Double adversarial attack against license plate recognition system
Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based attacks.To address this issue, a dual adversarial attack method was proposed for license plate recognition (LPR) systems in a DNN-based scenario.It w...
Saved in:
Published in | 网络与信息安全学报 Vol. 9; no. 3; pp. 16 - 27 |
---|---|
Main Author | |
Format | Journal Article |
Language | English |
Published |
POSTS&TELECOM PRESS Co., LTD
01.06.2023
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Abstract | Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based attacks.To address this issue, a dual adversarial attack method was proposed for license plate recognition (LPR) systems in a DNN-based scenario.It was demonstrated that an adversarial patch added to the pattern location of the license plate can render the target detection subsystem of the LPR system unable to detect the license plate class.Additionally, the natural rust and stains were simulated by adding irregular single-connected area random points to the license plate image, which results in the misrecognition of the license plate number.or the license plate research, different shapes of adversarial patches and different colors of adversarial patches are designed as a way to generate adversarial license plates and migrate them to the physical world.Experimental results show that the designed adversarial samples are undetectable by the human eye and can deceive the license plate recognition system, such as EasyPR.The success rate of the attack in the physical world can reach 99%.The study sheds light on the vulnerability of deep learning and the adversarial attack of LPR, and offers a positive contribution toward improving the robustness of license plate recognition models. |
---|---|
AbstractList | Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based attacks.To address this issue, a dual adversarial attack method was proposed for license plate recognition (LPR) systems in a DNN-based scenario.It was demonstrated that an adversarial patch added to the pattern location of the license plate can render the target detection subsystem of the LPR system unable to detect the license plate class.Additionally, the natural rust and stains were simulated by adding irregular single-connected area random points to the license plate image, which results in the misrecognition of the license plate number.or the license plate research, different shapes of adversarial patches and different colors of adversarial patches are designed as a way to generate adversarial license plates and migrate them to the physical world.Experimental results show that the designed adversarial samples are undetectable by the human eye and can deceive the license plate recognition system, such as EasyPR.The success rate of the attack in the physical world can reach 99%.The study sheds light on the vulnerability of deep learning and the adversarial attack of LPR, and offers a positive contribution toward improving the robustness of license plate recognition models. |
Author | Xianyi CHEN, Jun GU1, Kai YAN, Dong JIANG, Linfeng XU, Zhangjie FU |
Author_xml | – sequence: 1 fullname: Xianyi CHEN, Jun GU1, Kai YAN, Dong JIANG, Linfeng XU, Zhangjie FU |
BookMark | eNqtjrFOwzAURT2UIYX-g_sBDXGcpPHaAoKdoZv14rxEL3XtyDaI_D0Von_Q6Vyd4eqs2cp5h4xtRZELoWr1POUUo8vLQjU7Uaif6yplIasVy27ulLHDi__qLHLovzFECASWQ0pgzhxGIBcTt2TQReSzhYQ8oPGjo0Te8bjEhJcn9jCAjbj55yP7eHv9PL7veg-TngNdICzaA-k_4cOoISQyFvVetdJ05bVrwKoHCY1qy3ovVd-ItpJK3vPrF-NrWc4 |
