arXiv:2409.17403cs.CRcs.AI2024-09被引 1

用动态投影干扰自动驾驶目标检测,成功率高达100%。

Transient Adversarial 3D Projection Attacks on Object Detection in Autonomous Driving

  • 通过颜色映射与几何变换优化投影图案
  • 在低光环境下对YOLOv3和Mask R-CNN攻击成功率100%
  • 适合关注自动驾驶安全漏洞的研究者

目标检测是自动驾驶中的关键任务。尽管已有研究提出对抗补丁或贴纸等攻击方式,但针对三维表面的投影攻击仍鲜有探索。与固定模式的对抗补丁不同,投影攻击可实现瞬时模式变化,更具灵活性。本文提出一种专为自动驾驶目标检测设计的对抗性3D投影攻击,将攻击建模为优化问题,结合颜色映射与几何变换模型。实验在室内环境下验证,低光照条件下对YOLOv3和Mask R-CNN的攻击成功率可达100%,凸显其在真实驾驶场景中的潜在危害。

原文摘要 · Abstract (English)

Object detection is a crucial task in autonomous driving. While existing research has proposed various attacks on object detection, such as those using adversarial patches or stickers, the exploration of projection attacks on 3D surfaces remains largely unexplored. Compared to adversarial patches or stickers, which have fixed adversarial patterns, projection attacks allow for transient modifications to these patterns, enabling a more flexible attack. In this paper, we introduce an adversarial 3D projection attack specifically targeting object detection in autonomous driving scenarios. We frame the attack formulation as an optimization problem, utilizing a combination of color mapping and geometric transformation models. Our results demonstrate the effectiveness of the proposed attack in deceiving YOLOv3 and Mask R-CNN in physical settings. Evaluations conducted in an indoor environment show an attack success rate of up to 100% under low ambient light conditions, highlighting the potential damage of our attack in real-world driving scenarios.

自动驾驶对抗攻击3D投影

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。