arXiv:2502.08374cs.CV2025-02被引 6

用高频信息替换生成隐蔽对抗样本,骗过自动驾驶感知系统

AdvSwap: Covert Adversarial Perturbation with High Frequency Info-swapping for Autonomous Driving Perception

  • 基于小波变换的高频信息交换,实现隐蔽攻击
  • 在GTSRB和nuScenes上成功欺骗交通标志识别,人眼难察觉
  • 适合研究自动驾驶安全漏洞或防御机制的人员

自动驾驶车辆的感知模块日益易受对抗性攻击,此类攻击利用神经网络漏洞,通过对抗输入威胁AI安全。现有全局噪声方法易被检测,且难以欺骗人类视觉系统。本文提出新型攻击方法AdvSwap,创新性地采用小波变换进行高频信息交换,生成隐蔽对抗样本并欺骗摄像头。AdvSwap利用可逆神经网络实现选择性高频信息替换,保持前向传播与数据完整性,有效移除原始标签数据并融入引导图像信息,生成隐蔽且鲁棒的对抗样本。在GTSRB和nuScenes数据集上的实验表明,该方法能对常见交通目标实施隐蔽攻击,生成样本既难被人眼察觉,也难被算法识别,同时具备强攻击鲁棒性和迁移能力。

原文摘要 · Abstract (English)

Perception module of Autonomous vehicles (AVs) are increasingly susceptible to be attacked, which exploit vulnerabilities in neural networks through adversarial inputs, thereby compromising the AI safety. Some researches focus on creating covert adversarial samples, but existing global noise techniques are detectable and difficult to deceive the human visual system. This paper introduces a novel adversarial attack method, AdvSwap, which creatively utilizes wavelet-based high-frequency information swapping to generate covert adversarial samples and fool the camera. AdvSwap employs invertible neural network for selective high-frequency information swapping, preserving both forward propagation and data integrity. The scheme effectively removes the original label data and incorporates the guidance image data, producing concealed and robust adversarial samples. Experimental evaluations and comparisons on the GTSRB and nuScenes datasets demonstrate that AdvSwap can make concealed attacks on common traffic targets. The generates adversarial samples are also difficult to perceive by humans and algorithms. Meanwhile, the method has strong attacking robustness and attacking transferability.

对抗攻击自动驾驶隐蔽攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。