Skip to content
Open access

Gradient-guided hierarchical feature attack for object detector

Jan 2024 · Journal of King Saud University: Computer and Information Sciences · Vol 36, pp. 101901 · 3 citations · 45 references
Computer Science

TL;DR

Gradient-guided Hierarchical Feature Attack (GHFA) is proposed to solve problems, which disrupts detector-extracted features using gradient-guided feature weighting and incorporates receptive field scaling and gradient scaling to balance the focus among feature maps and enhance attack performance.

Abstract

Deep neural networks (DNNs) are vulnerable to adversarial attacks, which can cause security risks in computer information systems. Feature disruption attacks, as a typical form of adversarial attack, optimize adversarial examples by disrupting the intermediate features extracted by DNN. The existing feature disruption attacks have limitations when it comes to objects of different scales within resolution features, favoring low-resolution feature maps and low-scoring objects. The imbalance above affects their effectiveness in object detection tasks. Gradient-guided Hierarchical Feature Attack (GHFA) is proposed to solve these problems, which disrupts detector-extracted features using gradient-guided feature weighting. GHFA incorporates receptive field scaling and gradient scaling to balance the focus among feature maps and enhance attack performance. The evaluation of GHFA on 9 object detectors demonstrates its superior transferability compared with the 6 comparative methods, surpassing the second-ranked method by 2.4%. Furthermore, the real-world applicability of GHFA is validated available by testing it on a commercial online object detection platform.

Read PDF

Similar papers

Review Aug 2026

A Comprehensive Review on Adversarial Attacks and Detection Techniques in Deep Learning Models for Image Analysis

The research methodology involved a systematic literature review using the Scopus database, adhering to Preferred Reporting Items for Systematic Reviews and Meta-Analyses guidelines, and focusing on recent advancements in attack and defence techniques.

Reeti Jaswal, Vikas Khullar, Surya Narayan Panda · 0 citations
Preprint Aug 2026

Multi-Task Consistency-based Detection of Adversarial Attacks

This work proposes an efficient and effective adversarial attack detection scheme leveraging the multi-task perception within a complex vision system, and develops a consistency score metric to measure the inconsistency between vision tasks.

Cong Chen, J. Monteuuis, Jonathan Petit · 0 citations
Sep 2026

Seeing Through Threats: (ADEx) Adversarial Detection through Explainability.

Deep Neural Networks (DNNs) remain vulnerable to adversarial perturbations, raising significant concerns in image processing applications, particularly in high-stakes domains such as medical imaging and security-critical systems. Most existing defense strategies are limited by domain specificity, architectural dependence, or the need for extensive retraining, making them impractical for real-world deployment. In this work, we propose ADEx, the first framework to integrate low-rank image approximation with explainability-driven analysis for the detection of adversarial samples. ADEx works by extracting a low-rank representation of the input image using Singular Value Thresholding (SVT), and identifying important image regions by computing class-specific gradient maps from the final layers of the classifier. These maps are then compared using Rank-Biased Overlap (RBO) to quantify the degree of attention drift induced by adversarial perturbations. ADEx is designed for adversarial detection in image classification systems, where class-specific gradient-based explanations are well defined. The framework operates without retraining or architectural modification and can be applied to a wide range of differentiable classifiers, provided gradient access is available for explanation generation. Extensive experiments across multiple datasets, architectures, and attack types demonstrate consistent performance, robustness to hyperparameter choices, and low sensitivity to calibration size. The method provides an interpretable and lightweight solution suitable for practical deployment.

Syamantak Sarkar, Nirmal Joseph, Sudhish N. George et al. · 0 citations
Open access Aug 2026

Enhanced Robustness in Neural Network Models against Adversarial Attacks and their Performance Analysis

Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance.

Surekha M., A. K. Sagar, Vineeta Khemchandani · 0 citations
Conference Aug 2026

Ada-MGNS: Enhancing Black-Box Transfer Attacks on Vision Transformers via Adaptive Momentum and Deep Attention Guidance

Transfer-based black-box attacks are an important tool for evaluating deployed vision models, yet adversarial examples generated from Vision Transformer (ViT) surrogates often exhibit limited cross-architecture transferability. Existing momentum-based attacks are effective for convolutional neural network (CNN) surrogates, but they can accumulate stale directions and overfit the surrogate when the source model is a ViT. This paper presents Ada-MGNS, a ViToriented transferable attack that combines adaptive momentum with deep attention guidance. The adaptive component measures the directional discrepancy between the current guided gradient and the accumulated trajectory, and then attenuates stale momentum when the search direction becomes unstable. The guidance component fuses the classification gradient with an auxiliary gradient extracted from the last transformer block’s attention responses, encouraging perturbations to disturb both output decisions and semantic aggregation. Experiments on ImageNet with four ViT surrogates, thirteen standard black-box targets, and five defense models show that Ada-MGNS consistently improves attack success rates over representative ViT-specific baselines, remains compatible with DI/TI transformations and effective against adversarially trained and purification-based defenses.

Lei Lu, Run-Han Yao, Qinghe Du et al. · 0 citations
Sep 2026

EGP-Defense: Enhancing Adversarial Robustness of LVLMs via Training-Free Edge-Guided Prompting

Large Vision-Language Models (LVLMs) have demonstrated remarkable multimodal comprehension capabilities, achieving state-of-the-art performance across various vision-language tasks. However, their performance drops significantly when facing adversarial attacks on the visual encoder. To alleviate this issue, existing approaches often rely on adversarial training, enhancing model robustness through substantial computational cost. Unlike these methods, this paper proposes a novel, training-free adversarial defense method called Edge-Guided Prompt Defense (EGP-Defense), which performs adversarial defense during the model inference stage. This method is based on a comprehensive analysis of image edges under various types of attacks. We observe that edge maps exhibit strong robustness against adversarial attacks, and the extracted edge features can effectively reflect key aspects of the original image. Building on this observation, we first apply the Canny operator to extract edge maps from input images, and then use LVLMs to generate textual descriptions based on these structural representations. To further distill the most critical information from these descriptions, we extract informative keywords and incorporate them as auxiliary prompts. These prompts guide the model to focus on task-relevant features during inference, thereby enhancing its robustness against adversarial perturbations. Extensive experiments demonstrate that EGP-Defense significantly improves the robustness of LVLMs against three types of adversarial attacks in both image classification and image caption tasks.

Bo-Yu Wang, Zi-Wen He, Xin-Jue Hu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.