首个基于点云的事件相机对抗攻击框架,可低代价高效破坏感知系统
Generating Adversarial Events: A Motion-Aware Point Cloud Framework
- 利用点云建模事件时空关系,突破传统不可导表示限制
- 实现100%攻击成功率,扰动成本极低且抗防御能力更强
- 适合安全评估、鲁棒性研究者,揭示事件系统深层安全隐患
事件相机广泛应用于自动驾驶、机器人及人机交互等安全关键领域。然而,深度神经网络对对抗样本的脆弱性给事件系统可靠性带来严重威胁。目前针对事件数据的对抗攻击研究极少,主要因主流事件表示不可导,难以扩展梯度攻击方法。本文提出MA-ADV——首个基于点云表示生成对抗事件的运动感知框架。该方法考虑事件中的高频噪声,采用扩散模型平滑扰动,充分挖掘事件的空间与时间关联。通过逐样本Adam优化、迭代精炼与二分搜索,精准定位最小代价扰动。大量实验表明,MA-ADV在保证100%攻击成功率的同时,扰动成本极低,并具备更强的防御绕过能力,凸显未来事件感知系统面临的关键安全挑战。
原文摘要 · Abstract (English)
Event cameras have been widely adopted in safety-critical domains such as autonomous driving, robotics, and human-computer interaction. A pressing challenge arises from the vulnerability of deep neural networks to adversarial examples, which poses a significant threat to the reliability of event-based systems. Nevertheless, research into adversarial attacks on events is scarce. This is primarily due to the non-differentiable nature of mainstream event representations, which hinders the extension of gradient-based attack methods. In this paper, we propose MA-ADV, a novel \textbf{M}otion-\textbf{A}ware \textbf{Adv}ersarial framework. To the best of our knowledge, this is the first work to generate adversarial events by leveraging point cloud representations. MA-ADV accounts for high-frequency noise in events and employs a diffusion-based approach to smooth perturbations, while fully leveraging the spatial and temporal relationships among events. Finally, MA-ADV identifies the minimal-cost perturbation through a combination of sample-wise Adam optimization, iterative refinement, and binary search. Extensive experimental results validate that MA-ADV ensures a 100\% attack success rate with minimal perturbation cost, and also demonstrate enhanced robustness against defenses, underscoring the critical security challenges facing future event-based perception systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。