让对抗攻击在真实场景中端到端优化,提升攻击成功率。
UNDREAM: Bridging Differentiable Rendering and Photorealistic Simulation for End-to-end Adversarial Attacks
- 结合可微渲染与逼真仿真,实现环境可控的对抗扰动优化。
- 支持天气、光照、视角等10+环境参数调节,生成多样物理合理攻击对象。
- 适合安全关键领域研究者测试自动驾驶系统鲁棒性。
部署于自动驾驶等安全关键应用中的深度学习模型,常通过仿真测试其对对抗攻击的鲁棒性。然而,现有仿真工具不可微,导致攻击无法融合真实环境因素,降低攻击成功率。为此,我们提出UNDREAM——首个连接逼真模拟器与可微渲染的软件框架,支持任意3D物体的端到端对抗扰动优化。该框架提供对天气、光照、背景、相机角度、轨迹及人和物体运动的完整控制,可快速构建多样化场景。我们展示了多种物理上合理的对抗物体,使研究者能在可配置环境中高效探索。该方法结合逼真仿真与可微优化,为物理对抗攻击研究开辟新路径。
原文摘要 · Abstract (English)
Deep learning models deployed in safety critical applications like autonomous driving use simulations to test their robustness against adversarial attacks in realistic conditions. However, these simulations are non-differentiable, forcing researchers to create attacks that do not integrate simulation environmental factors, reducing attack success. To address this limitation, we introduce UNDREAM, the first software framework that bridges the gap between photorealistic simulators and differentiable renderers to enable end-to-end optimization of adversarial perturbations on any 3D objects. UNDREAM enables manipulation of the environment by offering complete control over weather, lighting, backgrounds, camera angles, trajectories, and realistic human and object movements, thereby allowing the creation of diverse scenes. We showcase a wide array of distinct physically plausible adversarial objects that UNDREAM enables researchers to swiftly explore in different configurable environments. This combination of photorealistic simulation and differentiable optimization opens new avenues for advancing research of physical adversarial attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。