arXiv:2604.23105cs.CV2026-04

提出可跨模型攻击的物理对抗补丁,提升自动驾驶目标检测安全威胁

Transferable Physical-World Adversarial Patches Against Object Detection in Autonomous Driving

论文配图:Transferable Physical-World Adversarial Patches Against Object Detection in Autonomous Driving
图 1 · 摘自论文原文
  • 基于多模型联合优化,生成具有强迁移性的物理对抗补丁
  • 在真实场景中对多个检测器攻击成功率超90%,显著优于现有方法
  • 适合研究对抗防御或评估自动驾驶系统鲁棒性的研究人员

深度学习推动了自动驾驶(AD)的重大进展,其中目标检测器是感知的核心。然而,对抗攻击对系统的可靠性和安全性构成严重威胁,尤其是物理对抗补丁形式的攻击。现有物理对抗补丁通常针对单一检测模型设计,跨模型迁移能力差。本文提出AdvAD,一种面向自动驾驶目标检测的迁移式物理攻击方法。该方法在统一框架下对多个检测模型进行优化,使生成的扰动能捕捉不同架构间的共享漏洞。优化过程自适应平衡各模型贡献,并增强对物理变化的鲁棒性。同时采用数据增强和几何变换,确保补丁在真实复杂条件下仍具有效性。数字与真实世界实验均表明,AdvAD在性能和迁移能力上持续优于当前最先进(SOTA)攻击方法。

原文摘要 · Abstract (English)

Deep learning drives major advances in autonomous driving (AD), where object detectors are central to perception. However, adversarial attacks pose significant threats to the reliability and safety of these systems, with physical adversarial patches representing a particularly potent form of attack. Physical adversarial patch attacks pose severe risks but are usually crafted for a single model, yielding poor transferability to unseen detectors. We propose AdvAD, a transfer-based physical attack against object detection in autonomous driving. Instead of targeting a specific detector, AdvAD optimizes adversarial patches over multiple detection models in a unified framework, encouraging the learned perturbations to capture shared vulnerabilities across architectures. The optimization process adaptively balances model contributions and enforces robustness to physical variations. It further employs data augmentation and geometric transformations to maintain patch effectiveness under diverse physical conditions. Experiments in both digital and real-world settings show that AdvAD consistently outperforms state-of-the-art (SOTA) attacks in performance and transferability.

对抗攻击自动驾驶目标检测物理攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。