提出针对激光雷达追踪模型的对抗攻击方法,揭示其脆弱性并提升隐蔽性。
Adversarial Attacks on LiDAR-Based Tracking Across Road Users: Robustness Evaluation and Target-Aware Black-Box Method
- 构建统一框架,适配白盒与黑盒攻击,扩展经典方法至点云域
- 新算法TAPG实现高攻击成功率且扰动更难被察觉,提升隐蔽性
- 实验证明先进追踪模型易受攻击,凸显鲁棒性设计的重要性
本文研究基于神经网络的激光雷达点云追踪模型在对抗攻击下的鲁棒性,这一关键问题常被性能优化所忽视。尽管模型采用Transformer或鸟瞰图(BEV)等先进架构,仍忽略对抗攻击、域偏移或数据损坏带来的挑战。我们建立统一的3D目标追踪对抗攻击框架,全面分析白盒与黑盒攻击策略。针对白盒攻击,定制损失函数以适配不同追踪范式,并将FGSM、C&W、PGD等方法扩展至点云领域。针对黑盒攻击,提出新型迁移式方法TAPG,兼顾攻击效果与扰动隐蔽性:采用启发式策略施加稀疏约束,利用随机子向量分解增强迁移能力。实验表明,先进追踪方法在白盒与黑盒攻击下均存在显著脆弱性,强调将对抗鲁棒性纳入模型设计的必要性。相比现有方法,TAPG在攻击有效性和扰动不可见性间取得更优平衡。
原文摘要 · Abstract (English)
In this study, we delve into the robustness of neural network-based LiDAR point cloud tracking models under adversarial attacks, a critical aspect often overlooked in favor of performance enhancement. These models, despite incorporating advanced architectures like Transformer or Bird's Eye View (BEV), tend to neglect robustness in the face of challenges such as adversarial attacks, domain shifts, or data corruption. We instead focus on the robustness of the tracking models under the threat of adversarial attacks. We begin by establishing a unified framework for conducting adversarial attacks within the context of 3D object tracking, which allows us to thoroughly investigate both white-box and black-box attack strategies. For white-box attacks, we tailor specific loss functions to accommodate various tracking paradigms and extend existing methods such as FGSM, C\&W, and PGD to the point cloud domain. In addressing black-box attack scenarios, we introduce a novel transfer-based approach, the Target-aware Perturbation Generation (TAPG) algorithm, with the dual objectives of achieving high attack performance and maintaining low perceptibility. This method employs a heuristic strategy to enforce sparse attack constraints and utilizes random sub-vector factorization to bolster transferability. Our experimental findings reveal a significant vulnerability in advanced tracking methods when subjected to both black-box and white-box attacks, underscoring the necessity for incorporating robustness against adversarial attacks into the design of LiDAR point cloud tracking models. Notably, compared to existing methods, the TAPG also strikes an optimal balance between the effectiveness of the attack and the concealment of the perturbations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。