Page 146 - 《软件学报》2026年第4期
P. 146
陇盛 等: 基于动量加速和任务均衡的目标检测对抗训练方法 1587
[7] Zhang HY, Yu YD, Jiao JT, Xing EP, El Ghaoui L, Jordan MI. Theoretically principled trade-off between robustness and accuracy. In:
Proc. of the 36th Int’l Conf. on Machine Learning. Long Beach: PMLR, 2019. 7472–7482.
[8] Wang LY, Cao Y, Liu BH, Zeng E, Liu K, Xia YQ. Ensemble adversarial training defense for time series classification models. Acta
Automatica Sinica, 2025, 51(1): 144–160 (in Chinese with English abstract). [doi: 10.16383/j.aas.c240050]
[9] Samangouei P, Kabkab M, Chellappa R. Defense-GAN: Protecting classifiers against adversarial attacks using generative models. In:
Proc. of the 2018 Int’l Conf. on Learning Representations. OpenReview.net. 2018.
[10] Yoon J, Hwang SJ, Lee J. Adversarial purification with score-based generative models. In: Proc. of the 38th Int’l Conf. on Machine
Learning. PMLR, 2021. 12062–12072.
[11] Metzen JH, Genewein T, Fischer V, Bischoff B. On detecting adversarial perturbations. In: Proc. of the 2017 Int’l Conf. on Learning
Representations. OpenReview.net. 2017.
[12] Pang TY, Du C, Dong YP, Zhu J. Towards robust detection of adversarial examples. In: Proc. of the 32nd Int’l Conf. on Neural
Information Processing Systems. Montréal: Curran Associates Inc., 2018. 4584–4594.
[13] Cohen J, Rosenfeld E, Kolter JZ. Certified adversarial robustness via randomized smoothing. In: Proc. of the 36th Int’l Conf. on Machine
Learning. Long Beach: PMLR, 2019. 1310–1320.
[14] Rekavandi AM, Farokhi F, Ohrimenko O, Rubinstein BIP. Certified adversarial robustness via randomized α-smoothing for regression
models. In: Proc. of the 38th Int’l Conf. on Neural Information Processing Systems. Vancouver: Curran Associates Inc., 2025.
134127–134150.
[15] Ma XZ, Ouyang WL, Simonelli A, Ricci E. 3D object detection from images for autonomous driving: A survey. IEEE Trans. on Pattern
Analysis and Machine Intelligence, 2024, 46(5): 3537–3556. [doi: 10.1109/TPAMI.2023.3346386]
[16] Wang SS, Lu SZ, Cao B. Medical image object detection algorithm for privacy-preserving federated learning. Journal of Computer-aided
Design & Computer Graphics, 2021, 33(10): 1553–1562 (in Chinese with English abstract). [doi: 10.3724/SP.J.1089.2021.18416]
[17] Lu JJ, Sibai H, Fabry E. Adversarial examples that fool detectors. arXiv:1712.02494, 2017.
[18] Xie CH, Wang JY, Zhang ZS, Zhou YY, Xie LX, Yuille A. Adversarial examples for semantic segmentation and object detection. In:
Proc. of the 2017 IEEE Int’l Conf. on Computer Vision (ICCV). Venice: IEEE, 2017. 1378–1387. [doi: 10.1109/ICCV.2017.153]
[19] Huang LF, Gao CY, Zhou YY, Xie CH, Yuille AL, Zou CQ, Liu N. Universal physical camouflage attacks on object detectors. In: Proc.
of the 2020 IEEE/CVF Conf. on Computer Vision and Pattern Recognition (CVPR). Seattle: IEEE, 2020. 717–726. [doi: 10.1109/
CVPR42600.2020.00080]
[20] Liang SY, Wu BY, Fan YB, Wei XX, Cao XC. Parallel rectangle flip attack: A query-based black-box attack against object detection. In:
Proc. of the 2021 IEEE/CVF Int’l Conf. on Computer Vision (ICCV). Montreal: IEEE, 2021. 7677–7687. [doi: 10.1109/ICCV48922.2021.
00760]
[21] Cai ZK, Xie XX, Li SS, Yin MJ, Song CY, Krishnamurthy SV, Roy-Chowdhury AK, Asif MS. Context-aware transfer attacks for object
detection. In: Proc. of the 36th AAAI Conf. on Artificial Intelligence. AAAI, 2022. 149–157. [doi: 10.1609/aaai.v36i1.19889]
[22] Huang H, Chen ZY, Chen HR, Wang YT, Zhang K. T-SEA: Transfer-based self-ensemble attack on object detection. In: Proc. of the
2023 IEEE/CVF Conf. on Computer Vision and Pattern Recognition (CVPR). Vancouver: IEEE, 2023. 20514–20523. [doi: 10.1109/
CVPR52729.2023.01965]
[23] Wei XX, Liang SY, Chen N, Cao XC. Transferable adversarial attacks for image and video object detection. In: Proc. of the 28th Int’l
Joint Conf. on Artificial Intelligence (IJCAI). Macao: Morgan Kaufmann, 2019. 954–960.
[24] Lu YX, Liu ZY, Luo YG, Deng SY, Jiang T, Ma JY, Dong YP. Black-box transferable attack method for object detection based on GAN.
Ruan Jian Xue Bao/Journal of Software, 2024, 35(7): 3531–3550 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/
6937.htm [doi: 10.13328/j.cnki.jos.006937]
[25] Wang XX, Chen J, He K, Zhang ZJ, Du RY, Li Q, She JS. Survey on adversarial attacks and defenses for object detection. Journal on
Communications, 2023, 44(11): 260–277 (in Chinese with English abstract). [doi: 10.11959/j.issn.1000-436x.2023223]
[26] Zhang HC, Wang JY. Towards adversarially robust object detection. In: Proc. of the 2019 IEEE/CVF Int’l Conf. on Computer Vision
(ICCV). Seoul: IEEE, 2019. 421–430. [doi: 10.1109/ICCV.2019.00051]
[27] Chen PC, Kung BH, Chen JC. Class-aware robust adversarial training for object detection. In: Proc. of the 2021 IEEE/CVF Conf. on
Computer Vision and Pattern Recognition (CVPR). Nashville: IEEE, 2021. 10415–10424. [doi: 10.1109/CVPR46437.2021.01028]
[28] Dong ZY, Wei PX, Lin L. Adversarially-aware robust object detector. In: Proc. of the 17th European Conf. on Computer Vision. Tel
Aviv: Springer, 2022. 297–313. [doi: 10.1007/978-3-031-20077-9_18]
2
[29] Nesterov YE. A method of solving a convex programming problem with convergence rate O(1/k ). Doklady Akademii Nauk SSSR, 1983,
269(3): 543–547.

