arXiv:2412.09150cs.CVcs.LG2024-12ICML被引 2

对比不同模型对交通标志攻击的敏感性,发现标准基线更易受攻击。

Evaluating Adversarial Attacks on Traffic Sign Classifiers beyond Standard Baselines

  • 分离模型与数据集,测试通用模型在攻击下的表现
  • 标准基线模型比通用模型更易被攻击,差异显著
  • 建议未来评估攻击时覆盖更广泛的模型基准

交通标志分类模型的对抗攻击是最早在现实世界中成功应用的案例之一。此后该领域研究多局限于重复使用如LISA-CNN或GTSRB-CNN等基线模型及相似实验设置,包括在交通标志上添加白色或黑色贴纸。本文将模型架构与数据集解耦,评估更通用的模型以实现公平比较。同时,对比了隐蔽型与可见型攻击设置,这些通常未被直接比较。结果表明,LISA-CNN或GTSRB-CNN等标准基线模型显著比通用模型更易受攻击。因此,我们建议未来评估新攻击时应覆盖更广泛的基线模型。代码已公开于https://github.com/KASTEL-MobilityLab/attacks-on-traffic-sign-recognition/。

原文摘要 · Abstract (English)

Adversarial attacks on traffic sign classification models were among the first successfully tried in the real world. Since then, the research in this area has been mainly restricted to repeating baseline models, such as LISA-CNN or GTSRB-CNN, and similar experiment settings, including white and black patches on traffic signs. In this work, we decouple model architectures from the datasets and evaluate on further generic models to make a fair comparison. Furthermore, we compare two attack settings, inconspicuous and visible, which are usually regarded without direct comparison. Our results show that standard baselines like LISA-CNN or GTSRB-CNN are significantly more susceptible than the generic ones. We, therefore, suggest evaluating new attacks on a broader spectrum of baselines in the future. Our code is available at \url{https://github.com/KASTEL-MobilityLab/attacks-on-traffic-sign-recognition/}.

对抗攻击交通标志模型评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。