arXiv:2409.12394cs.CVcs.AI2024-09NeurIPS被引 9

用荧光墨水制作隐形攻击贴,骗过交通标志识别系统

The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition

  • 用荧光墨水设计隐形攻击贴,通过紫外线激发干扰识别
  • 低光下攻击成功率98.31%,可绕过五种主流防御机制
  • 适合研究物理对抗攻击的人员,或关注自动驾驶安全者

近期,交通标志识别(TSR)系统成为物理对抗攻击的焦点。现有攻击多依赖显眼贴纸、投影或易被阻挡的不可见光与声信号。本文提出一种新型攻击介质——荧光墨水,构建隐蔽高效的物理对抗贴片FIPatch,推动该领域进展。我们首先在数字域建模荧光效应,确定最优攻击参数,并指导现实世界中的荧光特性设定。通过在目标标志上施加精心设计的荧光扰动,攻击者可在后续使用紫外光触发荧光效果,导致TSR系统误分类标志,进而引发交通事故。全面评估表明,在低光条件下,攻击成功率达98.31%;同时成功绕过五种主流防御机制,成功率高达96.72%。

原文摘要 · Abstract (English)

Recently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%.

对抗攻击交通识别物理攻击荧光

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。