IEEE/CVF International Conference on Computer Vision,
2023., articleTitle=null, refAbstract=null), Reference(id=1190013545623421142, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2023, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[5], rfOrder=4, authorNames=HUANG Q, DONG X, CHEN D, journalName=Improving adversarial robustness of masked autoencoders via test-time frequency-domain prompting, refType=null, unstructuredReference=
HUANG Q,
DONG X,
CHEN D, et al.
Improving adversarial robustness of masked autoencoders via test-time frequency-domain prompting[C]. Paris: Proceedings of the IEEE/CVF International Conference on Computer Vision,
2023., articleTitle=null, refAbstract=null), Reference(id=1190013545690530007, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=null, volume=null, issue=null, pageStart=null, pageEnd=null, url=https://arxiv.org/abs/1712.09665, language=null, rfNumber=[6], rfOrder=5, authorNames=BROWN T B, DANDELION Mané, ROY A, journalName=null, refType=null, unstructuredReference=
BROWN T B,
DANDELION Mané,
ROY A, et al. Adversarial Pat-ch[EB/OL]. (2017-11-27)[2024-11-10]. https://arxiv.org/abs/1712.09665, articleTitle=Adversarial Pat-ch, refAbstract=null), Reference(id=1190013545782804696, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=null, volume=null, issue=null, pageStart=null, pageEnd=null, url=https://arxiv.org/abs/1806.02299, language=null, rfNumber=[7], rfOrder=6, authorNames=LIU Xin, YANG Huanrui, LIU Ziwei, journalName=null, refType=null, unstructuredReference=
LIU Xin,
YANG Huanrui,
LIU Ziwei, et al. Dpatch: an adversarial patch attack on object detectors[EB/OL]. (2019-04-23)[2024-11-10]. https://arxiv.org/abs/1806.02299, articleTitle=Dpatch: an adversarial patch attack on object detectors, refAbstract=null), Reference(id=1190013545849913561, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2019, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[8], rfOrder=7, authorNames=THYS S, RANST W V, GOEDEME T, journalName=IEEE, refType=null, unstructuredReference=
THYS S,
RANST W V,
GOEDEME T. Fooling automated survei-llance cameras: adversarial patches to attack person detection[J].
IEEE,
2019. DOI:
10.1109/CVPRW.2019.00012 ., articleTitle=Fooling automated survei-llance cameras: adversarial patches to attack person detection, refAbstract=null), Reference(id=1190013545929605338, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2020, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[9], rfOrder=8, authorNames=HUANG L F, GAO C Y, ZHOU Y Y, journalName=null, refType=null, unstructuredReference=
HUANG L F,
GAO C Y,
ZHOU Y Y, et al. Universal physical camouflage attacks on object detectors[C/OL]. IEEE/CVF Confere-nce on Computer Vision and Pattern Recognition,
2020., articleTitle=Universal physical camouflage attacks on object detectors, refAbstract=null), Reference(id=1190013545992519899, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2020, volume=null, issue=null, pageStart=1, pageEnd=17, url=null, language=null, rfNumber=[10], rfOrder=9, authorNames=WU Z X, LIM S N, DAVIS L S, journalName=Making an invisibility cloak: real world adversarial attacks on object detectors, refType=null, unstructuredReference=
WU Z X,
LIM S N,
DAVIS L S, et al.
Making an invisibility cloak: real world adversarial attacks on object detectors[C]//Computer Vision-ECCV 2020. Cham: Springer,
2020: 1-17., articleTitle=null, refAbstract=null), Reference(id=1190013546093183196, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2016, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[11], rfOrder=10, authorNames=SHARIF M, BHAGAVATUL S, BAUER L, journalName=Accessorize to a crime: real and stealthy attacks on state-of the-art face recogni-tion, refType=null, unstructuredReference=
SHARIF M,
BHAGAVATUL S,
BAUER L, et al.
Accessorize to a crime: real and stealthy attacks on state-of the-art face recogni-tion[C]. New York: Proceedings of the
2016 ACM SIGSAC Confe-rence on Computer and Communications Security, 2016., articleTitle=null, refAbstract=null), Reference(id=1190013546198040797, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[12], rfOrder=11, authorNames=SONG D, EYKHOLT K, EVTIMOV I, journalName=Physical adversarial examples for object detectors, refType=null, unstructuredReference=
SONG D,
EYKHOLT K,
EVTIMOV I, et al.
Physical adversarial examples for object detectors[C]. Berkeley: 12th USENIX Workshop on Offensive Technologies,
2018., articleTitle=null, refAbstract=null), Reference(id=1190013546281926878, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2019, volume=null, issue=null, pageStart=52, pageEnd=68, url=null, language=null, rfNumber=[13], rfOrder=12, authorNames=CHEN S T, CORNELIUS C, MARTIN J, journalName=Shape shifter: robust physical adversarial attack on faster R CNN object detector, refType=null, unstructuredReference=
CHEN S T,
CORNELIUS C,
MARTIN J, et al.
