Empirical Investigation of Adversarial Attacks for Semi-Supervised Object Detection
Junhyung Jo, J.-H. Kim, Young-Joo Suh · 2024
Semi-supervised learning (SSL) techniques have been rapidly developed and adopted in various vision tasks because of their advantage of leveraging unlabeled data. However, existing works have neglected the vulnerability of SSL because most of the existing adversarial attacks are mainly discussed in a supervised learning manner. In this paper, we study the effects of adversarial examples on Semi-Supervised Object Detection (SS-OD) which is the mainstream of SSL techniques. We build our hypothesis that attacks on the supervised learning model are also effective on SSL models. Since the state-of-the-art SS-OD methods borrow the teacher-student network, we prepared two pseudo-label based SS-OD networks to validate our hypothesis. We attempt to attack the inference model with adversarial examples crafted by using pretrained auxiliary model and found that SS-OD networks are more vulnerable to adversarial attacks. In addition, we found that selecting different loss components of SS-OD networks to generate perturbations determines the effect and performance of the attack such as misclassification or mislocalization. Visual examples are provided for a clearer understanding. To the best of our knowledge, this is the first effort to investigate the vulnerability of SS-OD.