用逼真路标贴纸诱导自动驾驶误检,隐蔽性强且效果稳定
Invisible Triggers, Visible Threats! Road-Style Adversarial Creation Attack for Visual 3D Detection in Autonomous Driving
- 生成类路面纹理的伪装贴纸,外观自然不引人注目
- 在多种检测器和场景下均能成功伪造不存在的障碍物
- 适用于真实道路攻击,揭示自动驾驶视觉系统的安全风险
现代自动驾驶系统依赖3D目标检测来感知三维环境中的前景物体,以支持后续预测与规划。基于RGB相机的视觉3D检测相比激光雷达方案更具成本优势。尽管检测精度已达到较高水平,当前基于深度神经网络的模型仍极易受到对抗样本攻击。为此,我们研究了自动驾驶场景下的现实可行对抗攻击。已有工作证明可在道路表面放置对抗贴纸,诱使检测器产生幻觉。但传统贴纸外观不自然,易被人类察觉,且内容固定,易被防御。针对此问题,我们提出AdvRoad,可生成多样化的、类路面纹理的对抗贴纸。这些贴纸外观逼真,能干扰检测器在指定位置感知不存在的物体。采用两阶段方法:道路风格对抗生成与场景关联适配,兼顾攻击效果与贴纸自然性,实现隐蔽攻击。大量实验表明,AdvRoad对不同检测器、场景和欺骗位置均具有良好泛化能力。物理实测进一步验证了其在真实环境中的实际威胁。
原文摘要 · Abstract (English)
Modern autonomous driving (AD) systems leverage 3D object detection to perceive foreground objects in 3D environments for subsequent prediction and planning. Visual 3D detection based on RGB cameras provides a cost-effective solution compared to the LiDAR paradigm. While achieving promising detection accuracy, current deep neural network-based models remain highly susceptible to adversarial examples. The underlying safety concerns motivate us to investigate realistic adversarial attacks in AD scenarios. Previous work has demonstrated the feasibility of placing adversarial posters on the road surface to induce hallucinations in the detector. However, the unnatural appearance of the posters makes them easily noticeable by humans, and their fixed content can be readily targeted and defended. To address these limitations, we propose the AdvRoad to generate diverse road-style adversarial posters. The adversaries have naturalistic appearances resembling the road surface while compromising the detector to perceive non-existent objects at the attack locations. We employ a two-stage approach, termed Road-Style Adversary Generation and Scenario-Associated Adaptation, to maximize the attack effectiveness on the input scene while ensuring the natural appearance of the poster, allowing the attack to be carried out stealthily without drawing human attention. Extensive experiments show that AdvRoad generalizes well to different detectors, scenes, and spoofing locations. Moreover, physical attacks further demonstrate the practical threats in real-world environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。