Shape shifter: robust physical adversarial attack on faster R CNN object detector[C]//European Conference on Machine Learning and Knowledge Discove-ry in Databases. Cham: Springer,
2019: 52-68., articleTitle=null, refAbstract=null), Reference(id=1190013546353230047, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2021, volume=null, issue=null, pageStart=8561, pageEnd=8570, url=null, language=null, rfNumber=[14], rfOrder=13, authorNames=WANG J K, LIU A S, YIN Z X, journalName=Dual attention sup pression attack: generate adversarial camouflage in physical world, refType=null, unstructuredReference=
WANG J K,
LIU A S,
YIN Z X, et al.
Dual attention sup pression attack: generate adversarial camouflage in physical world[C]//2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE,
2021: 8561-8570., articleTitle=null, refAbstract=null), Reference(id=1190013546432921824, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2019, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[15], rfOrder=14, authorNames=AURDAL L, LKKEN K H, KLAUSEN R A, journalName=Adversarial camouflage for naval vessels, refType=null, unstructuredReference=
AURDAL L,
LKKEN K H,
KLAUSEN R A, et al.
Adversarial camouflage for naval vessels[C]. Bellingham: Artificial Intelligence and Machine Learning in Defense Applications,
2019., articleTitle=null, refAbstract=null), Reference(id=1190013546504224993, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2020, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[16], rfOrder=15, authorNames=ADHIKARI A, HOLLANDER R D, TOLIOS I, journalName=Adversarial patch camouflage against aerial detection, refType=null, unstructuredReference=
ADHIKARI A,
HOLLANDER R D,
TOLIOS I, et al.
Adversarial patch camouflage against aerial detection[C]. Bellingham: Artificial Intelligence and Machine Learning in Defense Applications II,
2020., articleTitle=null, refAbstract=null), Reference(id=1190013546575528162, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2015, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[17], rfOrder=16, authorNames=SIMONYAN K, ZISSERMAN A, journalName=Very deep convolutional networks for large-scale image recognition, refType=null, unstructuredReference=
SIMONYAN K,
ZISSERMAN A.
Very deep convolutional networks for large-scale image recognition[C]. San Diego: International Confe-rence on Learning Representations,
2015., articleTitle=null, refAbstract=null), Reference(id=1190013546697162979, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2016, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[18], rfOrder=17, authorNames=HE K, ZHANG X, REN S, journalName=IEEE, refType=null, unstructuredReference=
HE K,
ZHANG X,
REN S, et al. Deep residual learning for image recognition[J].
IEEE,
2016. DOI:
10.1109/CVPR.2016.90 ., articleTitle=Deep residual learning for image recognition, refAbstract=null), Reference(id=1190013546797826276, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2014, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[19], rfOrder=18, authorNames=KRAUSE J, STARK M, DENG J, journalName=3D object representations for fine-grained categorization, refType=null, unstructuredReference=
KRAUSE J,
STARK M,
DENG J, et al.
3D object representations for fine-grained categorization[C]. Sydney: IEEE International Confere-nce on Computer Vision Workshops,
2014., articleTitle=null, refAbstract=null), Reference(id=1190013546869129445, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=null, volume=null, issue=null, pageStart=null, pageEnd=null, url=https://arxiv.org/abs/1412.6980, language=null, rfNumber=[20], rfOrder=19, authorNames=KINGMA D, BA J, journalName=null, refType=null, unstructuredReference=
KINGMA D,
BA J. Adam: A method for stochastic optimization[EB/OL]. (2017-11-29)[2024-11-10]. https://arxiv.org/abs/1412.6980, articleTitle=Adam: A method for stochastic optimization, refAbstract=null), Reference(id=1190013546944626918, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=null, volume=null, issue=null, pageStart=null, pageEnd=null, url=https://arxiv.org/abs/2111.04266, language=null, rfNumber=[21], rfOrder=20, authorNames=LI X, JI S B, journalName=null, refType=null, unstructuredReference=
LI X,
JI S B. Generative dynamic patch attack[EB/OL]. (2021-11-15)[2024-11-10]. https://arxiv.org/abs/2111.04266, articleTitle=Generative dynamic patch attack, refAbstract=null), Reference(id=1190013547028512999, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2017, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[22], rfOrder=21, authorNames=LIU Z, YUAN L, WENG L, journalName=A high resolution optical satellite imagedataset for ship recognition and some new baselines, refType=null, unstructuredReference=
LIU Z,
YUAN L,
WENG L, et al.
