用扩散模型生成自然可定制的对抗性伪装,骗过车辆检测器
CNCA: Toward Customizable and Natural Generation of Adversarial Camouflage for Vehicle Detectors
- 基于预训练扩散模型,通过文本提示生成纹理
- 物理与数字实验均显示伪装更自然且攻击成功率高
- 适合需要隐蔽性和可控性的对抗攻击研究
针对现有物理对抗伪装方法生成的图案过于显眼、易被人类识别的问题,本文提出一种可定制且自然的对抗伪装攻击(CNCA)方法。该方法利用现成的预训练扩散模型,通过用户自定义的文本提示采样最优纹理图像,在保持高攻击性能的同时生成更自然的伪装图案。在数字与物理世界中的大量实验及用户研究结果表明,相较于最先进基线,本方法生成的伪装在自然度上显著提升,同时具备竞争性攻击效果。代码已公开。
原文摘要 · Abstract (English)
Prior works on physical adversarial camouflage against vehicle detectors mainly focus on the effectiveness and robustness of the attack. The current most successful methods optimize 3D vehicle texture at a pixel level. However, this results in conspicuous and attention-grabbing patterns in the generated camouflage, which humans can easily identify. To address this issue, we propose a Customizable and Natural Camouflage Attack (CNCA) method by leveraging an off-the-shelf pre-trained diffusion model. By sampling the optimal texture image from the diffusion model with a user-specific text prompt, our method can generate natural and customizable adversarial camouflage while maintaining high attack performance. With extensive experiments on the digital and physical worlds and user studies, the results demonstrate that our proposed method can generate significantly more natural-looking camouflage than the state-of-the-art baselines while achieving competitive attack performance. Our code is available at \href{https://anonymous.4open.science/r/CNCA-1D54}{https://anonymous.4open.science/r/CNCA-1D54}
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。