HyperAIHyperAI

Command Palette

Search for a command to run...

3 months ago

Natural Adversarial Objects

Felix Lau Nishant Subramani Sasha Harrison Aerin Kim Elliot Branson Rosanne Liu

Natural Adversarial Objects

Abstract

Although state-of-the-art object detection methods have shown compelling performance, models often are not robust to adversarial attacks and out-of-distribution data. We introduce a new dataset, Natural Adversarial Objects (NAO), to evaluate the robustness of object detection models. NAO contains 7,934 images and 9,943 objects that are unmodified and representative of real-world scenarios, but cause state-of-the-art detection models to misclassify with high confidence. The mean average precision (mAP) of EfficientDet-D7 drops 74.5% when evaluated on NAO compared to the standard MSCOCO validation set. Moreover, by comparing a variety of object detection architectures, we find that better performance on MSCOCO validation set does not necessarily translate to better performance on NAO, suggesting that robustness cannot be simply achieved by training a more accurate model. We further investigate why examples in NAO are difficult to detect and classify. Experiments of shuffling image patches reveal that models are overly sensitive to local texture. Additionally, using integrated gradients and background replacement, we find that the detection model is reliant on pixel information within the bounding box, and insensitive to the background context when predicting class labels. NAO can be downloaded at https://drive.google.com/drive/folders/15P8sOWoJku6SSEiHLEts86ORfytGezi8.

Benchmarks

BenchmarkMethodologyMetrics
object-detection-on-naoEfficientDet-D2
mAP: 12.8
mAP w/o OOD: 25.4
mAR: 40.2
object-detection-on-naoEfficientDet-D4
mAP: 15.0
mAP w/o OOD: 29.6
mAR: 42.7
object-detection-on-naoEfficientDet-D7
mAP: 13.6
mAP w/o OOD: 26.6
mAR: 40.8
object-detection-on-naoFaster RCNN
mAP: 13.5
mAP w/o OOD: 22.8
mAR: 41.4
object-detection-on-naoRetinaNet-R50
mAP: 11.1
mAP w/o OOD: 19.5
mAR: 37.2
object-detection-on-naoYOLOv3
mAP: 10.0
mAP w/o OOD: 17.5
mAR: 28.4
object-detection-on-naoMask RCNN R50
mAP: 15.2
mAP w/o OOD: 24.6
mAR: 43.8

Build AI with AI

From idea to launch — accelerate your AI development with free AI co-coding, out-of-the-box environment and best price of GPUs.

AI Co-coding
Ready-to-use GPUs
Best Pricing
Get Started

Hyper Newsletters

Subscribe to our latest updates
We will deliver the latest updates of the week to your inbox at nine o'clock every Monday morning
Powered by MailChimp