An Imperceptible Adversarial Attack Against 3-D Object Detectors in Autonomous Driving
Yizhou Wang, Libing Wu, Jiong Jin, Enshu Wang, Zhuangzhuang Zhang, Yu Zhao
Wuhan University Swinburne University of Technology City University of Hong Kong
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
As LiDAR-based 3-D object detection gains attention, existing research on point cloud adversarial attacks has exposed vulnerabilities in 3-D neural network models, which can further impact the reliability of perception systems in autonomous driving. However, current adversarial attacks primarily focus on the point cloud classification tasks, while detection tasks are more challenging to attack because they involve the localization of multiple targets and the sparse distribution of objects. Existing methods often implement attacks by adding global perturbations to the point clouds, which results in poor attack performance and lack of imperceptibility. In this article, we investigate the robustness of 3-D object detectors against adversarial examples. We propose a novel imperceptible attack method to generate 3-D adversarial point clouds. First, we introduce the saliency map for the point clouds, assigning the unique value to each point to measure its importance to the model’s discrimination results. These salient points are then aggregated and adaptively matched to different attack areas corresponding to different targets. Next, we design an optimization-based attack algorithm to generate adversarial point clouds, which are supervised by a dual-loss function consisting of the detection loss to ensure attack effectiveness and the distance loss to limit gap with the original point cloud. Finally, we conducted experiments on two real-world datasets, the KITTI and Waymo Open datasets, to evaluate the proposed attack method. Extensive experiments demonstrate that our attack method achieves average attack success rates of 83.07% and 77.11% on two datasets against seven 3-D object detectors with minimal perturbations. Additionally, the generated adversarial point clouds exhibit strong transferability across multiple mainstream detectors.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIAdversarial Robustness in Machine Learning
Biometric Identification and Security · Advanced Neural Network Applications
参考文献 53
此处列出前 3 条
引用本文 6
按被引量排序,此处列出前 3 条