arXiv:2510.06952cs.CV2025-10

用文本生成物理可实现的激光雷达隐身3D物体,突破现有攻击局限。

OBJVanish: Physically Realizable Text-to-3D Adv. Generation of LiDAR-Invisible Objects

  • 通过优化文本提示中的动作、物体和姿态,生成激光雷达不可见的3D行人模型。
  • 在CARLA仿真与真实环境中均使6个主流激光雷达检测器失效。
  • 基于13种真实物体组合,确保生成模型可物理实现,适合自动驾驶安全测试。

基于激光雷达的3D目标检测是自动驾驶的核心,漏检可能导致严重安全风险。现有针对3D点云的对抗攻击虽能添加优化扰动,但难以实现完全消失且难于物理落地。本文提出首个文本到3D的对抗生成方法(Phy3DAdvGen),系统研究拓扑、连通性与强度对检测脆弱性的影响,并在CARLA仿真中结合多类物体进行实验。基于13个真实3D物体组成的对象库,约束生成过程,确保物理可实现性。迭代优化文本提示中的动词、物体与姿态,生成真正隐形于激光雷达的行人。大量实验表明,该方法在仿真与真实环境均可规避6个前沿激光雷达3D检测器,揭示了关键安全应用中的漏洞。

原文摘要 · Abstract (English)

LiDAR-based 3D object detectors are fundamental to autonomous driving, where failing to detect objects poses severe safety risks. Developing effective 3D adversarial attacks is essential for thoroughly testing these detection systems and exposing their vulnerabilities before real-world deployment. However, existing adversarial attacks that add optimized perturbations to 3D points have two critical limitations: they rarely cause complete object disappearance and prove difficult to implement in physical environments. We introduce the text-to-3D adversarial generation method, a novel approach enabling physically realizable attacks that can generate 3D models of objects truly invisible to LiDAR detectors and be easily realized in the real world. Specifically, we present the first empirical study that systematically investigates the factors influencing detection vulnerability by manipulating the topology, connectivity, and intensity of individual pedestrian 3D models and combining pedestrians with multiple objects within the CARLA simulation environment. Building on the insights, we propose the physically-informed text-to-3D adversarial generation (Phy3DAdvGen) that systematically optimizes text prompts by iteratively refining verbs, objects, and poses to produce LiDAR-invisible pedestrians. To ensure physical realizability, we construct a comprehensive object pool containing 13 3D models of real objects and constrain Phy3DAdvGen to generate 3D objects based on combinations of objects in this set. Extensive experiments demonstrate that our approach can generate 3D pedestrians that evade six state-of-the-art (SOTA) LiDAR 3D detectors in both CARLA simulation and physical environments, thereby highlighting vulnerabilities in safety-critical applications.

3D对抗攻击激光雷达自动驾驶文本生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。