arXiv:2508.05414cs.CV2025-08IJCAI被引 6

通过梯度校准与去相关,提升物理对抗伪装的攻击成功率。

Physical Adversarial Camouflage through Gradient Calibration and Regularization

  • 用梯度校准确保不同距离下纹理更新一致
  • 多角度优化中通过梯度去相关提升稳定性和成功率
  • 实测在多种场景下攻击成功率提升超10%、适合安全测试

深度目标检测技术的进展对自动驾驶等安全关键领域影响深远。然而,物理对抗伪装通过改变物体表面纹理,可严重威胁系统安全。现有方法在真实环境中表现受限,主要面临两大挑战:一是不同距离导致采样点密度不一,阻碍梯度优化的局部连续性;二是多角度更新纹理梯度时产生冲突,降低优化稳定性与攻击效果。为此,我们提出一种基于梯度优化的新型对抗伪装框架。首先引入梯度校准策略,通过将稀疏采样点的梯度传播至未采样点,确保跨距离梯度更新一致性。其次设计梯度去相关方法,依据损失值优先级并正交化梯度,消除冗余或冲突更新,增强多角度优化的稳定性与有效性。大量实验结果表明,该方法在多个检测模型、角度和距离条件下显著超越现有技术,平均攻击成功率(ASR)在距离上提升13.46%,在角度上提升11.03%。此外,真实场景评估凸显了系统设计需更强鲁棒性。

原文摘要 · Abstract (English)

The advancement of deep object detectors has greatly affected safety-critical fields like autonomous driving. However, physical adversarial camouflage poses a significant security risk by altering object textures to deceive detectors. Existing techniques struggle with variable physical environments, facing two main challenges: 1) inconsistent sampling point densities across distances hinder the gradient optimization from ensuring local continuity, and 2) updating texture gradients from multiple angles causes conflicts, reducing optimization stability and attack effectiveness. To address these issues, we propose a novel adversarial camouflage framework based on gradient optimization. First, we introduce a gradient calibration strategy, which ensures consistent gradient updates across distances by propagating gradients from sparsely to unsampled texture points. Additionally, we develop a gradient decorrelation method, which prioritizes and orthogonalizes gradients based on loss values, enhancing stability and effectiveness in multi-angle optimization by eliminating redundant or conflicting updates. Extensive experimental results on various detection models, angles and distances show that our method significantly exceeds the state of the art, with an average increase in attack success rate (ASR) of 13.46% across distances and 11.03% across angles. Furthermore, empirical evaluation in real-world scenarios highlights the need for more robust system design.

对抗攻击物理安全目标检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。