arXiv:2507.18484cs.CVcs.AI2025-07TPAMI被引 5

提出主动防御框架,通过环境互动提升3D视觉系统的抗攻击能力。

Reinforced Embodied Active Defense: Exploiting Adaptive Interaction for Robust Visual Perception in Adversarial 3D Environments

  • 采用多步目标优化,结合准确率与预测熵最小化实现自适应防御。
  • 在多个任务中将攻击成功率显著降低,同时保持正常任务精度。
  • 适合复杂动态场景,如自动驾驶、人脸识别等实际应用。

三维环境中对抗攻击已成为影响视觉感知系统可靠性的重要威胁,尤其在身份验证和自动驾驶等安全敏感场景中。此类攻击利用对抗补丁和三维物体,通过复杂场景中的漏洞操纵深度神经网络(DNN)预测。现有防御方法如对抗训练和净化主要依赖被动策略,常需预设对抗手法假设,难以适应动态三维环境。为此,本文提出强化具身主动防御(Rein-EAD),一种通过环境自适应探索与交互提升感知鲁棒性的主动防御框架。该框架采用多步目标,平衡即时预测准确率与预测熵最小化,优化多步时间窗内的防御策略。此外,引入基于不确定性的奖励重塑机制,高效更新策略,降低计算开销,无需可微环境即可部署。大量实验验证了Rein-EAD的有效性,在多种任务中显著降低攻击成功率,同时维持标准准确率。值得注意的是,其对未见过的自适应攻击具有强泛化能力,适用于三维物体分类、人脸识别及自动驾驶等真实复杂任务。

原文摘要 · Abstract (English)

Adversarial attacks in 3D environments have emerged as a critical threat to the reliability of visual perception systems, particularly in safety-sensitive applications such as identity verification and autonomous driving. These attacks employ adversarial patches and 3D objects to manipulate deep neural network (DNN) predictions by exploiting vulnerabilities within complex scenes. Existing defense mechanisms, such as adversarial training and purification, primarily employ passive strategies to enhance robustness. However, these approaches often rely on pre-defined assumptions about adversarial tactics, limiting their adaptability in dynamic 3D settings. To address these challenges, we introduce Reinforced Embodied Active Defense (Rein-EAD), a proactive defense framework that leverages adaptive exploration and interaction with the environment to improve perception robustness in 3D adversarial contexts. By implementing a multi-step objective that balances immediate prediction accuracy with predictive entropy minimization, Rein-EAD optimizes defense strategies over a multi-step horizon. Additionally, Rein-EAD involves an uncertainty-oriented reward-shaping mechanism that facilitates efficient policy updates, thereby reducing computational overhead and supporting real-world applicability without the need for differentiable environments. Comprehensive experiments validate the effectiveness of Rein-EAD, demonstrating a substantial reduction in attack success rates while preserving standard accuracy across diverse tasks. Notably, Rein-EAD exhibits robust generalization to unseen and adaptive attacks, making it suitable for real-world complex tasks, including 3D object classification, face recognition and autonomous driving.

主动防御3D对抗强化学习视觉鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。