arXiv:2604.06865cs.CVcs.AI2026-04

从真实监控场景出发,系统分析对抗攻击的持久性与多模态规避问题。

Physical Adversarial Attacks on AI Surveillance Systems:Detection, Tracking, and Visible--Infrared Evasion

  • 聚焦监控系统中的时序持续性、多模态感知与载体真实性挑战。
  • 揭示现有攻击在跨帧追踪与可见-红外双模态下效果衰减的局限性。
  • 适合关注安防系统鲁棒性评估的研究者与工程实践者参考。

物理对抗攻击在接近实际部署的监控系统中受到越来越多关注,而非仅限于孤立的图像基准测试。在此类场景中,人体检测、多目标追踪、可见-红外传感以及攻击载体的实际形态需同时考虑。一个在单帧中抑制检测器的扰动,若身份在后续帧中被恢复,则实际影响有限;仅基于RGB的攻击结果难以反映依赖可见光与热成像协同工作的夜间系统;显著的贴纸可能代表与可穿戴或选择性激活载体截然不同的威胁模型。本文从监控视角综述物理攻击,不追求全面列举,而是聚焦于监控系统中的核心问题:时序持久性、传感模态、载体真实性和系统级目标。通过四维分类框架梳理已有工作,并讨论近期在多目标追踪、双模态可见-红外规避及可控服装方面的进展,反映了领域趋势的转变。还总结了评估方法与未解难题,包括距离鲁棒性、相机-流水线差异、身份级别度量和激活感知测试。研究表明,监控系统的鲁棒性不能仅通过孤立的单帧基准可靠判断,必须在时间维度、跨传感器层面和真实物理部署约束下综合考察。

原文摘要 · Abstract (English)

Physical adversarial attacks are increasingly studied in settings that resemble deployed surveillance systems rather than isolated image benchmarks. In these settings, person detection, multi-object tracking, visible--infrared sensing, and the practical form of the attack carrier all matter at once. This changes how the literature should be read. A perturbation that suppresses a detector in one frame may have limited practical effect if identity is recovered over time; an RGB-only result may say little about night-time systems that rely on visible and thermal inputs together; and a conspicuous patch can imply a different threat model from a wearable or selectively activated carrier. This paper reviews physical attacks from that surveillance-oriented viewpoint. Rather than attempting a complete catalogue of all physical attacks in computer vision, we focus on the technical questions that become central in surveillance: temporal persistence, sensing modality, carrier realism, and system-level objective. We organize prior work through a four-part taxonomy and discuss how recent results on multi-object tracking, dual-modal visible--infrared evasion, and controllable clothing reflect a broader change in the field. We also summarize evaluation practices and unresolved gaps, including distance robustness, camera-pipeline variation, identity-level metrics, and activation-aware testing. The resulting picture is that surveillance robustness cannot be judged reliably from isolated per-frame benchmarks alone; it has to be examined as a system problem unfolding over time, across sensors, and under realistic physical deployment constraints.

物理攻击监控系统多模态对抗样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。