arXiv:2503.12567cs.CV2025-03被引 2

用生成对抗网络防御交通标志的对抗贴纸攻击,提升识别准确率90%。

GAN-Based Single-Stage Defense for Traffic Sign Classification Under Adversarial Patch

  • 基于GAN设计单阶段防御,无需预知贴纸样式即可应对多种攻击。
  • 在各类交通标志上使分类准确率提升最高达90%,整体提升55%。
  • 计算高效、模型无关,适合自动驾驶系统实时部署。

计算机视觉在保障自动驾驶车辆安全导航中起关键作用,感知模块可识别交通标志、信号灯及道路使用者。然而,该模块易受对抗攻击影响,特别是对抗贴纸攻击(APA),即攻击者在物体上放置特制贴纸以欺骗分类器,导致误识别,引发严重事故。为增强自动驾驶感知系统的安全性,本文提出一种基于生成对抗网络(GAN)的单阶段防御策略,用于抵御不同类别交通标志上的APA。该方法无需事先了解贴纸设计,对不同尺寸贴纸均有效。相比多阶段防御,本方法计算开销更低,更适合实时部署。实验表明,在所研究的交通标志类别中,该防御策略使分类准确率最高提升90%,所有交通标志的整体准确率提升55%。该防御策略具备模型无关性,可适用于任意交通标志分类模型。

原文摘要 · Abstract (English)

Computer vision plays a critical role in ensuring the safe navigation of autonomous vehicles (AVs). An AV perception module facilitates safe navigation. This module enables AVs to recognize traffic signs, traffic lights, and various road users. However, the perception module is vulnerable to adversarial attacks, which can compromise its accuracy and reliability. One such attack is the adversarial patch attack (APA), an attack in which an adversary strategically places a specially crafted sticker on an object to deceive object classifiers. Such an APA can cause AVs to misclassify traffic signs, leading to catastrophic incidents. To enhance the security of an AV perception system against APAs, this study develops a Generative Adversarial Network (GAN)-based single-stage defense strategy for traffic sign classification. This approach is tailored to defend against APAs across different classes of traffic signs, without prior knowledge of a patch's design, and is effective against patches of varying sizes. In addition, our single-stage defense is computationally efficient, requiring significantly lower computation time than existing multi-stage defenses, making it suitable for real-time deployment in autonomous driving systems. Compared to a classifier without any defense mechanism, our experimental analysis demonstrates that the defense strategy presented in this paper improves our classifier's accuracy under APA conditions by up to 90% considering the traffic sign classes considered in this study. and overall classification accuracy is enhanced by 55% for all traffic signs considered in this study. Our defense strategy is model agnostic, making it applicable to any traffic sign classifier, regardless of the underlying classification model.

对抗攻击GAN防御自动驾驶交通标志

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。