提出可物理实施的对抗补丁攻击,专攻多模态大模型自动驾驶系统。
PhysPatch: A Physically Realizable and Transferable Adversarial Patch Attack for Multimodal Large Language Models-based Autonomous Driving Systems
- 联合优化补丁位置、形状与内容,提升攻击效果。
- 在多个大模型上实现高迁移性,成功诱导错误决策。
- 补丁置于真实场景可行区域,具备实际部署潜力。
多模态大语言模型(MLLMs)凭借强大的视觉-语言推理能力,正成为自动驾驶系统的核心组件。然而,这类模型易受对抗攻击,尤其是对抗补丁攻击,在真实场景中构成严重威胁。现有补丁攻击方法主要针对目标检测模型,难以有效迁移到架构复杂、具备推理能力的MLLM系统。为此,我们提出PhysPatch,一种专为基于MLLM的自动驾驶系统设计的可物理实现且高迁移性的对抗补丁攻击框架。该方法通过语义掩码初始化实现逼真布局,采用SVD引导的局部对齐损失结合补丁引导的裁剪-缩放策略增强迁移性,并引入势场法进行掩码精细化。在开源、商用及具备推理能力的MLLM上广泛实验表明,PhysPatch显著优于现有方法,能有效引导系统生成目标感知与规划输出。同时,补丁始终位于自动驾驶场景中物理可行区域,确保强现实适用性与可部署性。
原文摘要 · Abstract (English)
Multimodal Large Language Models (MLLMs) are becoming integral to autonomous driving (AD) systems due to their strong vision-language reasoning capabilities. However, MLLMs are vulnerable to adversarial attacks, particularly adversarial patch attacks, which can pose serious threats in real-world scenarios. Existing patch-based attack methods are primarily designed for object detection models and perform poorly when transferred to MLLM-based systems due to the latter's complex architectures and reasoning abilities. To address these limitations, we propose PhysPatch, a physically realizable and transferable adversarial patch framework tailored for MLLM-based AD systems. PhysPatch jointly optimizes patch location, shape, and content to enhance attack effectiveness and real-world applicability. It introduces a semantic-based mask initialization strategy for realistic placement, an SVD-based local alignment loss with patch-guided crop-resize to improve transferability, and a potential field-based mask refinement method. Extensive experiments across open-source, commercial, and reasoning-capable MLLMs demonstrate that PhysPatch significantly outperforms prior methods in steering MLLM-based AD systems toward target-aligned perception and planning outputs. Moreover, PhysPatch consistently places adversarial patches in physically feasible regions of AD scenes, ensuring strong real-world applicability and deployability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。