arXiv:2508.10600cs.CV2025-08

提出更贴近真实场景的攻击评估方法,提升对抗补丁在自动驾驶中的实战效果。

Towards Powerful and Practical Patch Attacks for 2D Object Detection in Autonomous Driving

  • 设计新指标PASR,结合严格交并比评估攻击成功率。
  • 引入定位-置信度抑制损失,增强补丁在不同模型间的迁移能力。
  • 采用概率尺度保持填充策略,保障高分辨率图像下的攻击有效性。

基于学习的自动驾驶系统仍易受对抗补丁攻击,威胁实际部署中的安全与可靠性。黑箱攻击因无需模型知识且成功率高而尤为值得关注,其迁移性研究可降低查询成本。以往基于迁移性的黑箱攻击多以平均精度(mAP)为评估指标并据此设计训练损失,但因存在多个检测框及宽松的交并比(IoU)阈值,导致攻击效果被高估,实际应用中成功率下降。此外,低分辨率数据训练的补丁在高分辨率图像上表现不佳,限制了其在自动驾驶数据集上的迁移性。为此,我们提出面向自动驾驶2D目标检测的高效实用攻击框架P$^3$A。首先,引入新指标实用攻击成功率(PASR),更准确反映对行人安全的实际威胁。其次,设计定位-置信度抑制损失(LCSL),提升在PASR下的攻击迁移性。最后,将概率尺度保持填充(PSPP)作为数据预处理步骤,保障高分辨率数据下的攻击效果。大量实验表明,P$^3$A在未见模型和未见高分辨率数据集上均优于现有最先进攻击方法,无论在新提出的基于IoU的评估标准还是传统mAP标准下均表现优异。

原文摘要 · Abstract (English)

Learning-based autonomous driving systems remain critically vulnerable to adversarial patches, posing serious safety and security risks in their real-world deployment. Black-box attacks, notable for their high attack success rate without model knowledge, are especially concerning, with their transferability extensively studied to reduce computational costs compared to query-based attacks. Previous transferability-based black-box attacks typically adopt mean Average Precision (mAP) as the evaluation metric and design training loss accordingly. However, due to the presence of multiple detected bounding boxes and the relatively lenient Intersection over Union (IoU) thresholds, the attack effectiveness of these approaches is often overestimated, resulting in reduced success rates in practical attacking scenarios. Furthermore, patches trained on low-resolution data often fail to maintain effectiveness on high-resolution images, limiting their transferability to autonomous driving datasets. To fill this gap, we propose P$^3$A, a Powerful and Practical Patch Attack framework for 2D object detection in autonomous driving, specifically optimized for high-resolution datasets. First, we introduce a novel metric, Practical Attack Success Rate (PASR), to more accurately quantify attack effectiveness with greater relevance for pedestrian safety. Second, we present a tailored Localization-Confidence Suppression Loss (LCSL) to improve attack transferability under PASR. Finally, to maintain the transferability for high-resolution datasets, we further incorporate the Probabilistic Scale-Preserving Padding (PSPP) into the patch attack pipeline as a data preprocessing step. Extensive experiments show that P$^3$A outperforms state-of-the-art attacks on unseen models and unseen high-resolution datasets, both under the proposed practical IoU-based evaluation metric and the previous mAP-based metrics.

对抗攻击自动驾驶目标检测黑箱攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。