A high resolution optical satellite imagedataset for ship recognition and some new baselines[C]. Hangzhou: Chinese Conference on Pattern Recognition and Machine Learning,
2017., articleTitle=null, refAbstract=null), Reference(id=1190013547112399080, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, doi=null, pmid=null, pmcid=null, year=2022, volume=null, issue=26, pageStart=361, pageEnd=373, url=null, language=null, rfNumber=[23], rfOrder=22, authorNames=ZHAN W, SUN C, WANG M, journalName=Soft Comput, refType=null, unstructuredReference=
ZHAN W,
SUN C,
WANG M, et al. An improved Yolov5 real-time detection method for small objects captured by UAV[J].
Soft Comput,
2022(26): 361-373., articleTitle=An improved Yolov5 real-time detection method for small objects captured by UAV, refAbstract=null)], funds=null, companyList=[AuthorCompany(id=1190013540531536018, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, xref=null, ext=[AuthorCompanyExt(id=1190013540544118931, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=R&D Center, China Academy of Launch Vehicle Technology, Beijing, 100076), AuthorCompanyExt(id=1190013540560896148, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, companyId=1190013540531536018, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=中国运载火箭技术研究院研究发展中心,北京,100076)])], figs=[ArticleFig(id=1190013543035535544, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Fig.1, caption=
Illustration of VggNet classifier structure, figureFileSmall=h13gNCRHki+Tes7BpYpxww==, figureFileBig=DZrvOjkCEynoU32QZH4XUA==, tableContent=null), ArticleFig(id=1190013543115227321, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=图1, caption=
VggNet分类器结构示意, figureFileSmall=h13gNCRHki+Tes7BpYpxww==, figureFileBig=DZrvOjkCEynoU32QZH4XUA==, tableContent=null), ArticleFig(id=1190013543207502010, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Fig.2, caption=
Illustration of ResNet classifier structure, figureFileSmall=ndx6fA+TEpxcW6EEKU9Oqg==, figureFileBig=IBH5G6i+X02oi4eFdv+LfA==, tableContent=null), ArticleFig(id=1190013543291388091, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=图2, caption=
ResNet分类器结构示意, figureFileSmall=ndx6fA+TEpxcW6EEKU9Oqg==, figureFileBig=IBH5G6i+X02oi4eFdv+LfA==, tableContent=null), ArticleFig(id=1190013543350108348, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Fig.3, caption=
Flowchart of proposed algorithm, figureFileSmall=KbIu00lu0zGu1+BDHZswGQ==, figureFileBig=1P9+NLHny6bZTHXQ4YD7FA==, tableContent=null), ArticleFig(id=1190013543417217213, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=图3, caption=
算法流程, figureFileSmall=KbIu00lu0zGu1+BDHZswGQ==, figureFileBig=1P9+NLHny6bZTHXQ4YD7FA==, tableContent=null), ArticleFig(id=1190013543488520382, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Fig.4, caption=
Illustration of both attack patch effect, figureFileSmall=hLAyFLFOJr/w+W9yOnwLAQ==, figureFileBig=JNDSG7dQz0cRDuE8DnV9nQ==, tableContent=null), ArticleFig(id=1190013543559823551, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=图4, caption=
两种攻击补丁效果示意, figureFileSmall=hLAyFLFOJr/w+W9yOnwLAQ==, figureFileBig=JNDSG7dQz0cRDuE8DnV9nQ==, tableContent=null), ArticleFig(id=1190013543631126720, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Fig.5, caption=
Illustration of attack object detection and recognition effect, figureFileSmall=JWEyXh7U6lXE1qfVVtAYAg==, figureFileBig=lARtkN7Q1ZtgP+P3YIM/pA==, tableContent=null), ArticleFig(id=1190013543706624193, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=图5, caption=
攻击目标检测与识别算法效果示意, figureFileSmall=JWEyXh7U6lXE1qfVVtAYAg==, figureFileBig=lARtkN7Q1ZtgP+P3YIM/pA==, tableContent=null), ArticleFig(id=1190013543790510274, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.1, caption=
