Existing research confirms the vulnerability of deep object detection models to gradient-based adversarial patch attacks, which manipulate detection outputs through carefully crafted perturbations. This process becomes prohibitively time-consuming, especially when multiple models are integrated for adversarial training. We propose a Variable Step-size Method (VSM) that dynamically adjusts attack step sizes based on adversarial loss ratios between perturbed and clean samples. Integrating VSM with PGD and MI-FGSM frameworks enables efficient generation of adversarial patches while maintaining attack transferability. Benchmark evaluations demonstrate VSM achieves 12–15% faster convergence than state-of-the-art methods while preserving 98–102% of baseline attack success rates across mainstream detection architectures. The adaptive step-size mechanism provides superior computational efficiency over conventional fixed-step approaches without compromising attack effectiveness.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

VSM-AP: An Adversarial Patch Generation Method with Variable Step Size Mechanism for Object Detection in Aerial Images

  • Leyu Dai,
  • Jindong Wang,
  • Bo Yang,
  • Mei Wang,
  • Hengwei Zhang

摘要

Existing research confirms the vulnerability of deep object detection models to gradient-based adversarial patch attacks, which manipulate detection outputs through carefully crafted perturbations. This process becomes prohibitively time-consuming, especially when multiple models are integrated for adversarial training. We propose a Variable Step-size Method (VSM) that dynamically adjusts attack step sizes based on adversarial loss ratios between perturbed and clean samples. Integrating VSM with PGD and MI-FGSM frameworks enables efficient generation of adversarial patches while maintaining attack transferability. Benchmark evaluations demonstrate VSM achieves 12–15% faster convergence than state-of-the-art methods while preserving 98–102% of baseline attack success rates across mainstream detection architectures. The adaptive step-size mechanism provides superior computational efficiency over conventional fixed-step approaches without compromising attack effectiveness.