用傅里叶形状生成红外对抗样本,让热成像目标逃过检测
Unleashing the Representational Power of Fourier Shapes for Attacking Infrared Object Detection

- 用可学习的傅里叶系数定义热屏蔽物边界,实现端到端优化
- 物理攻击在25米外成功率超88%,跨角度、姿态和人体均有效
- 适合研究红外防御或对抗攻击的工程师与安全研究人员
红外目标检测对自动驾驶和监控至关重要,但易受物理对抗攻击。与依赖颜色纹理的可见光攻击不同,红外攻击需操控热信号,因此热屏蔽材料的几何形状成为主要攻击载体。现有基于形状的方法在表征能力与优化性能间存在根本权衡,限制了攻击效果。本文提出将可学习的傅里叶形状引入红外域,采用端到端可微框架,通过环绕数定理将一组紧凑的傅里叶系数解析映射为像素级掩码,实现高效梯度优化,生成能诱使人类目标逃逸检测的强对抗形状。大量数字与物理实验全面验证了优越性能:所生成的物理贴片在多种距离、角度、姿态和个体下均表现出显著鲁棒性,在25米以上距离攻击成功率超过88%(置信度=0.5)。代码已开源。
原文摘要 · Abstract (English)
Infrared object detection is crucial for perception in autonomous driving and surveillance but remains vulnerable to physical adversarial attacks. Unlike in the RGB domain, where attacks rely on color texture, infrared attacks must manipulate thermal signatures, making the geometry shape of heat-blocking materials the primary adversarial information carrier. Current shape-based methods suffer from a fundamental trade-off between representational capability and optimization power, limiting their attack effectiveness.In this work, we overcome this dilemma by introducing learnable Fourier shapes to the infrared domain. We utilize an end-to-end differentiable framework where a compact set of Fourier coefficients, defining the shape boundary, is analytically mapped to a pixel-space mask via the winding number theorem. This enables efficient gradient-based optimization to generate potent shapes that cause human targets to evade detection. Extensive digital and physical experiments provide a comprehensive evaluation and validate our superior performance. Our resulting physical patch achieves striking robustness, successfully evading detectors across diverse distances, angles, poses, and individuals, and achieves over 88% attack success rate at distances greater than 25m (conf.=0.5). Code is available at https://github.com/Yongyx99/Fourier-shape-attack.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。