Comparison of patch attack effect by two classifiers(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 方法 | A b | A a | A t | ALD _2 | Ave |
| 本文方法(VggNet) | 0.957 | 0.060 | 0.575 | 0.282 | 0.701 |
| 本文方法(ResNet) | 0.957 | 0.273 | 0.711 | 0.278 | 0.615 |
| GDPA | 0.957 | 0.229 | 0.884 | 0.194 | 0.625 |
), ArticleFig(id=1190013543861813443, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表1, caption=
两种分类器补丁攻击效果对比(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 方法 | A b | A a | A t | ALD _2 | Ave |
| 本文方法(VggNet) | 0.957 | 0.060 | 0.575 | 0.282 | 0.701 |
| 本文方法(ResNet) | 0.957 | 0.273 | 0.711 | 0.278 | 0.615 |
| GDPA | 0.957 | 0.229 | 0.884 | 0.194 | 0.625 |
), ArticleFig(id=1190013543937310916, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.2, caption=
Comparison of average (Ave )(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 0.617 | 0.607 | 0.599 | 0.591 | 0.582 | 0.575 |
| 0.2 | 0.612 | 0.601 | 0.592 | 0.580 | 0.573 | 0.567 |
| 0.3 | 0.609 | 0.592 | 0.589 | 0.584 | 0.588 | 0.574 |
| 0.4 | 0.607 | 0.595 | 0.592 | 0.604 | 0.606 | 0.621 |
| 0.5 | 0.604 | 0.597 | 0.602 | 0.617 | 0.644 | 0.676 |
| 0.6 | 0.602 | 0.598 | 0.619 | 0.646 | 0.687 | 0.701 |
| ResNet | 0.1 | 0.505 | 0.495 | 0.488 | 0.480 | 0.474 | 0.468 |
| 0.2 | 0.502 | 0.489 | 0.480 | 0.472 | 0.467 | 0.467 |
| 0.3 | 0.497 | 0.484 | 0.478 | 0.483 | 0.493 | 0.511 |
| 0.4 | 0.495 | 0.481 | 0.485 | 0.497 | 0.523 | 0.553 |
| 0.5 | 0.493 | 0.483 | 0.492 | 0.515 | 0.560 | 0.599 |
| 0.6 | 0.492 | 0.482 | 0.492 | 0.533 | 0.573 | 0.615 |
), ArticleFig(id=1190013544037974213, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表2, caption=
综合指标(Ave )对比(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 0.617 | 0.607 | 0.599 | 0.591 | 0.582 | 0.575 |
| 0.2 | 0.612 | 0.601 | 0.592 | 0.580 | 0.573 | 0.567 |
| 0.3 | 0.609 | 0.592 | 0.589 | 0.584 | 0.588 | 0.574 |
| 0.4 | 0.607 | 0.595 | 0.592 | 0.604 | 0.606 | 0.621 |
| 0.5 | 0.604 | 0.597 | 0.602 | 0.617 | 0.644 | 0.676 |
| 0.6 | 0.602 | 0.598 | 0.619 | 0.646 | 0.687 | 0.701 |
| ResNet | 0.1 | 0.505 | 0.495 | 0.488 | 0.480 | 0.474 | 0.468 |
| 0.2 | 0.502 | 0.489 | 0.480 | 0.472 | 0.467 | 0.467 |
| 0.3 | 0.497 | 0.484 | 0.478 | 0.483 | 0.493 | 0.511 |
| 0.4 | 0.495 | 0.481 | 0.485 | 0.497 | 0.523 | 0.553 |
| 0.5 | 0.493 | 0.483 | 0.492 | 0.515 | 0.560 | 0.599 |
| 0.6 | 0.492 | 0.482 | 0.492 | 0.533 | 0.573 | 0.615 |
), ArticleFig(id=1190013544113471686, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.3, caption=
Comparison of accuracy of classifier after patch attack (A a)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 0.481 | 0.478 | 0.463 | 0.450 | 0.442 | 0.427 |
| 0.2 | 0.483 | 0.459 | 0.431 | 0.408 | 0.381 | 0.353 |
| 0.3 | 0.481 | 0.444 | 0.401 | 0.354 | 0.293 | 0.277 |
| 0.4 | 0.476 | 0.431 | 0.368 | 0.283 | 0.226 | 0.165 |
| 0.5 | 0.474 | 0.403 | 0.317 | 0.228 | 0.153 | 0.092 |
| 0.6 | 0.473 | 0.389 | 0.266 | 0.169 | 0.096 | 0.060 |
| ResNet | 0.1 | 0.934 | 0.926 | 0.908 | 0.893 | 0.876 | 0.859 |
| 0.2 | 0.925 | 0.909 | 0.876 | 0.845 | 0.808 | 0.760 |
| 0.3 | 0.927 | 0.899 | 0.838 | 0.749 | 0.664 | 0.588 |
| 0.4 | 0.924 | 0.884 | 0.782 | 0.668 | 0.551 | 0.453 |
| 0.5 | 0.921 | 0.855 | 0.727 | 0.580 | 0.430 | 0.331 |
| 0.6 | 0.915 | 0.84 | 0.698 | 0.500 | 0.382 | 0.273 |
), ArticleFig(id=1190013544205746375, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表3, caption=
补丁攻击后分类器的准确率(A a)对比
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 0.481 | 0.478 | 0.463 | 0.450 | 0.442 | 0.427 |
| 0.2 | 0.483 | 0.459 | 0.431 | 0.408 | 0.381 | 0.353 |
| 0.3 | 0.481 | 0.444 | 0.401 | 0.354 | 0.293 | 0.277 |
| 0.4 | 0.476 | 0.431 | 0.368 | 0.283 | 0.226 | 0.165 |
| 0.5 | 0.474 | 0.403 | 0.317 | 0.228 | 0.153 | 0.092 |
| 0.6 | 0.473 | 0.389 | 0.266 | 0.169 | 0.096 | 0.060 |
