Shielding Object Detection: Enhancing Adversarial Defense through Ensemble Methods

Ziwen Peng, Xi Chen, Wei Huang, Xianglong Kong, Jianpeng Li, Song Xue · 2024

Deep Learning (DL) techniques have gained significant attention in the field of object detection. However, the susceptibility of DL models to adversarial attacks has raised concerns regarding their applicability in safety-critical domains. While adversarial training can improve the robustness of object detection models, it often comes at the expense of reduced detection performance. In light of this tradeoff, this paper proposes a novel framework aimed at enhancing the adversarial robustness of object detection models through the utilization of ensemble methods. The proposed approach uses a novel diversity training strategy to reduce the attack transferability between submodels in the ensemble. Specifically, it adds penalties to the cosine similarity of input gradients with respect to localization loss and classification loss between submodels. Furthermore, a detection aggregation algorithm is developed to effectively combine the detection results obtained from the submodels. Extensive experiments are conducted on real-world benchmarks, as well as popular object detection models. The results validate the effectiveness of the approach in countering both adversarial perturbation-based and adversarial patch-based attacks.

Read the paper · More papers on PaperTik