用反光贴纸在车灯下隐身攻击交通标志识别系统
Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign Recognition Systems
- 用受车灯激活的反光材料制作隐形攻击贴纸
- 35米距离动态场景攻击成功率超93.4%,实测对商用系统有效
- 比传统贴纸更难被发现,适合研究车辆安全漏洞者
交通标志识别对自动驾驶安全至关重要,但易受贴纸或激光投影等对抗攻击。现有攻击方式或显眼或难部署,存在未被探索的安全漏洞。本文提出对抗性反光贴纸(ARP),结合贴纸高可部署性与激光攻击的隐蔽性,利用仅在目标车灯照射下激活的反光材料实现隐身攻击。通过开发反光模拟方法并使用黑盒优化,最大化攻击效果。ARP在35米动态场景中成功率≥93.4%,在真实条件下对商用交通标志识别系统攻击成功率≥60%。用户研究表明,其隐蔽性接近正常标志,且较以往贴纸攻击提升≥1.9%隐蔽性评分。本文还提出DPR Shield防御方案,通过战略性布置偏振滤镜,对停车标志和限速标志的微棱镜贴纸攻击防御成功率≥75%。
原文摘要 · Abstract (English)
Traffic sign recognition plays a critical role in ensuring safe and efficient transportation of autonomous vehicles but remain vulnerable to adversarial attacks using stickers or laser projections. While existing attack vectors demonstrate security concerns, they suffer from visual detectability or implementation constraints, suggesting unexplored vulnerability surfaces in TSR systems. We introduce the Adversarial Retroreflective Patch (ARP), a novel attack vector that combines the high deployability of patch attacks with the stealthiness of laser projections by utilizing retroreflective materials activated only under victim headlight illumination. We develop a retroreflection simulation method and employ black-box optimization to maximize attack effectiveness. ARP achieves $\geq$93.4\% success rate in dynamic scenarios at 35 meters and $\geq$60\% success rate against commercial TSR systems in real-world conditions. Our user study demonstrates that ARP attacks maintain near-identical stealthiness to benign signs while achieving $\geq$1.9\% higher stealthiness scores than previous patch attacks. We propose the DPR Shield defense, employing strategically placed polarized filters, which achieves $\geq$75\% defense success rates for stop signs and speed limit signs against micro-prism patches.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。