| ResNet | 0.1 | 0.934 | 0.926 | 0.908 | 0.893 | 0.876 | 0.859 |
| 0.2 | 0.925 | 0.909 | 0.876 | 0.845 | 0.808 | 0.760 |
| 0.3 | 0.927 | 0.899 | 0.838 | 0.749 | 0.664 | 0.588 |
| 0.4 | 0.924 | 0.884 | 0.782 | 0.668 | 0.551 | 0.453 |
| 0.5 | 0.921 | 0.855 | 0.727 | 0.580 | 0.430 | 0.331 |
| 0.6 | 0.915 | 0.84 | 0.698 | 0.500 | 0.382 | 0.273 |
), ArticleFig(id=1190013544323186888, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.4, caption=
Comparison of no misclassify the accuracy of the specified target (A t)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 1.000 | 1.000 | 1.000 | 0.999 | 0.999 | 0.998 |
| 0.2 | 1.000 | 1.000 | 0.998 | 0.998 | 0.992 | 0.983 |
| 0.3 | 0.999 | 0.999 | 0.993 | 0.977 | 0.945 | 0.938 |
| 0.4 | 1.000 | 0.997 | 0.977 | 0.919 | 0.880 | 0.803 |
| 0.5 | 1.000 | 0.994 | 0.952 | 0.879 | 0.760 | 0.641 |
| 0.6 | 1.000 | 0.982 | 0.905 | 0.790 | 0.639 | 0.575 |
| ResNet | 0.1 | 1.000 | 1.000 | 1.000 | 1.000 | 0.998 | 0.997 |
| 0.2 | 1.000 | 1.000 | 1.000 | 1.000 | 0.997 | 0.984 |
| 0.3 | 1.000 | 1.000 | 1.000 | 0.997 | 0.975 | 0.956 |
| 0.4 | 1.000 | 1.000 | 0.999 | 0.985 | 0.930 | 0.849 |
| 0.5 | 1.000 | 0.999 | 0.997 | 0.965 | 0.863 | 0.749 |
| 0.6 | 1.000 | 1.000 | 0.994 | 0.941 | 0.828 | 0.711 |
), ArticleFig(id=1190013544440627401, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表4, caption=
未误分类指定目标的准确率(A t)对比
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 1.000 | 1.000 | 1.000 | 0.999 | 0.999 | 0.998 |
| 0.2 | 1.000 | 1.000 | 0.998 | 0.998 | 0.992 | 0.983 |
| 0.3 | 0.999 | 0.999 | 0.993 | 0.977 | 0.945 | 0.938 |
| 0.4 | 1.000 | 0.997 | 0.977 | 0.919 | 0.880 | 0.803 |
| 0.5 | 1.000 | 0.994 | 0.952 | 0.879 | 0.760 | 0.641 |
| 0.6 | 1.000 | 0.982 | 0.905 | 0.790 | 0.639 | 0.575 |
| ResNet | 0.1 | 1.000 | 1.000 | 1.000 | 1.000 | 0.998 | 0.997 |
| 0.2 | 1.000 | 1.000 | 1.000 | 1.000 | 0.997 | 0.984 |
| 0.3 | 1.000 | 1.000 | 1.000 | 0.997 | 0.975 | 0.956 |
| 0.4 | 1.000 | 1.000 | 0.999 | 0.985 | 0.930 | 0.849 |
| 0.5 | 1.000 | 0.999 | 0.997 | 0.965 | 0.863 | 0.749 |
| 0.6 | 1.000 | 1.000 | 0.994 | 0.941 | 0.828 | 0.711 |
), ArticleFig(id=1190013544520319178, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.5, caption=
Comparison of average Lp distortion (ALD _2)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 0.024 | 0.047 | 0.070 | 0.093 | 0.116 | 0.138 |
| 0.2 | 0.034 | 0.068 | 0.101 | 0.134 | 0.167 | 0.199 |
| 0.3 | 0.042 | 0.084 | 0.125 | 0.166 | 0.207 | 0.245 |
| 0.4 | 0.084 | 0.096 | 0.144 | 0.191 | 0.234 | 0.274 |
| 0.5 | 0.055 | 0.109 | 0.162 | 0.213 | 0.255 | 0.281 |
| 0.6 | 0.059 | 0.118 | 0.176 | 0.228 | 0.259 | 0.282 |
| ResNet | 0.1 | 0.023 | 0.047 | 0.070 | 0.093 | 0.115 | 0.137 |
| 0.2 | 0.034 | 0.068 | 0.101 | 0.133 | 0.165 | 0.194 |
| 0.3 | 0.042 | 0.084 | 0.124 | 0.161 | 0.194 | 0.222 |
| 0.4 | 0.048 | 0.098 | 0.140 | 0.179 | 0.214 | 0.242 |
| 0.5 | 0.055 | 0.107 | 0.155 | 0.198 | 0.235 | 0.263 |
| 0.6 | 0.059 | 0.116 | 0.166 | 0.213 | 0.250 | 0.278 |
), ArticleFig(id=1190013544608399563, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表5, caption=
对抗攻击失真度(ALD _2)对比
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器类型 | 补丁面积 | 10 | 20 | 30 | 40 | 50 | 60 |
| VggNet | 0.1 | 0.024 | 0.047 | 0.070 | 0.093 | 0.116 | 0.138 |
| 0.2 | 0.034 | 0.068 | 0.101 | 0.134 | 0.167 | 0.199 |
| 0.3 | 0.042 | 0.084 | 0.125 | 0.166 | 0.207 | 0.245 |
| 0.4 | 0.084 | 0.096 | 0.144 | 0.191 | 0.234 | 0.274 |
| 0.5 | 0.055 | 0.109 | 0.162 | 0.213 | 0.255 | 0.281 |
| 0.6 | 0.059 | 0.118 | 0.176 | 0.228 | 0.259 | 0.282 |
| ResNet | 0.1 | 0.023 | 0.047 | 0.070 | 0.093 | 0.115 | 0.137 |
| 0.2 | 0.034 | 0.068 | 0.101 | 0.133 | 0.165 | 0.194 |
| 0.3 | 0.042 | 0.084 | 0.124 | 0.161 | 0.194 | 0.222 |
| 0.4 | 0.048 | 0.098 | 0.140 | 0.179 | 0.214 | 0.242 |
| 0.5 | 0.055 | 0.107 | 0.155 | 0.198 | 0.235 | 0.263 |
