提出可打印的3D高斯对抗包裹,真实且鲁棒地攻击自动驾驶视觉系统。
3DGAA: Realistic and Robust 3D Gaussian-based Adversarial Attack for Autonomous Driving
- 用3D高斯溅射建模,多视角优化保持视觉一致性。
- 在多个检测器上实现检测置信度与平均精度显著下降。
- 适合安全评估、防御设计与信息取证领域研究人员参考。
基于摄像头的车联网与自动驾驶感知仍易受物理对抗攻击。以往攻击要么优化图像平面纹理,破坏跨视角一致性;要么依赖难以制作和部署的形状修改。本文提出一种以可制造性为先的框架,学习视图一致且几何不变的车辆对抗包裹。方法通过3D高斯溅射代理进行三维多视角优化,对视角、光照和遮挡的期望下保持一致性,最终生成仅含打印纹理的实体物,不改变车辆原始几何结构。在匹配的CARLA仿真、小型车辆实物实验及多个现代检测器上验证。包裹在多视角下显著且稳定降低检测置信度与平均精度,同时保持感知真实性。消融实验分析了物理滤波、物理增强与形状一致性正则的影响,效率分析报告收敛时间与内存占用。额外实验包括攻击成功率(ASR)、mIoU分割退化、跨检测器迁移攻击、扰动面积公平性诊断及常见输入预处理防御下的鲁棒性。通过三维优化与几何保持的结合,本研究为安全关键自动驾驶系统的感知压力测试提供了可行路径,并为信息取证与安全评估提供依据。
原文摘要 · Abstract (English)
Camera-based perception in connected and autonomous vehicles remains exposed to physical adversarial attacks. Prior attacks often either optimize image-plane textures, weakening cross-view consistency, or rely on shape modifications that are difficult to fabricate and deploy. Both cases limit their value for security and safety assessment of camera-based perception. This paper introduces a fabrication-first framework that learns view-consistent, geometry-preserving adversarial wraps for vehicles. The method performs three-dimensional multi-view optimization with a 3D Gaussian splatting surrogate to enforce consistency under an expectation over viewpoint, illumination, and occlusion, while the final artifact is constrained to print-only textures that keep vehicle geometry unchanged. We evaluate the framework through matched CARLA simulations, controlled miniature-vehicle physical evidence, and tests on multiple modern detectors. The wraps produce substantial and stable reductions in detection confidence and average precision across views while maintaining perceptual realism. Ablation studies isolate the effects of physical filtering, physical augmentation, and shape-consistency regularization, while efficiency analyses report convergence time and memory profiles. Additional experiments report ASR, mIoU-based segmentation degradation, cross-detector transfer against physical attack baselines, perturbation-area fairness diagnostics, and robustness under common input preprocessing defenses. By coupling three-dimensional optimization with a geometry-preserving realization, the study supports a practical pathway to systematically stress-test camera perception in safety-critical autonomous driving systems and provides evidence that can inform defense design and evaluation protocols in information forensics and security.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。