arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于激光雷达距离图像合成的对抗引导扩散

Adversarially Guided Diffusion for LiDAR Range Image Synthesis

Stavros Bouras, Antonios Makris, Alexandros Gkillas, Aris S. Lalos, Konstantinos Tserpes

arXiv 2607.09787首次发表:更新:

发表机构

School of Electrical and Computer Engineering, National Technical University of Athens; Industrial Systems Institute, Athena Research Center(雅典国立技术大学电气与计算机工程学院; 雅典娜研究中心工业系统研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对二维距离图像分割的无限制对抗攻击,提出基于扩散并利用分割损失对抗引导的方法,在SemanticKITTI数据集实验,能跨架构转移,相比基线在有效性与现实性间有独特权衡,实现可控退化。

AI 中文摘要

激光雷达语义分割是自动驾驶中的关键感知任务,错误预测会影响下游规划和安全关键决策。尽管对抗攻击在图像分类和3D点云分割中被广泛研究,但二维距离图像(三维点云的投影)中的无限制对抗样本仍未被充分探索。本文提出的方法是首个基于扩散的针对二维距离图像分割的无限制对抗攻击,利用分割损失的对抗引导。通过在采样时直接应用引导,该方法生成无限制对抗样本,在诱导结构化分割错误的同时,保持与学习到的激光雷达数据流形接近。在SemanticKITTI数据集上使用RangeNet++和CENet分割网络的实验表明,该攻击在不同引导强度下提供可调节的退化,且能跨分割架构转移。与有范数限制的FGSM和SegPGD基线相比,该攻击在有效性和现实性之间提供了独特的权衡,实现可控的白盒和转移退化,同时保持具有竞争力的分布和视觉现实性。

英文摘要

LiDAR semantic segmentation is a key perception task in autonomous driving, where false predictions can affect downstream planning and safety-critical decision-making. Although adversarial attacks, and specifically adversarial examples, have been widely studied for image classification and 3D point cloud segmentation, unrestricted adversarial examples remain largely unexplored in the space of 2D range images, which are projections of 3D point clouds. The proposed method is, to the best of our knowledge, the first diffusion-based unrestricted adversarial attack against 2D range-image segmentation, using adversarial guidance from a segmentation loss. By applying guidance directly during sampling, the method produces unrestricted adversarial examples that remain close to the learned LiDAR data manifold while inducing structured segmentation errors. Experiments on the SemanticKITTI dataset using RangeNet++ and CENet segmentation networks demonstrate that the attack provides adjustable degradation across guidance strengths and transfers across segmentation architectures. Compared with norm-bounded FGSM and SegPGD baselines, the proposed attack offers a distinct effectiveness-realism trade-off, achieving controllable white-box and transfer degradation while maintaining competitive distributional and visual realism.

CommentsAccepted at the 1st Workshop on Secure and Trustworthy AI (STAI 2026), co-located with the European Conference on Machine Learning and Principles and Practice of Knowledge Discovery in Databases (ECML PKDD 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