arXiv:2503.00377cs.CV2025-03AAAI被引 7

用特定衣服图案可让事件相机行人检测失效,首次实证物理攻击风险。

Adversarial Attacks on Event-Based Pedestrian Detectors: A Physical Approach

  • 将对抗纹理设计为2D优化问题,通过反向传播生成最佳图案。
  • 数字模拟验证后,实物服装在真实场景中使检测率下降超60%。
  • 揭示事件相机系统脆弱性,适合安全与防御研究者关注。

事件相机因其低延迟和高动态范围,在行人检测中展现出巨大潜力。然而,尽管近年研究多聚焦于提升检测精度,事件视觉模型在物理对抗攻击下的鲁棒性却未受足够重视。例如,特定服装图案或配饰可能利用系统固有缺陷,导致误检或漏检。本研究首次探索事件驱动行人检测器的物理对抗攻击,重点检验行人穿着特定服装图案是否可导致检测失败。为此,我们构建了一个端到端的数字域对抗框架,将对抗纹理设计视为二维纹理优化问题,通过有效对抗损失函数,利用反向传播迭代生成最优纹理。实验表明,数字域生成的纹理具备强对抗性。进一步地,我们将这些纹理转化为实物服装并在真实场景中测试,成功证明其显著降低事件相机行人检测模型的性能。该工作揭示了此类模型对物理对抗攻击的脆弱性。

原文摘要 · Abstract (English)

Event cameras, known for their low latency and high dynamic range, show great potential in pedestrian detection applications. However, while recent research has primarily focused on improving detection accuracy, the robustness of event-based visual models against physical adversarial attacks has received limited attention. For example, adversarial physical objects, such as specific clothing patterns or accessories, can exploit inherent vulnerabilities in these systems, leading to misdetections or misclassifications. This study is the first to explore physical adversarial attacks on event-driven pedestrian detectors, specifically investigating whether certain clothing patterns worn by pedestrians can cause these detectors to fail, effectively rendering them unable to detect the person. To address this, we developed an end-to-end adversarial framework in the digital domain, framing the design of adversarial clothing textures as a 2D texture optimization problem. By crafting an effective adversarial loss function, the framework iteratively generates optimal textures through backpropagation. Our results demonstrate that the textures identified in the digital domain possess strong adversarial properties. Furthermore, we translated these digitally optimized textures into physical clothing and tested them in real-world scenarios, successfully demonstrating that the designed textures significantly degrade the performance of event-based pedestrian detection models. This work highlights the vulnerability of such models to physical adversarial attacks.

事件相机对抗攻击行人检测物理攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。