ContentType | Journal Article |
DBID | DOA |
DOI | 10.11959/j.issn.2096-109x.2023034 |
DatabaseName | Directory of Open Access Journals |
DatabaseTitleList | |
Database_xml | – sequence: 1 dbid: DOA name: DOAJ Directory of Open Access Journals url: https://www.doaj.org/ sourceTypes: Open Website |
DeliveryMethod | fulltext_linktorsrc |
EndPage | 27 |
ExternalDocumentID | oai_doaj_org_article_7983cb2230fe4da3a69825739d618439 |
GroupedDBID | GROUPED_DOAJ |
ID | FETCH-doaj_primary_oai_doaj_org_article_7983cb2230fe4da3a69825739d6184393 |
IEDL.DBID | DOA |
ISSN | 2096-109X |
IngestDate | Thu Jul 04 21:10:57 EDT 2024 |
IsDoiOpenAccess | true |
IsOpenAccess | true |
IsPeerReviewed | false |
IsScholarly | false |
Issue | 3 |
Language | English |
LinkModel | DirectLink |
MergedId | FETCHMERGED-doaj_primary_oai_doaj_org_article_7983cb2230fe4da3a69825739d6184393 |
OpenAccessLink | https://doaj.org/article/7983cb2230fe4da3a69825739d618439 |
ParticipantIDs | doaj_primary_oai_doaj_org_article_7983cb2230fe4da3a69825739d618439 |
PublicationCentury | 2000 |
PublicationDate | 2023-06-01 |
PublicationDateYYYYMMDD | 2023-06-01 |
PublicationDate_xml | – month: 06 year: 2023 text: 2023-06-01 day: 01 |
PublicationDecade | 2020 |
PublicationTitle | 网络与信息安全学报 |
PublicationYear | 2023 |
Publisher | POSTS&TELECOM PRESS Co., LTD |
Publisher_xml | – name: POSTS&TELECOM PRESS Co., LTD |
Score | 3.7771194 |
Snippet | Recent studies have revealed that deep neural networks (DNN) used in artificial intelligence systems are highly vulnerable to adversarial sample-based... |
SourceID | doaj |
SourceType | Open Website |
StartPage | 16 |
SubjectTerms | adversarial attack adversarial patch adversarial spot license plate recognition |
Title | Double adversarial attack against license plate recognition system |
URI | https://doaj.org/article/7983cb2230fe4da3a69825739d618439 |
Volume | 9 |
hasFullText | 1 |
inHoldings | 1 |
isFullTextHit | |
isPrint | |
link | http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwrV1NS8QwEB1kD-JFFBW_ieB1d2vStM3RXVxWQU8KvZUkTQQt3cVW8Oc7k-yKnjzoNYEkk6-ZRybvAVzWPM248YhOpEKAUnAzNFIZYkZUdZ7Wwib0wfn-IZs_pXelLL9JfVFOWKQHjhM3zlUhrEEnlniX1lroTCGoyYWqg1RJ_Lp3JSOYIiU5jMnxblHlJlyEG0FJNX4JJ2q0rvsYkWh4ItIfRP3Bo8x2YHsVCrLrOIRd2HDtHkwwojWNY5qEkjtN24Ppvtf2lelnRPFdzxo8223n2LLBOJF9ZQAtWhZpmffhdnbzOJ0PqdNqGekkKiJ4DgVodrUyu_rNbHEAg3bRukNgLrFojvWSW_S3xhaG-4LeN7nwROVyBJO_93f8H42cwBZNfMy0OoVB__buztCn9-Y8LN8n66ihpQ |
link.rule.ids | 315,786,790,870,2115,27955,27956 |
linkProvider | Directory of Open Access Journals |
openUrl | ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Double+adversarial+attack+against+license+plate+recognition+system&rft.jtitle=%E7%BD%91%E7%BB%9C%E4%B8%8E%E4%BF%A1%E6%81%AF%E5%AE%89%E5%85%A8%E5%AD%A6%E6%8A%A5&rft.au=Xianyi+CHEN%2C+Jun+GU1%2C+Kai+YAN%2C+Dong+JIANG%2C+Linfeng+XU%2C+Zhangjie+FU&rft.date=2023-06-01&rft.pub=POSTS%26TELECOM+PRESS+Co.%2C+LTD&rft.issn=2096-109X&rft.volume=9&rft.issue=3&rft.spage=16&rft.epage=27&rft_id=info:doi/10.11959%2Fj.issn.2096-109x.2023034&rft.externalDBID=DOA&rft.externalDocID=oai_doaj_org_article_7983cb2230fe4da3a69825739d618439 |
thumbnail_l | http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/lc.gif&issn=2096-109X&client=summon |
thumbnail_m | http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/mc.gif&issn=2096-109X&client=summon |
thumbnail_s | http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/sc.gif&issn=2096-109X&client=summon |