arXiv:2607.09787cs.CVcs.LG2026-07中稿 · the 1st Workshop o…

用扩散模型生成逼真且可控的雷达图像对抗样本

Adversarially Guided Diffusion for LiDAR Range Image Synthesis

论文配图:Adversarially Guided Diffusion for LiDAR Range Image Synthesis
图 1 · 摘自论文原文
  • 通过分割损失引导扩散过程,生成结构化错误的对抗图
  • 在SemanticKITTI上实现可调节的白盒与跨模型攻击效果
  • 兼顾攻击有效性与图像真实性,适合安全评估研究

LiDAR语义分割是自动驾驶中的关键感知任务,错误预测会影响下游规划与安全决策。尽管对抗攻击在图像分类和3D点云分割中已有广泛研究,但针对二维范围图像(2D range images)的无限制对抗样本仍鲜有探索。本文提出首个基于扩散模型的无限制对抗攻击方法,利用分割损失进行对抗引导。通过在采样阶段直接施加引导,生成贴近真实数据流形、却引发结构性分割错误的对抗样本。在SemanticKITTI数据集上使用RangeNet++和CENet网络的实验表明,该攻击可调节攻击强度,并在不同分割架构间实现迁移。相比范数约束的FGSM和SegPGD基线,本方法在有效性和真实性之间取得更优平衡,实现可控的白盒与迁移攻击,同时保持优异的分布与视觉真实性。

原文摘要 · Abstract (English)

LiDAR semantic segmentation is a key perception task in autonomous driving, where false predictions can affect downstream planning and safety-critical decision-making. Although adversarial attacks, and specifically adversarial examples, have been widely studied for image classification and 3D point cloud segmentation, unrestricted adversarial examples remain largely unexplored in the space of 2D range images, which are projections of 3D point clouds. The proposed method is, to the best of our knowledge, the first diffusion-based unrestricted adversarial attack against 2D range-image segmentation, using adversarial guidance from a segmentation loss. By applying guidance directly during sampling, the method produces unrestricted adversarial examples that remain close to the learned LiDAR data manifold while inducing structured segmentation errors. Experiments on the SemanticKITTI dataset using RangeNet++ and CENet segmentation networks demonstrate that the attack provides adjustable degradation across guidance strengths and transfers across segmentation architectures. Compared with norm-bounded FGSM and SegPGD baselines, the proposed attack offers a distinct effectiveness-realism trade-off, achieving controllable white-box and transfer degradation while maintaining competitive distributional and visual realism.

对抗攻击扩散模型雷达感知自动驾驶

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。