黑盒攻击可让基于CNN的SLAM系统76%帧失效,深度图攻击更致命。
Black-box Adversarial Attacks on CNN-based SLAM Algorithms
- 对RGB图像施加黑盒扰动,破坏GCN-SLAM特征检测
- 中等规模攻击导致TUM数据集76%帧追踪失败
- 攻击深度图比攻击RGB图像危害更大,易引发系统崩溃
深度学习持续推动特征检测进步,提升了同时定位与地图构建(SLAM)的精度。然而,深度神经网络易受对抗攻击的影响,制约其在自动驾驶导航等场景中的可靠部署。尽管基于卷积神经网络(CNN)的SLAM算法日益受到关注,但针对其中特征检测器的对抗攻击仍缺乏系统研究。本文针对GCN-SLAM算法,对输入的RGB图像施加黑盒对抗扰动。在TUM数据集上的实验表明,即使中等规模的攻击,也能导致高达76%的帧出现追踪失败。此外,实验还揭示了攻击深度图而非RGB图像对SLAM系统造成更严重的灾难性影响。
原文摘要 · Abstract (English)
Continuous advancements in deep learning have led to significant progress in feature detection, resulting in enhanced accuracy in tasks like Simultaneous Localization and Mapping (SLAM). Nevertheless, the vulnerability of deep neural networks to adversarial attacks remains a challenge for their reliable deployment in applications, such as navigation of autonomous agents. Even though CNN-based SLAM algorithms are a growing area of research there is a notable absence of a comprehensive presentation and examination of adversarial attacks targeting CNN-based feature detectors, as part of a SLAM system. Our work introduces black-box adversarial perturbations applied to the RGB images fed into the GCN-SLAM algorithm. Our findings on the TUM dataset [30] reveal that even attacks of moderate scale can lead to tracking failure in as many as 76% of the frames. Moreover, our experiments highlight the catastrophic impact of attacking depth instead of RGB input images on the SLAM system.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。