arXiv:2504.10888cs.CVcs.AI2025-04中稿 · ACMMM 2025被引 11

用颜色控制热响应,实现跨场景红外可见光检测器的通用对抗攻击

CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared Detectors

  • 通过颜色映射生成可统一优化的跨模态对抗补丁
  • 在四个数据集上数字攻击成功率超现有方法,物理测试中跨尺度转移性强
  • 适合研究对抗攻击、多模态检测鲁棒性的研究人员

对抗补丁被广泛用于评估真实场景下目标检测系统的鲁棒性。这类补丁最初针对单模态检测器(如可见光或红外),近期扩展至可见光-红外双模态检测器。然而,现有双模态对抗补丁在多样物理场景中攻击效果有限。为此,我们提出CDUPatch,一种针对可见光-红外目标检测器在不同尺度、视角和场景下的通用跨模态补丁攻击方法。具体地,我们发现颜色变化导致热吸收差异,从而引起红外成像中的温度差异。基于此,提出一个RGB-to-infrared适配器,将RGB补丁映射为红外补丁,实现跨模态补丁的统一优化。通过学习最优颜色分布,可调控补丁的热响应并生成对抗性红外纹理。此外,引入多尺度裁剪策略,并构建新数据集MSDrone,包含不同尺度和视角的航拍车辆图像。这些数据增强策略提升了补丁在真实条件下的鲁棒性。在四个基准数据集(如DroneVehicle、LLVIP、VisDrone、MSDrone)上的实验表明,本方法在数字域优于现有补丁攻击。大量物理测试进一步验证其在尺度、视角和场景间的强迁移能力。

原文摘要 · Abstract (English)

Adversarial patches are widely used to evaluate the robustness of object detection systems in real-world scenarios. These patches were initially designed to deceive single-modal detectors (e.g., visible or infrared) and have recently been extended to target visible-infrared dual-modal detectors. However, existing dual-modal adversarial patch attacks have limited attack effectiveness across diverse physical scenarios. To address this, we propose CDUPatch, a universal cross-modal patch attack against visible-infrared object detectors across scales, views, and scenarios. Specifically, we observe that color variations lead to different levels of thermal absorption, resulting in temperature differences in infrared imaging. Leveraging this property, we propose an RGB-to-infrared adapter that maps RGB patches to infrared patches, enabling unified optimization of cross-modal patches. By learning an optimal color distribution on the adversarial patch, we can manipulate its thermal response and generate an adversarial infrared texture. Additionally, we introduce a multi-scale clipping strategy and construct a new visible-infrared dataset, MSDrone, which contains aerial vehicle images in varying scales and perspectives. These data augmentation strategies enhance the robustness of our patch in real-world conditions. Experiments on four benchmark datasets (e.g., DroneVehicle, LLVIP, VisDrone, MSDrone) show that our method outperforms existing patch attacks in the digital domain. Extensive physical tests further confirm strong transferability across scales, views, and scenarios.

对抗攻击多模态检测红外成像通用补丁

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。