用注意力融合多视角图像,修复光斑攻击下的交通标志
Secure Traffic Sign Recognition: An Attention-Enabled Universal Image Inpainting Mechanism against Light Patch Attacks
- 通过多视角图像融合与注意力机制修复被恶意光斑污染的标志
- 在三个主流识别模型上平均提升准确率54.8%
- 针对隐蔽性强的光斑攻击设计,适合自动驾驶安全防护
交通标志识别系统在智能驾驶中至关重要,但依赖深度学习使其易受对抗攻击。近期出现一种新型攻击:向标志投射精心设计的恶意光斑,相比传统贴纸更隐蔽且易实现。为应对该威胁,本文提出通用图像修复机制SafeSign,基于注意力增强的多视角图像融合,修复受光斑污染的标志,保障识别准确性。首先分析恶意光斑对标志局部与全局特征空间的影响;随后构建基于二值掩码的U-Net生成管道,合成多样化的污染样本以训练修复模型;进而设计注意力机制网络,联合利用多视角互补信息完成修复。大量实验表明,SafeSign在三个常用识别模型上平均提升准确率54.8%,有效抵御光斑攻击。
原文摘要 · Abstract (English)
Traffic sign recognition systems play a crucial role in assisting drivers to make informed decisions while driving. However, due to the heavy reliance on deep learning technologies, particularly for future connected and autonomous driving, these systems are susceptible to adversarial attacks that pose significant safety risks to both personal and public transportation. Notably, researchers recently identified a new attack vector to deceive sign recognition systems: projecting well-designed adversarial light patches onto traffic signs. In comparison with traditional adversarial stickers or graffiti, these emerging light patches exhibit heightened aggression due to their ease of implementation and outstanding stealthiness. To effectively counter this security threat, we propose a universal image inpainting mechanism, namely, SafeSign. It relies on attention-enabled multi-view image fusion to repair traffic signs contaminated by adversarial light patches, thereby ensuring the accurate sign recognition. Here, we initially explore the fundamental impact of malicious light patches on the local and global feature spaces of authentic traffic signs. Then, we design a binary mask-based U-Net image generation pipeline outputting diverse contaminated sign patterns, to provide our image inpainting model with needed training data. Following this, we develop an attention mechanism-enabled neural network to jointly utilize the complementary information from multi-view images to repair contaminated signs. Finally, extensive experiments are conducted to evaluate SafeSign's effectiveness in resisting potential light patch-based attacks, bringing an average accuracy improvement of 54.8% in three widely-used sign recognition models
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。