Unveiling vulnerabilities: evading YOLOv5 object detection through adversarial perturbations and steganography

Gauri Sharma,Urvashi Garg
DOI: https://doi.org/10.1007/s11042-024-18563-8
IF: 2.577
2024-02-16
Multimedia Tools and Applications
Abstract:In the realm of machine learning, a discernible surge in research has been observed, focusing on the development of adversarial perturbations with the intent to subvert the capabilities of Deep Neural Networks (DNNs), particularly in the context of object detection and classification. Despite the availability of cutting-edge systems such as the widely acclaimed You Look Only Once (YOLO)v5 model, renowned for its swift image and video classification and detection prowess, our research embarks on a distinctive course exposing the weakness of this detection model and how easily it can be manipulated. This paper seeks to highlight the weaknesses of one of the most advanced neural networks when subjected to carefully crafted adversarial attacks. Our method entails intentionally inserting adversarial perturbations into photos via image-in-image steganography, a technique that is essentially imperceptible to the human eye yet capable of significantly lowering YOLOv5's confidence levels. This approach was carefully, evaluated on a Magnetic Resonance Imaging (MRI) dataset containing around 1100 brain pictures. A comparison between regular and encoded photos undergoing steganography unveiled a substantial decrease in precision values, plummeting from a noteworthy 0.711 to a mere 0.0346.
computer science, information systems, theory & methods,engineering, electrical & electronic, software engineering
What problem does this paper attempt to address?