用AI协作生成能骗过自动驾驶视觉系统的物理对抗贴纸。
MAGIC: Mastering Physical Adversarial Generation in Context through Collaborative LLM Agents
- 三类大模型代理协同设计贴纸与部署位置,兼顾欺骗性与自然性。
- 在nuImage和真实场景中均有效攻击YOLO和DETR检测系统。
- 适合安全研究者、自动驾驶测试人员了解视觉系统漏洞。
驾驶场景中的物理对抗攻击可暴露视觉感知模型的关键漏洞。然而,由于现实环境多样且需保持视觉自然性,开发此类攻击仍具挑战。本文将物理对抗攻击重新定义为一次性贴纸生成问题,提出MAGIC框架,通过多模态大模型代理协同实现场景上下文感知的对抗贴纸生成与部署。MAGIC包含三个专用代理:生成代理(GAgent)利用提示工程生成欺骗性贴纸;部署代理(DAgent)基于场景理解确定最优放置策略;自检代理(EAgent)提供过程监督与迭代优化。在nuImage数据集及实拍真实场景中验证,MAGIC在数字与物理层面均有效攻击YOLO与DETR系列目标检测系统,统计与视觉结果表明其高效且具备实际威胁能力。
原文摘要 · Abstract (English)
Physical adversarial attacks in driving scenarios can expose critical vulnerabilities in visual perception models. However, developing such attacks remains challenging due to diverse real-world environments and the requirement for maintaining visual naturality. Building upon this challenge, we reformulate physical adversarial attacks as a one-shot patch generation problem. Our approach generates adversarial patches through a deep generative model that considers the specific scene context, enabling direct physical deployment in matching environments. The primary challenge lies in simultaneously achieving two objectives: generating adversarial patches that effectively mislead object detection systems while determining contextually appropriate deployment within the scene. We propose MAGIC (Mastering Physical Adversarial Generation In Context), a novel framework powered by multi-modal LLM agents to address these challenges. MAGIC automatically understands scene context and generates adversarial patch through the synergistic interaction of language and vision capabilities. In particular, MAGIC orchestrates three specialized LLM agents: The adv-patch generation agent (GAgent) masters the creation of deceptive patches through strategic prompt engineering for text-to-image models. The adv-patch deployment agent (DAgent) ensures contextual coherence by determining optimal deployment strategies based on scene understanding. The self-examination agent (EAgent) completes this trilogy by providing critical oversight and iterative refinement of both processes. We validate our method on both digital and physical levels, i.e., nuImage and manually captured real-world scenes, where both statistical and visual results prove that our MAGIC is powerful and effective for attacking widely applied object detection systems, i.e., YOLO and DETR series.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。