Home Technology peripherals AI Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Sep 11, 2023 pm 06:53 PM
theory visual perception Visible Light - Thermal Infrared Imaging

In recent years, the exploration of safety assessment of visual perception systems has gradually deepened. Researchers have successfully implemented visible light modal safety assessment technology based on different carriers such as glasses, stickers, clothes, etc., and there are also some new attempts targeting infrared modalities. . But they can only work in a single mode.


With the development of artificial intelligence technology, visible light-thermal infrared imaging technology has been used in many safety-critical tasks such as security monitoring and autonomous driving. Among them, visible light imaging can It provides rich texture information during the day, and infrared imaging can clearly display the thermal radiation distribution of the target at night. The combination of the two brings many advantages to the visual perception system, such as 24-hour full coverage and freedom from environmental limitations. Therefore, a unified security assessment method for multi-modal visual perception systems is also urgently needed to be studied.

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

However, achieving multimodal assessment is extremely challenging. First of all, it is difficult to universally apply attack methods under different imaging mechanisms. Previous methods were proposed based on the imaging characteristics of specific target modalities, and are difficult to work in other modalities. Furthermore, it is difficult to balance stealth performance, production cost and flexible application. It is not easy to be dual effective in visible light and the more difficult infrared mode, and it is even more difficult to achieve low-cost and convenient production and use.

Faced with many challenges, researchers from the Beihang Institute of Artificial Intelligence explored the common shape attributes between visible light and infrared modes, and innovatively proposed "cross- Modal universal countermeasure patch" to achieve visible-infrared synchronized stealth. It selects materials that are easy to obtain, low cost, and have excellent thermal insulation properties to make convenient patches, which are ready to use. While filling the gaps in the robustness evaluation technology of visible light-infrared multi-modal detection systems in the current physical world, it also takes into account The ease and immediacy of physical implementation. Experiments demonstrate the effectiveness of this method under different detection models and modalities, as well as its generalization in multiple scenarios. Currently, this paper has been accepted by ICCV 2023.
Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.


Paper link: https://arxiv.org/abs/2307.07859
Code link: https://github.com/Aries-iai/Cross-modal_Patch_Attack

Technical points

This research uses evolutionary algorithm as The basic framework is based on the three perspectives of shape modeling, shape optimization, and modal balance for program design and effect improvement. The specific process is as shown in the figure:
Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

##1. Multi-anchor shape modeling based on spline interpolation

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.
For the basics For the shape modeling part, the researchers designed a new paradigm of point optimization modeling, which can directly adjust the patch shape by changing the point coordinates. In this process, the movement of the anchor point will not be restricted by direction, distance, etc., effectively increasing the search for patch shapes. space. On this basis, in order to ensure the naturalness of the shape, it also uses the spline interpolation method to achieve smooth connections, and the splines will follow the control points more closely.

2. Boundary-limited shape optimization algorithm based on differential evolution

Effective optimization means are required to implement the attack. This researcher considered the time cost, actual effect, etc., used the evolutionary algorithm as the basic framework, and improved it from the two perspectives of boundary setting and fitness function:

( 1) Boundary setting: Boundary setting for anchor points improves the effectiveness of deformation and reduces time costs. It has the following settings: no loops or self-intersections will be formed in the curve segment; cusps will not easily appear in the curve segment; and they will not appear in the invalid area.

Take the anchor point
as an example. The blue part in the figure below is the boundary setting legend, and the orange part is the error instance: Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.
About the boundary determination of the anchor point
Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes. The mathematical expression is as follows: Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.
(2) Fitness function: Unlike previous work that only targets a single mode for attack evaluation, this work focuses on the two modes of visible light and infrared, and there is a natural problem of balancing the differences in modal effects. . Therefore, in order to avoid going to the extreme of easily optimizing a single mode, the researchers innovatively proposed a cross-modal fitness function based on detector confidence score perception, encouraging the exploration of successful directions while balancing the difference in the effects of the two modes, and finally the survival of the fittest based on scores. Taking into account the difference in attack difficulty between the initial stage and the later stage, it uses an exponential function instead of a linear function to highlight the difference in attack progress in different stages.
Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.##                                                                                                                                                                   ’ ’ s to ’ s ’ ’ s ’ s ’ s ’ s ‐ ‐ ‐ ‐ ‐ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​
The algorithm iterates the exploration process until both modes successfully attack, and outputs the optimal shape strategy.The complete optimization process is as follows:

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

##Experimental results

Experiment 1: Cross-modal attack performance verification for different series of detectors

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Experiment 2: Shape ablation experiment

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

##Experiment 3: Ablation experiment for cross-modal fitness function

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Experiment 4: Method robustness verification under physical implementation deviation

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Experiment 5: Validation of method effectiveness under different physical conditions

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.

Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.##Performance verification visualization results under different angles, distances, postures, and scenarios

##Summary
##The work of this paper is based on natural shape optimization. Combining deformation patches with cross-modal attacks, a visible-infrared multi-modal robustness evaluation method in physical environments is designed. This method can evaluate the robustness of a multi-modal (visible light-infrared) target detection system, effectively correct the detector model based on the evaluation results, and simultaneously improve the accuracy of target image detection in both visible light and infrared modes. In physics It can be truly implemented and applied in the environment, and contribute to the robustness evaluation and improvement of multi-modal detection systems.

The above is the detailed content of Beihang University breaks down modal barriers and introduces a universal physical counterattack method across visible and infrared modes.. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Breaking through the boundaries of traditional defect detection, 'Defect Spectrum' achieves ultra-high-precision and rich semantic industrial defect detection for the first time. Breaking through the boundaries of traditional defect detection, 'Defect Spectrum' achieves ultra-high-precision and rich semantic industrial defect detection for the first time. Jul 26, 2024 pm 05:38 PM

In modern manufacturing, accurate defect detection is not only the key to ensuring product quality, but also the core of improving production efficiency. However, existing defect detection datasets often lack the accuracy and semantic richness required for practical applications, resulting in models unable to identify specific defect categories or locations. In order to solve this problem, a top research team composed of Hong Kong University of Science and Technology Guangzhou and Simou Technology innovatively developed the "DefectSpectrum" data set, which provides detailed and semantically rich large-scale annotation of industrial defects. As shown in Table 1, compared with other industrial data sets, the "DefectSpectrum" data set provides the most defect annotations (5438 defect samples) and the most detailed defect classification (125 defect categories

Training with millions of crystal data to solve the crystallographic phase problem, the deep learning method PhAI is published in Science Training with millions of crystal data to solve the crystallographic phase problem, the deep learning method PhAI is published in Science Aug 08, 2024 pm 09:22 PM

Editor |KX To this day, the structural detail and precision determined by crystallography, from simple metals to large membrane proteins, are unmatched by any other method. However, the biggest challenge, the so-called phase problem, remains retrieving phase information from experimentally determined amplitudes. Researchers at the University of Copenhagen in Denmark have developed a deep learning method called PhAI to solve crystal phase problems. A deep learning neural network trained using millions of artificial crystal structures and their corresponding synthetic diffraction data can generate accurate electron density maps. The study shows that this deep learning-based ab initio structural solution method can solve the phase problem at a resolution of only 2 Angstroms, which is equivalent to only 10% to 20% of the data available at atomic resolution, while traditional ab initio Calculation

NVIDIA dialogue model ChatQA has evolved to version 2.0, with the context length mentioned at 128K NVIDIA dialogue model ChatQA has evolved to version 2.0, with the context length mentioned at 128K Jul 26, 2024 am 08:40 AM

The open LLM community is an era when a hundred flowers bloom and compete. You can see Llama-3-70B-Instruct, QWen2-72B-Instruct, Nemotron-4-340B-Instruct, Mixtral-8x22BInstruct-v0.1 and many other excellent performers. Model. However, compared with proprietary large models represented by GPT-4-Turbo, open models still have significant gaps in many fields. In addition to general models, some open models that specialize in key areas have been developed, such as DeepSeek-Coder-V2 for programming and mathematics, and InternVL for visual-language tasks.