| 0.6 | 0.059 | 0.116 | 0.166 | 0.213 | 0.250 | 0.278 |
), ArticleFig(id=1190013544679702732, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.6, caption=
Comparison of ablation study(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 方法 | A a | A t | ALD _2 | Ave |
| 本文方法 | 0.060 | 0.575 | 0.282 | 0.701 |
| 本文方法-L target | 0.077 | 1.000 | 0.346 | 0.558 |
| 本文方法-L ori | 0.081 | 0.602 | 0.266 | 0.696 |
| 本文方法-P G | 0.089 | 1.000 | 0.345 | 0.556 |
), ArticleFig(id=1190013544771977421, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表6, caption=
消融试验对比(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 方法 | A a | A t | ALD _2 | Ave |
| 本文方法 | 0.060 | 0.575 | 0.282 | 0.701 |
| 本文方法-L target | 0.077 | 1.000 | 0.346 | 0.558 |
| 本文方法-L ori | 0.081 | 0.602 | 0.266 | 0.696 |
| 本文方法-P G | 0.089 | 1.000 | 0.345 | 0.556 |
), ArticleFig(id=1190013544876835022, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.7, caption=
Comparison of various indicators(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器 | A b | A a | A t | ALD _2 | Ave |
| VggNet | 0.957 | 0.060 | 0.575 | 0.282 | 0.701 |
| VggNet-split | 0.957 | 0.124 | 0.757 | 0.290 | 0.635 |
), ArticleFig(id=1190013544956526799, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表7, caption=
各项指标对比(β=0.5)
, figureFileSmall=null, figureFileBig=null, tableContent=
| 分类器 | A b | A a | A t | ALD _2 | Ave |
| VggNet | 0.957 | 0.060 | 0.575 | 0.282 | 0.701 |
| VggNet-split | 0.957 | 0.124 | 0.757 | 0.290 | 0.635 |
), ArticleFig(id=1190013545036218576, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=EN, label=Tab.8, caption=
Comparison of object detection and recognition
, figureFileSmall=null, figureFileBig=null, tableContent=
| 方法 | Class | P | R | mAP@0.5 | mAP@0.5:0.95 |
| Yolov5 | boat | 0.522 | 0.337 | 0.397 | 0.297 |
| Yolov5 w/本文 | boat | 0.269 | 0.162 | 0.168 | 0.115 |
), ArticleFig(id=1190013545128493265, tenantId=1146029695717560320, journalId=1146119989267898375, articleId=1189585008365921270, language=CN, label=表8, caption=
目标检测与识别任务补丁攻击效果对比
, figureFileSmall=null, figureFileBig=null, tableContent=
| 方法 | Class | P | R | mAP@0.5 | mAP@0.5:0.95 |
| Yolov5 | boat | 0.522 | 0.337 | 0.397 | 0.297 |
| Yolov5 w/本文 | boat | 0.269 | 0.162 | 0.168 | 0.115 |
)], attaches=null, journal=Journal(id=1146118917132496903, delFlag=0, nameCn=导弹与航天运载技术(中英文), nameEn=Missiles and Space Vehicles, nameHistory1=null, nameHistory2=null, issn=2097-1974, eissn=, cn=10-1807/V, coden=null, periodic=1, language=CN, oaType=否, ccby=null, superviseOffice=null, ownerOffice=null, pubOffice=null, editorOffice=null, officeType=null, aims=null, clcCode=null, officeProv=null, officeCity=null, officeAddr=null, officeZip=null, officeEmail=null, officePhone=null, editDirector=null, officeDirector=null, officeDirectorPhone=null, officeStaffNum=null, officeEmpNum=null, coverPicUrl=DdfacUcWE1ibGHaCsbhL8w==, journalPrice=null, startedYear=null, abbrevIsoEn=Miss Space Veh, journalRemark=null, publicationField=null, createdTime=null, updatedTime=1753780023753, createdBy=null, updatedBy=13701087609, firstLetterCn=M, firstLetterEn=M, subjectCode=Engineering, subjectName=工程, subjectCodeEn=Engineering, subjectNameEn=null, picCn=DdfacUcWE1ibGHaCsbhL8w==, picEn=jBog3LY3UHfAAYfYEqIBHg==, jcr=null, cjcr=null, exts=[JournalExt(id=1157000535829205111, language=CN, name=导弹与航天运载技术(中英文), nameHistory1=null, nameHistory2=null, managedBy=, sponsoredBy=, publishedBy=, editorOffice=, officeProv=null, officeCity=null, officeAddr=, officeZip=, editDirector=null, officeDirector=null, officePhone=null, coverPicUrl=null, journalRemark=, submitArticleUrl=null, websiteUrl=, createdTime=1753780023772, updatedTime=1753780023772, createdBy=13701087609, updatedBy=13701087609, submissionGuidelinesUrl=null, submissionAuthorUrl=https://journal.ids.fzyun.cn/auth/realms/journal/protocol/openid-connect/auth?client_id=journal-ddht-author&redirect_uri=https%3A%2F%2Fddht.portal.founderss.cn%2Foauth%2Fcallback&response_type=code&scope=phone+openid+email+profile&state=fefa73ea-30bb-4b68, submissionEditorUrl=https://journal.ids.fzyun.cn/auth/realms/journal/protocol/openid-connect/auth?client_id=journal-ddht-author&redirect_uri=https%3A%2F%2Fddht.portal.founderss.cn%2Foauth%2Fcallback&response_type=code&scope=phone+openid+email+profile&state=fefa73ea-30bb-4b68, submissionReviewUrl=https://journal.ids.fzyun.cn/auth/realms/journal/protocol/openid-connect/auth?client_id=journal-ddht-author&redirect_uri=https%3A%2F%2Fddht.portal.founderss.cn%2Foauth%2Fcallback&response_type=code&scope=phone+openid+email+profile&state=fefa73ea-30bb-4b68, submissionCeEditorUrl=https://journal.ids.fzyun.cn/auth/realms/journal/protocol/openid-connect/auth?client_id=journal-ddht-author&redirect_uri=https%3A%2F%2Fddht.portal.founderss.cn%2Foauth%2Fcallback&response_type=code&scope=phone+openid+email+profile&state=fefa73ea-30bb-4b68, submissionAeEditorUrl=https://journal.ids.fzyun.cn/auth/realms/journal/protocol/openid-connect/auth?client_id=journal-ddht-author&redirect_uri=https%3A%2F%2Fddht.portal.founderss.cn%2Foauth%2Fcallback&response_type=code&scope=phone+openid+email+profile&state=fefa73ea-30bb-4b68, option={"copyright":""}), JournalExt(id=1157000535871148152, language=EN, name=Missiles and Space Vehicles, nameHistory1=null, nameHistory2=null, managedBy=, sponsoredBy=, publishedBy=, editorOffice=, officeProv=null, officeCity=null, officeAddr=, officeZip=, editDirector=null, officeDirector=null, officePhone=null, coverPicUrl=null, journalRemark=, submitArticleUrl=null, websiteUrl=, createdTime=1753780023782, updatedTime=1753780023782, createdBy=13701087609, updatedBy=13701087609, submissionGuidelinesUrl=null, submissionAuthorUrl=https://journal.ids.fzyun.cn/auth/realms/journal/protocol/openid-connect/auth?client_id=journal-ddht-author&redirect_uri=https%3A%2F%2Fddht.portal.founderss.cn%2Foauth%2Fcallback&response_type=code&scope=phone+openid+email+profile&state=fefa73ea-30bb-4b68, submissionEditorUrl=, submissionReviewUrl=, submissionCeEditorUrl=, submissionAeEditorUrl=, option={"copyright":""})], databaseList=null, tenantJournalId=1146119989267898375, websiteList=[Website(id=1148243202378817956, webName=null, webTitle=null, webDomain=null, webCopyrigh=null, webIpcNo=null, seoTitle=null, seoKeywords=null, seoDescription=null, tenantJournalId=null, journalId=1146119989267898375, journalNameCn=null, journalNameEn=null, grayFlag=null, tenantId=1146029695717560320, platformId=null, journalGroupId=null, journalGroupNameCn=null, journalGroupNameEn=null, type=1, domain=https://castjournals.cast.org.cn/joweb/ddyht/CN, language=CN, createTime=1751692112774, createBy=18614031015, updateTime=1753519037132, updateBy=18614031015, name=导弹与航天运载技术-中文站点, tplId=1146099689490845704, title=导弹与航天运载技术(中英文), delFlag=0, indexPage=/home, props=[WebsiteProps(id=1148620442723704855, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202378817956, code=articleTextType, value=kx, createTime=1751782053881, updateTime=1751782053881, creator=18614031015, updator=18614031015), WebsiteProps(id=1148620442694344724, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202378817956, code=banner, value=null, createTime=1751782053874, updateTime=1751782053874, creator=18614031015, updator=18614031015), WebsiteProps(id=1148620442677567507, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202378817956, code=logo, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic?fileId=gfUyzanfTuxQ2yc+L/MeWA==, createTime=1751782053870, updateTime=1751782053870, creator=18614