提出标准化框架,让物理攻击更可复现、可比较。
Revisiting Physically Realizable Adversarial Object Attack against LiDAR-based Detection: Clarifying Problem Formulation and Experimental Protocols
- 构建设备无关的统一攻击框架,抽象物理攻击关键要素。
- 实验证明仿真攻击可成功迁移至真实激光雷达系统。
- 适合关注车载感知安全与对抗鲁棒性的研究者。
激光雷达3D目标检测的对抗鲁棒性因其在现实场景中的广泛应用而至关重要。尽管已有大量数字攻击通过操纵点云或网格实现,但这些方法常缺乏物理可实现性,实际影响有限。物理对抗物体攻击仍研究不足,且因实验设置不一致与硬件差异导致结果难以复现。为此,我们提出一种设备无关、标准化的框架,抽象物理对抗物体攻击的关键要素,支持多种方法,并提供开源代码与仿真及真实环境下的基准测试协议。该框架实现了公平比较,加速了研究进展,并通过将仿真攻击成功迁移至真实激光雷达系统得到验证。此外,我们还深入分析了影响攻击成功率的因素,深化了对真实世界激光雷达感知中对抗鲁棒性的理解。
原文摘要 · Abstract (English)
Adversarial robustness in LiDAR-based 3D object detection is a critical research area due to its widespread application in real-world scenarios. While many digital attacks manipulate point clouds or meshes, they often lack physical realizability, limiting their practical impact. Physical adversarial object attacks remain underexplored and suffer from poor reproducibility due to inconsistent setups and hardware differences. To address this, we propose a device-agnostic, standardized framework that abstracts key elements of physical adversarial object attacks, supports diverse methods, and provides open-source code with benchmarking protocols in simulation and real-world settings. Our framework enables fair comparison, accelerates research, and is validated by successfully transferring simulated attacks to a physical LiDAR system. Beyond the framework, we offer insights into factors influencing attack success and advance understanding of adversarial robustness in real-world LiDAR perception.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。