让伪装图案在复杂光照下仍能骗过自动驾驶系统
R-PGA: Robust Physical Adversarial Camouflage Generation via Relightable 3D Gaussian Splatting
- 用可重光的3D高斯点云模拟真实物体,分离材质与光照
- 通过挖掘最坏场景降低损失峰,提升攻击鲁棒性
- 适合研究物理对抗攻击或自动驾驶安全的读者
物理对抗伪装对自动驾驶系统构成严重安全威胁,通过将对抗纹理映射到3D物体上实现。然而,现有方法在复杂动态场景中表现脆弱,难以适应多变的几何(如视角)和辐射度(如动态光照、大气散射)变化。我们归因于仿真与优化中的两大根本缺陷:一是依赖粗糙简化仿真(如CARLA),导致显著领域差距,使优化局限于有偏特征空间;二是标准平均性能策略造成陡峭损失曲面,使伪装易受配置变化影响。为此,我们提出基于可重光3D高斯点云的攻击框架R-PGA。技术上,为提升仿真保真度,利用3DGS实现照片级重建,并引入物理解耦属性以分离材质与光照;设计混合渲染管线,用精确的可重光3DGS渲染前景,结合预训练图像翻译模型合成匹配前景的逼真背景。为增强优化鲁棒性,提出硬物理配置挖掘(HPCM)模块,主动挖掘最坏物理配置并抑制其损失峰值,不仅降低整体损失幅度,还有效平坦损失曲面,确保在不同物理配置下保持一致的对抗效果与鲁棒性。
原文摘要 · Abstract (English)
Physical adversarial camouflage poses a severe security threat to autonomous driving systems by mapping adversarial textures onto 3D objects. Nevertheless, current methods remain brittle in complex dynamic scenarios, failing to generalize across diverse geometric (e.g., viewing configurations) and radiometric (e.g., dynamic illumination, atmospheric scattering) variations. We attribute this deficiency to two fundamental limitations in simulation and optimization. First, the reliance on coarse, oversimplified simulations (e.g., via CARLA) induces a significant domain gap, confining optimization to a biased feature space. Second, standard strategies targeting average performance result in a rugged loss landscape, leaving the camouflage vulnerable to configuration shifts.To bridge these gaps, we propose the Relightable Physical 3D Gaussian Splatting (3DGS) based Attack framework (R-PGA). Technically, to address the simulation fidelity issue, we leverage 3DGS to ensure photo-realistic reconstruction and augment it with physically disentangled attributes to decouple intrinsic material from lighting. Furthermore, we design a hybrid rendering pipeline that leverages precise Relightable 3DGS for foreground rendering, while employing a pre-trained image translation model to synthesize plausible relighted backgrounds that align with the relighted foreground.To address the optimization robustness issue, we propose the Hard Physical Configuration Mining (HPCM) module, designed to actively mine worst-case physical configurations and suppress their corresponding loss peaks. This strategy not only diminishes the overall loss magnitude but also effectively flattens the rugged loss landscape, ensuring consistent adversarial effectiveness and robustness across varying physical configurations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。