A Transferable Adversarial Attack Framework for Object Detection via Spatial-Frequency Information Masking
Object detectors based on convolutional neural networks (CNNs) have been widely applied for autonomous driving and industrial defect detection. Recent studies have shown that they are vulnerable to adversarial examples. Existing attack methods rely on the output of the object detector’s detection head to generate adversarial examples, which limits their applicability. Furthermore, optimizing the loss function of the object detector to generate adversarial perturbations can cause the perturbations to overfit to the source object detector, reducing the transferability of adversarial examples. To address these issues, we propose a novel adversarial example generation framework consisting of a spatial-frequency information masking (SFIM) method and two independent attack branches. The SFIM method masks partial spatial and frequency domain information of the augmented examples to generate diverse adversarial examples. The two independent attack branches, one targeting the backbone network and the other targeting the region proposal network (RPN), are fused with the SFIM method. The two attack branches do not rely on the output of the object detector’s detection head and are applicable to different attack scenarios. Extensive experiments on the PASCAL VOC and MS COCO datasets show that the adversarial examples generated by the proposed framework are highly transferable and can effectively attack black-box detectors of different architectures.
Paper
Full text
A Transferable Adversarial Attack Framework for Object Detection via Spatial-Frequency Information Masking
OpenAlex · Adversarial Robustness in Machine Learning · 2025
Abstract
Object detectors based on convolutional neural networks (CNNs) have been widely applied for autonomous driving and industrial defect detection. Recent studies have shown that they are vulnerable to adversarial examples. Existing attack methods rely on the output of the object detector’s detection head to generate adversarial examples, which limits their applicability. Furthermore, optimizing the loss function of the object detector to generate adversarial perturbations can cause the perturbations to overfit to the source object detector, reducing the transferability of adversarial examples. To address these issues, we propose a novel adversarial example generation framework consisting of a spatial-frequency information masking (SFIM) method and two independent attack branches. The SFIM method masks partial spatial and frequency domain information of the augmented examples to generate diverse adversarial examples. The two independent attack branches, one targeting the backbone network and the other targeting the region proposal network (RPN), are fused with the SFIM method. The two attack branches do not rely on the output of the object detector’s detection head and are applicable to different attack scenarios. Extensive experiments on the PASCAL VOC and MS COCO datasets show that the adversarial examples generated by the proposed framework are highly transferable and can effectively attack black-box detectors of different architectures.