arXiv:2502.18724cs.CVcs.CR2025-02被引 2

用贴纸生成通用对抗扰动,骗过交通标志识别系统

Adversarial Universal Stickers: Universal Perturbation Attacks on Traffic Sign using Stickers

  • 设计可通用的黑白贴纸扰动,一张贴纸适配所有交通标志
  • 在虚拟街景数据集上攻击成功率超90%,稳定误导模型
  • 为自动驾驶安全提供真实威胁演示,适合关注防御的研究者

近年来,深度学习模型的对抗攻击不断增多。传统方法需为每张图像设计不同扰动才能导致误分类,效率低下。而通用扰动研究致力于设计一种可应用于数据集中所有图像的单一扰动,从而引发模型误判。本文将通用扰动拓展至交通标志与自动驾驶系统场景,提出一种新方法:生成外观如黑白贴纸的通用扰动,可任意粘贴于任何交通标志上,均能导致模型错误识别。与传统扰动不同,该贴纸具备普适性——同一贴纸、相同位置即可作用于各类标志。为安全开展实验,本文构建基于街景图像的虚拟测试环境,避免物理修改标志。实验表明,该贴纸在美交通标志数据集上持续误导主流识别模型,攻击成功率高,揭示了简单贴纸对自动驾驶系统的实际安全威胁,凸显对手轻易生成通用对抗贴纸的能力。

原文摘要 · Abstract (English)

Adversarial attacks on deep learning models have proliferated in recent years. In many cases, a different adversarial perturbation is required to be added to each image to cause the deep learning model to misclassify it. This is ineffective as each image has to be modified in a different way. Meanwhile, research on universal perturbations focuses on designing a single perturbation that can be applied to all images in a data set, and cause a deep learning model to misclassify the images. This work advances the field of universal perturbations by exploring universal perturbations in the context of traffic signs and autonomous vehicle systems. This work introduces a novel method for generating universal perturbations that visually look like simple black and white stickers, and using them to cause incorrect street sign predictions. Unlike traditional adversarial perturbations, the adversarial universal stickers are designed to be applicable to any street sign: same sticker, or stickers, can be applied in same location to any street sign and cause it to be misclassified. Further, to enable safe experimentation with adversarial images and street signs, this work presents a virtual setting that leverages Street View images of street signs, rather than the need to physically modify street signs, to test the attacks. The experiments in the virtual setting demonstrate that these stickers can consistently mislead deep learning models used commonly in street sign recognition, and achieve high attack success rates on dataset of US traffic signs. The findings highlight the practical security risks posed by simple stickers applied to traffic signs, and the ease with which adversaries can generate adversarial universal stickers that can be applied to many street signs.

对抗攻击交通标志通用扰动自动驾驶

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。