Double adversarial attack against license plate recognition system

Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based attacks.To address this issue, a dual adversarial attack method was proposed for license plate recognition (LPR) systems in a DNN-based scenario.It w...

Full description

Saved in:
Bibliographic Details
Published in网络与信息安全学报 Vol. 9; no. 3; pp. 16 - 27
Main Author Xianyi CHEN, Jun GU1, Kai YAN, Dong JIANG, Linfeng XU, Zhangjie FU
Format Journal Article
LanguageEnglish
Published POSTS&TELECOM PRESS Co., LTD 01.06.2023
Subjects
Online AccessGet full text

Cover

Loading…
Abstract Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based attacks.To address this issue, a dual adversarial attack method was proposed for license plate recognition (LPR) systems in a DNN-based scenario.It was demonstrated that an adversarial patch added to the pattern location of the license plate can render the target detection subsystem of the LPR system unable to detect the license plate class.Additionally, the natural rust and stains were simulated by adding irregular single-connected area random points to the license plate image, which results in the misrecognition of the license plate number.or the license plate research, different shapes of adversarial patches and different colors of adversarial patches are designed as a way to generate adversarial license plates and migrate them to the physical world.Experimental results show that the designed adversarial samples are undetectable by the human eye and can deceive the license plate recognition system, such as EasyPR.The success rate of the attack in the physical world can reach 99%.The study sheds light on the vulnerability of deep learning and the adversarial attack of LPR, and offers a positive contribution toward improving the robustness of license plate recognition models.
AbstractList Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based attacks.To address this issue, a dual adversarial attack method was proposed for license plate recognition (LPR) systems in a DNN-based scenario.It was demonstrated that an adversarial patch added to the pattern location of the license plate can render the target detection subsystem of the LPR system unable to detect the license plate class.Additionally, the natural rust and stains were simulated by adding irregular single-connected area random points to the license plate image, which results in the misrecognition of the license plate number.or the license plate research, different shapes of adversarial patches and different colors of adversarial patches are designed as a way to generate adversarial license plates and migrate them to the physical world.Experimental results show that the designed adversarial samples are undetectable by the human eye and can deceive the license plate recognition system, such as EasyPR.The success rate of the attack in the physical world can reach 99%.The study sheds light on the vulnerability of deep learning and the adversarial attack of LPR, and offers a positive contribution toward improving the robustness of license plate recognition models.
Author Xianyi CHEN, Jun GU1, Kai YAN, Dong JIANG, Linfeng XU, Zhangjie FU
Author_xml – sequence: 1
  fullname: Xianyi CHEN, Jun GU1, Kai YAN, Dong JIANG, Linfeng XU, Zhangjie FU
