arXiv:2411.18776cs.CVcs.CR2024-11被引 4

用落叶制造对抗攻击,让交通标志识别系统误判。

Fall Leaf Adversarial Attack on Traffic Sign Classification

  • 利用自然掉落的树叶作为对抗扰动,隐蔽性强。
  • 不同树种、大小、颜色和角度的落叶均能引发高误判率。
  • 揭示了边缘检测漏洞,适合研究自动驾驶安全的学者参考。

对抗性图像扰动攻击已成为机器学习算法的重大威胁,尤其在图像分类场景中。这类攻击通过细微扰动输入图像,导致神经网络错误分类,而图像对人类仍清晰可辨。自动驾驶系统中的交通标志识别尤为关键,误判可能导致错误行为。本文提出一类新型对抗攻击:不依赖人工添加的贴纸、油漆或灯光,而是利用自然产生的落叶。由于落叶可能源自附近树木,此类攻击具备合理否认性。研究分析了多种树种的落叶,考察其大小、颜色及旋转角度对误判的影响。实验表明该方法具有高成功率,并探讨了攻击与边缘检测机制之间的关联,而边缘检测是许多图像分类算法的核心环节。

原文摘要 · Abstract (English)

Adversarial input image perturbation attacks have emerged as a significant threat to machine learning algorithms, particularly in image classification setting. These attacks involve subtle perturbations to input images that cause neural networks to misclassify the input images, even though the images remain easily recognizable to humans. One critical area where adversarial attacks have been demonstrated is in automotive systems where traffic sign classification and recognition is critical, and where misclassified images can cause autonomous systems to take wrong actions. This work presents a new class of adversarial attacks. Unlike existing work that has focused on adversarial perturbations that leverage human-made artifacts to cause the perturbations, such as adding stickers, paint, or shining flashlights at traffic signs, this work leverages nature-made artifacts: tree leaves. By leveraging nature-made artifacts, the new class of attacks has plausible deniability: a fall leaf stuck to a street sign could come from a near-by tree, rather than be placed there by an malicious human attacker. To evaluate the new class of the adversarial input image perturbation attacks, this work analyses how fall leaves can cause misclassification in street signs. The work evaluates various leaves from different species of trees, and considers various parameters such as size, color due to tree leaf type, and rotation. The work demonstrates high success rate for misclassification. The work also explores the correlation between successful attacks and how they affect the edge detection, which is critical in many image classification algorithms.

对抗攻击自动驾驶图像安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。