通过扰动特征让机器人定位系统出错,揭示了视觉定位的致命漏洞。
Adversarial Attacks on Robot Localization Systems via Deep Feature Perturbation

- 用轻量网络扰动查询特征分布,诱导定位系统返回错误匹配项。
- 在真实与模拟环境中,使基于产品量化系统的定位精度下降超70%。
- 攻击隐蔽且计算开销极小,适合针对部署中的机器人系统。
机器人定位系统对自主导航与安全至关重要。对抗性扰动可导致系统误定位、导航错误或不安全交互,尤其在关键任务场景中风险更高。本文研究基于深度学习的定位流程对对抗攻击的脆弱性,提出一种新型框架,专门针对视觉定位系统中的产品量化(PQ)机制生成对抗查询。该方法采用轻量级产品量化网络(LPQN)扰动查询特征编码,通过误导检索过程返回语义无关的数据库条目。对抗查询通过两阶段生成:前向传播扰动特征分布,后向传播通过优化细化扰动。LPQN的轻量化设计使扰动具有极低计算开销,但效果显著。大量实验在受控与真实机器人环境中验证,本方法大幅降低PQN性能,暴露出实际应用中的关键安全隐患。
原文摘要 · Abstract (English)
Robot localization systems are critical for autonomous navigation and safety. Adversarial perturbations can mislead these systems, resulting in mislocalization, navigation errors, or unsafe interactions, especially in mission-critical scenarios. This paper investigates the vulnerability of deep learning based localization pipelines to adversarial attacks. We propose a novel framework for generating adversarial queries that specifically target Product Quantization (PQ) in visual localization systems. Our method employs a Lightweight Product Quantization Network (LPQN) to perturb query feature encodings, misleading the retrieval process by returning semantically irrelevant database entries. Adversarial queries are generated via a two-phase procedure: a forward pass that perturbs feature distributions and a backward pass that refines the perturbation through optimization. The lightweight design of LPQN allows the creation of subtle yet highly effective perturbations with minimal computational overhead. Extensive experiments in both controlled and real-world robotic environments demonstrate that our approach substantially degrades PQN performance, exposing critical vulnerabilities in practical applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。