arXiv:2505.08835cs.CRcs.AI2025-05被引 2

研究无人商店视觉系统如何被对抗补丁攻击干扰,提出新防御思路。

Robustness Analysis against Adversarial Patch Attacks in Fully Unmanned Stores

  • 设计三类物理环境下的对抗补丁攻击:隐藏、制造、篡改目标物体。
  • 引入颜色直方图相似性损失,提升攻击成功率;实测在真实场景中有效。
  • 适用于安全评估、模型鲁棒性研究者,尤其关注无人零售安防的团队。

基于人工智能的全自动结账系统推动了无人商店的发展,但其存在固有的安全漏洞,易受物理环境中对抗补丁攻击的影响。本研究揭示了对抗补丁可严重干扰无人商店中的目标检测模型,导致盗窃、库存错误等问题。我们分析了三类攻击——隐藏、创建与篡改,并提出一种利用目标类别颜色信息的新颖颜色直方图相似性损失函数。除传统混淆矩阵评估外,还引入基于边界框的指标以衡量实际影响。实验在数字环境训练的零食与水果检测模型上进行,随后在模拟真实无人商店(含RGB摄像头与现实条件)的物理测试平台上验证。进一步评估了黑盒场景下的攻击效果,发现影子攻击可在无模型参数访问的情况下提升攻击成功率。研究强调需构建更强防御机制,指出现有实时检测系统防御能力不足,并提出多种主动防护策略,为提升目标检测模型鲁棒性、强化无人零售安全提供关键洞见。

原文摘要 · Abstract (English)

The advent of convenient and efficient fully unmanned stores equipped with artificial intelligence-based automated checkout systems marks a new era in retail. However, these systems have inherent artificial intelligence security vulnerabilities, which are exploited via adversarial patch attacks, particularly in physical environments. This study demonstrated that adversarial patches can severely disrupt object detection models used in unmanned stores, leading to issues such as theft, inventory discrepancies, and interference. We investigated three types of adversarial patch attacks -- Hiding, Creating, and Altering attacks -- and highlighted their effectiveness. We also introduce the novel color histogram similarity loss function by leveraging attacker knowledge of the color information of a target class object. Besides the traditional confusion-matrix-based attack success rate, we introduce a new bounding-boxes-based metric to analyze the practical impact of these attacks. Starting with attacks on object detection models trained on snack and fruit datasets in a digital environment, we evaluated the effectiveness of adversarial patches in a physical testbed that mimicked a real unmanned store with RGB cameras and realistic conditions. Furthermore, we assessed the robustness of these attacks in black-box scenarios, demonstrating that shadow attacks can enhance success rates of attacks even without direct access to model parameters. Our study underscores the necessity for robust defense strategies to protect unmanned stores from adversarial threats. Highlighting the limitations of the current defense mechanisms in real-time detection systems and discussing various proactive measures, we provide insights into improving the robustness of object detection models and fortifying unmanned retail environments against these attacks.

对抗攻击无人商店目标检测安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。