BookMark eNqtjrFOwzAURT2UIYX-g_sBDXGcpPHaAoKdoZv14rxEL3XtyDaI_D0Von_Q6Vyd4eqs2cp5h4xtRZELoWr1POUUo8vLQjU7Uaif6yplIasVy27ulLHDi__qLHLovzFECASWQ0pgzhxGIBcTt2TQReSzhYQ8oPGjo0Te8bjEhJcn9jCAjbj55yP7eHv9PL7veg-TngNdICzaA-k_4cOoISQyFvVetdJ05bVrwKoHCY1qy3ovVd-ItpJK3vPrF-NrWc4
ContentType Journal Article
DBID DOA
DOI 10.11959/j.issn.2096-109x.2023034
DatabaseName Directory of Open Access Journals
DatabaseTitleList
Database_xml – sequence: 1
  dbid: DOA
  name: DOAJ Directory of Open Access Journals
  url: https://www.doaj.org/
  sourceTypes: Open Website
DeliveryMethod fulltext_linktorsrc
EndPage 27
ExternalDocumentID oai_doaj_org_article_7983cb2230fe4da3a69825739d618439
GroupedDBID GROUPED_DOAJ
ID FETCH-doaj_primary_oai_doaj_org_article_7983cb2230fe4da3a69825739d6184393
IEDL.DBID DOA
ISSN 2096-109X
IngestDate Thu Jul 04 21:10:57 EDT 2024
IsDoiOpenAccess true
IsOpenAccess true
IsPeerReviewed false
IsScholarly false
Issue 3
Language English
LinkModel DirectLink
MergedId FETCHMERGED-doaj_primary_oai_doaj_org_article_7983cb2230fe4da3a69825739d6184393
OpenAccessLink https://doaj.org/article/7983cb2230fe4da3a69825739d618439
ParticipantIDs doaj_primary_oai_doaj_org_article_7983cb2230fe4da3a69825739d618439
PublicationCentury 2000
PublicationDate 2023-06-01
PublicationDateYYYYMMDD 2023-06-01
PublicationDate_xml – month: 06
  year: 2023
  text: 2023-06-01
  day: 01
PublicationDecade 2020
PublicationTitle 网络与信息安全学报
PublicationYear 2023
Publisher POSTS&TELECOM PRESS Co., LTD
Publisher_xml – name: POSTS&TELECOM PRESS Co., LTD
Score 3.7771194
Snippet Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based...
SourceID doaj
SourceType Open Website
StartPage 16
SubjectTerms adversarial attack
adversarial patch
adversarial spot
license plate recognition
Title Double adversarial attack against license plate recognition system
URI https://doaj.org/article/7983cb2230fe4da3a69825739d618439
Volume 9
hasFullText 1
inHoldings 1
isFullTextHit
isPrint
link http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwrV1NS8QwEB1kD-JFFBW_ieB1d2vStM3RXVxWQU8KvZUkTQQt3cVW8Oc7k-yKnjzoNYEkk6-ZRybvAVzWPM248YhOpEKAUnAzNFIZYkZUdZ7Wwib0wfn-IZs_pXelLL9JfVFOWKQHjhM3zlUhrEEnlniX1lroTCGoyYWqg1RJ_Lp3JSOYIiU5jMnxblHlJlyEG0FJNX4JJ2q0rvsYkWh4ItIfRP3Bo8x2YHsVCrLrOIRd2HDtHkwwojWNY5qEkjtN24Ppvtf2lelnRPFdzxo8223n2LLBOJF9ZQAtWhZpmffhdnbzOJ0PqdNqGekkKiJ4DgVodrUyu_rNbHEAg3bRukNgLrFojvWSW_S3xhaG-4LeN7nwROVyBJO_93f8H42cwBZNfMy0OoVB__buztCn9-Y8LN8n66ihpQ
link.rule.ids 315,786,790,870,2115,27955,27956
linkProvider Directory of Open Access Journals
openUrl ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Double+adversarial+attack+against+license+plate+recognition+system&rft.jtitle=%E7%BD%91%E7%BB%9C%E4%B8%8E%E4%BF%A1%E6%81%AF%E5%AE%89%E5%85%A8%E5%AD%A6%E6%8A%A5&rft.au=Xianyi+CHEN%2C+Jun+GU1%2C+Kai+YAN%2C+Dong+JIANG%2C+Linfeng+XU%2C+Zhangjie+FU&rft.date=2023-06-01&rft.pub=POSTS%26TELECOM+PRESS+Co.%2C+LTD&rft.issn=2096-109X&rft.volume=9&rft.issue=3&rft.spage=16&rft.epage=27&rft_id=info:doi/10.11959%2Fj.issn.2096-109x.2023034&rft.externalDBID=DOA&rft.externalDocID=oai_doaj_org_article_7983cb2230fe4da3a69825739d618439
thumbnail_l http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/lc.gif&issn=2096-109X&client=summon
thumbnail_m http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/mc.gif&issn=2096-109X&client=summon
thumbnail_s http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/sc.gif&issn=2096-109X&client=summon