用荧光墨水在交通标志上设隐蔽后门,让自动驾驶系统误判。
FIGhost: Fluorescent Ink-based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition
- 用紫外线激活的荧光墨水做触发器,肉眼不可见且难追踪。
- 攻击在真实环境中对主流检测器和视觉大模型均有效,抗干扰强。
- 适合研究对抗攻击或自动驾驶安全的学者与工程师。
交通标志识别(TSR)系统对自动驾驶至关重要,但易受后门攻击。现有物理后门攻击或缺乏隐蔽性、控制不灵活,或忽略新兴的视觉-大语言模型(VLM)。本文提出FIGhost,首个基于荧光墨水的物理世界后门攻击。荧光触发器在正常光照下不可见,仅在紫外光下激活,具备优异隐蔽性、灵活性与不可追溯性。受现实涂鸦启发,设计逼真触发形状,并通过基于插值的荧光仿真算法增强鲁棒性。此外,开发自动化后门样本生成方法,支持三种攻击目标。大量物理世界实验证明,FIGhost对先进检测器和VLM均有效,能在环境变化下保持稳定,且可有效规避现有防御机制。
原文摘要 · Abstract (English)
Traffic sign recognition (TSR) systems are crucial for autonomous driving but are vulnerable to backdoor attacks. Existing physical backdoor attacks either lack stealth, provide inflexible attack control, or ignore emerging Vision-Large-Language-Models (VLMs). In this paper, we introduce FIGhost, the first physical-world backdoor attack leveraging fluorescent ink as triggers. Fluorescent triggers are invisible under normal conditions and activated stealthily by ultraviolet light, providing superior stealthiness, flexibility, and untraceability. Inspired by real-world graffiti, we derive realistic trigger shapes and enhance their robustness via an interpolation-based fluorescence simulation algorithm. Furthermore, we develop an automated backdoor sample generation method to support three attack objectives. Extensive evaluations in the physical world demonstrate FIGhost's effectiveness against state-of-the-art detectors and VLMs, maintaining robustness under environmental variations and effectively evading existing defenses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。