给卡车生成骗过检测器的伪装图案,让先进目标检测失效
TACO: Adversarial Camouflage Optimization on Trucks to Fool Object Detectors
- 用可微渲染在3D卡车模型上优化对抗性伪装纹理
- 使YOLOv8在未见数据上检测准确率降至[email protected]=0.0099
- 生成图案兼具视觉真实性和跨模型欺骗能力
对抗攻击威胁自动驾驶和国防系统中机器学习模型的可靠性。随着YOLOv8等模型日益鲁棒,开发有效的对抗方法愈发困难。本文提出卡车对抗伪装优化(TACO)框架,通过 Unreal Engine 5 将可微渲染与真实感渲染网络结合,在3D车辆模型上生成针对YOLOv8的目标检测器欺骗纹理。为确保纹理既有效欺骗检测器又具视觉合理性,引入卷积平滑损失函数(Convolutional Smooth Loss)。实验表明,TACO显著降低YOLOv8检测性能,未见测试数据上达到[email protected]=0.0099。此外,该对抗纹理对Faster R-CNN及早期YOLO版本也表现出强迁移能力。
原文摘要 · Abstract (English)
Adversarial attacks threaten the reliability of machine learning models in critical applications like autonomous vehicles and defense systems. As object detectors become more robust with models like YOLOv8, developing effective adversarial methodologies is increasingly challenging. We present Truck Adversarial Camouflage Optimization (TACO), a novel framework that generates adversarial camouflage patterns on 3D vehicle models to deceive state-of-the-art object detectors. Adopting Unreal Engine 5, TACO integrates differentiable rendering with a Photorealistic Rendering Network to optimize adversarial textures targeted at YOLOv8. To ensure the generated textures are both effective in deceiving detectors and visually plausible, we introduce the Convolutional Smooth Loss function, a generalized smooth loss function. Experimental evaluations demonstrate that TACO significantly degrades YOLOv8's detection performance, achieving an [email protected] of 0.0099 on unseen test data. Furthermore, these adversarial patterns exhibit strong transferability to other object detection models such as Faster R-CNN and earlier YOLO versions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。