Google AI won the IMO Mathematical Olympiad silver medal, the mathematical reasoning model AlphaProof was launched, and reinforcement learning is so back Google AI won the IMO Mathematical Olympiad silver medal, the mathematical reasoning model AlphaProof was launched, and reinforcement learning is so back Jul 26, 2024 pm 02:40 PM

For AI, Mathematical Olympiad is no longer a problem. On Thursday, Google DeepMind's artificial intelligence completed a feat: using AI to solve the real question of this year's International Mathematical Olympiad IMO, and it was just one step away from winning the gold medal. The IMO competition that just ended last week had six questions involving algebra, combinatorics, geometry and number theory. The hybrid AI system proposed by Google got four questions right and scored 28 points, reaching the silver medal level. Earlier this month, UCLA tenured professor Terence Tao had just promoted the AI ​​Mathematical Olympiad (AIMO Progress Award) with a million-dollar prize. Unexpectedly, the level of AI problem solving had improved to this level before July. Do the questions simultaneously on IMO. The most difficult thing to do correctly is IMO, which has the longest history, the largest scale, and the most negative

PRO | Why are large models based on MoE more worthy of attention? PRO | Why are large models based on MoE more worthy of attention? Aug 07, 2024 pm 07:08 PM

In 2023, almost every field of AI is evolving at an unprecedented speed. At the same time, AI is constantly pushing the technological boundaries of key tracks such as embodied intelligence and autonomous driving. Under the multi-modal trend, will the situation of Transformer as the mainstream architecture of AI large models be shaken? Why has exploring large models based on MoE (Mixed of Experts) architecture become a new trend in the industry? Can Large Vision Models (LVM) become a new breakthrough in general vision? ...From the 2023 PRO member newsletter of this site released in the past six months, we have selected 10 special interpretations that provide in-depth analysis of technological trends and industrial changes in the above fields to help you achieve your goals in the new year. be prepared. This interpretation comes from Week50 2023

Nature's point of view: The testing of artificial intelligence in medicine is in chaos. What should be done? Nature's point of view: The testing of artificial intelligence in medicine is in chaos. What should be done? Aug 22, 2024 pm 04:37 PM

Editor | ScienceAI Based on limited clinical data, hundreds of medical algorithms have been approved. Scientists are debating who should test the tools and how best to do so. Devin Singh witnessed a pediatric patient in the emergency room suffer cardiac arrest while waiting for treatment for a long time, which prompted him to explore the application of AI to shorten wait times. Using triage data from SickKids emergency rooms, Singh and colleagues built a series of AI models that provide potential diagnoses and recommend tests. One study showed that these models can speed up doctor visits by 22.3%, speeding up the processing of results by nearly 3 hours per patient requiring a medical test. However, the success of artificial intelligence algorithms in research only verifies this

To provide a new scientific and complex question answering benchmark and evaluation system for large models, UNSW, Argonne, University of Chicago and other institutions jointly launched the SciQAG framework To provide a new scientific and complex question answering benchmark and evaluation system for large models, UNSW, Argonne, University of Chicago and other institutions jointly launched the SciQAG framework Jul 25, 2024 am 06:42 AM

Editor |ScienceAI Question Answering (QA) data set plays a vital role in promoting natural language processing (NLP) research. High-quality QA data sets can not only be used to fine-tune models, but also effectively evaluate the capabilities of large language models (LLM), especially the ability to understand and reason about scientific knowledge. Although there are currently many scientific QA data sets covering medicine, chemistry, biology and other fields, these data sets still have some shortcomings. First, the data form is relatively simple, most of which are multiple-choice questions. They are easy to evaluate, but limit the model's answer selection range and cannot fully test the model's ability to answer scientific questions. In contrast, open-ended Q&A

The accuracy rate reaches 60.8%. Zhejiang University's chemical retrosynthesis prediction model based on Transformer was published in the Nature sub-journal The accuracy rate reaches 60.8%. Zhejiang University's chemical retrosynthesis prediction model based on Transformer was published in the Nature sub-journal Aug 06, 2024 pm 07:34 PM

Editor | KX Retrosynthesis is a critical task in drug discovery and organic synthesis, and AI is increasingly used to speed up the process. Existing AI methods have unsatisfactory performance and limited diversity. In practice, chemical reactions often cause local molecular changes, with considerable overlap between reactants and products. Inspired by this, Hou Tingjun's team at Zhejiang University proposed to redefine single-step retrosynthetic prediction as a molecular string editing task, iteratively refining the target molecular string to generate precursor compounds. And an editing-based retrosynthetic model EditRetro is proposed, which can achieve high-quality and diverse predictions. Extensive experiments show that the model achieves excellent performance on the standard benchmark data set USPTO-50 K, with a top-1 accuracy of 60.8%.

See all articles