论文标题
半透明补丁:对对象探测器的物理和普遍攻击
The Translucent Patch: A Physical and Universal Attack on Object Detectors
论文作者
论文摘要
近年来,对物体探测器的身体对抗性攻击已经增加了成功。但是,这些攻击需要直接访问感兴趣的对象,以便应用物理补丁。此外,要隐藏多个对象,必须将对抗补丁应用于每个对象。在本文中,我们提出了一个不接触式的半透明物理贴片,其中包含精心构造的图案,该图案放在相机的镜头上,以欺骗最新的对象探测器。补丁的主要目标是隐藏所选目标类的所有实例。此外,用于构建补丁的优化方法旨在确保检测其他(未靶向)类的方法没有受到伤害。因此,在我们的实验中,这些实验是根据用于自动驾驶的最新对象检测模型进行的,我们研究了斑块对所选目标类别和其他类别的检测的影响。我们表明,我们的补丁能够防止检测到所有停止符号实例的42.27%,同时对其他类别的检测保持较高(近80%)。
Physical adversarial attacks against object detectors have seen increasing success in recent years. However, these attacks require direct access to the object of interest in order to apply a physical patch. Furthermore, to hide multiple objects, an adversarial patch must be applied to each object. In this paper, we propose a contactless translucent physical patch containing a carefully constructed pattern, which is placed on the camera's lens, to fool state-of-the-art object detectors. The primary goal of our patch is to hide all instances of a selected target class. In addition, the optimization method used to construct the patch aims to ensure that the detection of other (untargeted) classes remains unharmed. Therefore, in our experiments, which are conducted on state-of-the-art object detection models used in autonomous driving, we study the effect of the patch on the detection of both the selected target class and the other classes. We show that our patch was able to prevent the detection of 42.27% of all stop sign instances while maintaining high (nearly 80%) detection of the other classes.