针对激光雷达目标检测的隐蔽攻击方法,成功率高达90%。
LiDAttack: Robust Black-box Attack on LiDAR-based Object Detection
- 用遗传算法加模拟退火优化扰动点位置和数量,实现隐蔽攻击。
- 在三个数据集上对三种模型攻击成功率达90%,效果显著。
- 适合研究自动驾驶安全、对抗样本防御的工程师和学者。
由于深度神经网络易受精心构造的对抗样本影响,针对激光雷达传感器的对抗攻击已被广泛研究。本文提出一种鲁棒的黑盒攻击方法LiDAttack,利用带有模拟退火策略的遗传算法,严格限制扰动点的位置与数量,实现隐蔽且高效的攻击。同时,该方法模拟扫描偏差,可适应真实场景中的动态变化。在三个数据集(KITTI、nuScenes 和自建数据)上,对三种主流目标检测模型(PointRCNN、PointPillar、PV-RCNN++)进行了大量实验,结果表明,LiDAttack在多种模型上均表现出高攻击成功率,最高可达90%。
原文摘要 · Abstract (English)
Since DNN is vulnerable to carefully crafted adversarial examples, adversarial attack on LiDAR sensors have been extensively studied. We introduce a robust black-box attack dubbed LiDAttack. It utilizes a genetic algorithm with a simulated annealing strategy to strictly limit the location and number of perturbation points, achieving a stealthy and effective attack. And it simulates scanning deviations, allowing it to adapt to dynamic changes in real world scenario variations. Extensive experiments are conducted on 3 datasets (i.e., KITTI, nuScenes, and self-constructed data) with 3 dominant object detection models (i.e., PointRCNN, PointPillar, and PV-RCNN++). The results reveal the efficiency of the LiDAttack when targeting a wide range of object detection models, with an attack success rate (ASR) up to 90%.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。