ARMOR:数据稀缺条件下面向流形的对抗鲁棒航拍目标检测训练
ARMOR: Manifold-Oriented Training for Adversarially Robust Aerial Object Detection under Data Scarcity
浏览论文内容
中文总结 AI 辅助
ARMOR 是一种面向流形的新型防御方法,通过掩码图像背景、在目标上注入随机补丁,在数据稀缺时提升航拍目标检测器的对抗鲁棒性,维持强干净性能且优于现有最优防御。
中文摘要 AI 辅助
航拍目标检测正越来越多地应用于实际场景,但模型仍易受物理通用对抗补丁影响,导致漏检目标。此外,防御者面临训练数据稀缺的实际约束:航拍图像的收集与标注成本高昂,部署站点通常仅能获取数百张图像,而非对抗鲁棒性基准所假设的数万张。为解决模型脆弱性与训练数据稀缺问题,我们提出面向流形的对抗鲁棒训练(Adversarial Robustness with Manifold-Oriented Training,ARMOR),这是一种在低数据 regime 下实现流形上对抗训练(On-Manifold Adversarial Training,OMAT)核心见解的新型防御方法。ARMOR 基于 OMAT 的核心思想,即建模数据流形——捕获数据相关特征的紧凑结构,在训练过程中学习并增强这些特征。OMAT 依赖于训练大型生成模型和对抗训练这类数据密集型操作来实现这一点,而 ARMOR 采用数据高效的方法,复用目标检测任务已提供的标签:ARMOR(i)掩码图像背景以保留与目标相关的特征,(ii)在目标上注入随机补丁以提升特征鲁棒性。我们使用可物理实现的对抗补丁开展低数据实验,评估无查询迁移攻击和感知防御攻击。ARMOR 维持超过 0.90 的强干净样本性能,同时比现有最优防御方法提升了最高 0.32 的对抗鲁棒性(以模型置信度衡量)。对打印补丁的物理实验证实,这些性能提升在部署后仍能保持。总体而言,ARMOR 将基于流形的训练见解转化为在训练数据稀缺条件下防御目标检测器的方案。
英文摘要
Aerial object detection is increasingly deployed in real-world applications, but models remain vulnerable to physical, universal adversarial patches that cause them to miss objects. Furthermore, defenders face the practical constraint of training data scarcity: aerial imagery is costly to collect and label, so a deployment site typically yields hundreds of images rather than the tens of thousands that adversarial robustness benchmarks assume. To tackle model vulnerability and training data scarcity, we propose Adversarial Robustness with Manifold-Oriented Training (ARMOR), a novel defense that realizes the core insights of on-manifold adversarial training (OMAT) in low-data regimes. ARMOR builds on the insight of OMAT to model the data manifold - the compact structure capturing the data's relevant features - to learn and robustify these features during training. While OMAT relies on the data-intensive operations of training large generative models and adversarial training to achieve this, ARMOR adopts a data-efficient approach that reuses labels the detection task already supplies: ARMOR (i) masks image backgrounds to retain object-relevant features, and (ii) injects randomized patches on objects to improve feature robustness. Our low-data experiments with physically-realizable adversarial patches evaluate both query-free transfer attacks and defense-aware attacks. ARMOR maintains strong clean performance of over 0.90 model confidence, while improving adversarial robustness by up to 0.32 in model confidence over state-of-the-art defenses. Physical experiments with printed patches confirm that these gains survive deployment. Overall, ARMOR translates insights from manifold-based training to defend object detectors amidst training data scarcity.
发表机构
- Georgia Institute of Technology(佐治亚理工学院)
- Khalifa University(哈利法大学)
- Technology Innovation Institute(技术创新研究院)
机构由 AI 辅助整理,请以论文原文为准。