让刚体模拟器失效:设计看似刚性实则易变形的对抗物体
Rigid Body Adversarial Attacks
- 通过优化构造与原物体几何和惯量一致的对抗物体
- 在刚体模拟中行为相同,但在可变形模拟中轨迹差异显著
- 适用于检验物理仿真系统鲁棒性,适合仿真安全研究者
由于性能优异且实现简单,刚体模拟器常被用于处理看似刚性的物体。然而,现实中无物质具有无限刚度,因此看似刚性的物体在可变形模拟中可能因非零柔度导致轨迹显著差异。受图像分类对抗攻击启发,本文提出针对刚体模拟器的对抗攻击方法:通过求解优化问题,构造出在碰撞几何和质量矩上与参考物体一致的感知刚性对抗物体,使其在刚体模拟中表现一致,但在更精确的可变形模拟中产生最大差异。我们在多个商用模拟器中验证了该方法的有效性。
原文摘要 · Abstract (English)
Due to their performance and simplicity, rigid body simulators are often used in applications where the objects of interest can considered very stiff. However, no material has infinite stiffness, which means there are potentially cases where the non-zero compliance of the seemingly rigid object can cause a significant difference between its trajectories when simulated in a rigid body or deformable simulator. Similarly to how adversarial attacks are developed against image classifiers, we propose an adversarial attack against rigid body simulators. In this adversarial attack, we solve an optimization problem to construct perceptually rigid adversarial objects that have the same collision geometry and moments of mass to a reference object, so that they behave identically in rigid body simulations but maximally different in more accurate deformable simulations. We demonstrate the validity of our method by comparing simulations of several examples in commercially available simulators.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。