031015, updator=18614031015), WebsiteProps(id=1148620442711121942, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202378817956, code=picServerUrl, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic, createTime=1751782053878, updateTime=1751782053878, creator=18614031015, updator=18614031015), WebsiteProps(id=1148620442706927637, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202378817956, code=staticResourcePath, value=https://castjournals.cast.org.cn/joweb/cast_kjdb_cn_619/, createTime=1751782053877, updateTime=1751782053877, creator=18614031015, updator=18614031015)]), Website(id=1155906039850618895, webName=null, webTitle=null, webDomain=null, webCopyrigh=null, webIpcNo=null, seoTitle=null, seoKeywords=null, seoDescription=null, tenantJournalId=null, journalId=1146119989267898375, journalNameCn=null, journalNameEn=null, grayFlag=null, tenantId=1146029695717560320, platformId=null, journalGroupId=null, journalGroupNameCn=null, journalGroupNameEn=null, type=1, domain=https://castjournals.cast.org.cn/joweb/ddyht/EN, language=EN, createTime=1753519075604, createBy=18614031015, updateTime=1753519075604, updateBy=18614031015, name=导弹与航天运载技术-英文站点, tplId=1146101810881728533, title=Missiles and Space Vehicles, delFlag=0, indexPage=/home, props=[WebsiteProps(id=1155907112585777347, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155906039850618895, code=articleTextType, value=kx, createTime=1753519331356, updateTime=1753519331356, creator=18614031015, updator=18614031015), WebsiteProps(id=1155907112556417216, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155906039850618895, code=banner, value=null, createTime=1753519331349, updateTime=1753519331349, creator=18614031015, updator=18614031015), WebsiteProps(id=1155907112552222911, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155906039850618895, code=logo, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic?fileId=gfUyzanfTuxQ2yc+L/MeWA==, createTime=1753519331348, updateTime=1753519331348, creator=18614031015, updator=18614031015), WebsiteProps(id=1155907112577388738, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155906039850618895, code=picServerUrl, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic, createTime=1753519331354, updateTime=1753519331354, creator=18614031015, updator=18614031015), WebsiteProps(id=1155907112564805825, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155906039850618895, code=staticResourcePath, value=https://castjournals.cast.org.cn/joweb/cast_kjdb_cn_619/, createTime=1753519331351, updateTime=1753519331351, creator=18614031015, updator=18614031015)])], journalTitle=导弹与航天运载技术(中英文), weixinUrl=null, journalUrl=null, iacademicId=null, status=0, seqNo=null, journalTitleEn=Missiles and Space Vehicles, journalPhotoCn=DdfacUcWE1ibGHaCsbhL8w==, journalPhotoEn=jBog3LY3UHfAAYfYEqIBHg==, journalFirstLetter=M, journalRecommend=null, journalNew=null, journalCollection=null, jcrJf=null, cjcrJf=null, jcrJfStr=null, cjcrJfStr=null, submissionFirstDecision=null, sciSubjectClassification=null, casSubjectClassification=null, citeScore=null, totalCitationFrequency=null, icpCode=null, psCode=null, advertisingLicenseCode=null, copyrightInformation=null, country=null, option=null, provinceCode=null, provinceName=null, collectFlag=false), detailUrlCn=https://castjournals.cast.org.cn/joweb/ddyht/CN/10.7654/j.issn.2097-1974.20250405, detailUrlEn=https://castjournals.cast.org.cn/joweb/ddyht/EN/10.7654/j.issn.2097-1974.20250405, pdfUrlCn=https://castjournals.cast.org.cn/joweb/ddyht/CN/PDF/10.7654/j.issn.2097-1974.20250405, pdfUrlEn=https://castjournals.cast.org.cn/joweb/ddyht/EN/PDF/10.7654/j.issn.2097-1974.20250405, aliStartDate=null, aliEndDate=null, collectionFlag=false, citedCount=null, citedUrl=null, reference=null)