arXiv:2501.08258cs.CVcs.CR2025-01

用投影在物理世界直接生成对抗补丁,解决打印贴纸效果差的问题。

Towards an End-to-End (E2E) Adversarial Learning and Application in the Physical World

  • 通过投影器实现物理域端到端对抗学习,无需数字域预训练。
  • 实测在户外真实场景中成功欺骗目标检测器,成功率显著提升。
  • 适合研究物理攻击的学者,或需高鲁棒性对抗样本的场景。

传统的基于补丁的对抗攻击通常在数字域生成后通过打印贴纸应用于物理世界,但因数字到物理的迁移能力有限而性能下降。已有研究尝试使用投影仪实施攻击,因此我们提出:能否完全在物理域内进行对抗学习(即补丁生成)?本文提出物理域对抗补丁学习增强框架(PAPLA),首次实现基于投影仪的端到端(E2E)物理域对抗学习。我们在控制实验室与真实户外环境中评估PAPLA,结果表明其攻击成功率显著优于传统数字学习-物理应用(DL-PA)方法。我们还分析了投影表面颜色、投影强度、环境光、距离及目标相对相机角度等环境因素对投影补丁有效性的影响。最终,在真实户外环境下成功对停放汽车和停车标志实施攻击。实验显示,在特定条件下,物理域端到端学习可消除迁移问题,确保绕过目标检测器。本文还探讨了物理域对抗学习的挑战与机遇,并指出该方法在某些场景下优于贴纸方案。

原文摘要 · Abstract (English)

The traditional learning process of patch-based adversarial attacks, conducted in the digital domain and then applied in the physical domain (e.g., via printed stickers), may suffer from reduced performance due to adversarial patches' limited transferability from the digital domain to the physical domain. Given that previous studies have considered using projectors to apply adversarial attacks, we raise the following question: can adversarial learning (i.e., patch generation) be performed entirely in the physical domain with a projector? In this work, we propose the Physical-domain Adversarial Patch Learning Augmentation (PAPLA) framework, a novel end-to-end (E2E) framework that converts adversarial learning from the digital domain to the physical domain using a projector. We evaluate PAPLA across multiple scenarios, including controlled laboratory settings and realistic outdoor environments, demonstrating its ability to ensure attack success compared to conventional digital learning-physical application (DL-PA) methods. We also analyze the impact of environmental factors, such as projection surface color, projector strength, ambient light, distance, and angle of the target object relative to the camera, on the effectiveness of projected patches. Finally, we demonstrate the feasibility of the attack against a parked car and a stop sign in a real-world outdoor environment. Our results show that under specific conditions, E2E adversarial learning in the physical domain eliminates the transferability issue and ensures evasion by object detectors. Finally, we provide insights into the challenges and opportunities of applying adversarial learning in the physical domain and explain where such an approach is more effective than using a sticker.

对抗攻击物理世界投影攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。