AdvSerial:通过语义特征抑制对基于基础设施的行人检测器进行物理对抗攻击
AdvSerial: Physical Adversarial Attacks on Infrastructure-mounted Pedestrian Detectors via Semantic Feature Suppression
浏览论文内容
中文总结 AI 辅助
针对基础设施行人检测器安全漏洞,提出AdvSerial框架,通过2D-3D联合优化、语义特征抑制等方法生成对抗补丁,在多检测器实验中成功率高、可转移性强,揭示故障模式,为相关防御设计提供思路。
中文摘要 AI 辅助
基于人工智能的视觉感知系统越来越多地应用于基础设施监控中,但其易受物理对抗攻击的安全漏洞对交通基础设施的可靠运行构成直接威胁。本文提出AdvSerial,一个动态的2D-3D联合优化框架,用于在基于基础设施的场景中针对行人检测器生成连续的高角度物理对抗补丁。通过UV映射将边界感知的拼接纹理映射到3D服装上,结合2D数字攻击与3D稀疏和连续帧渲染,并在强制时间连续性的同时明确抑制特定于人的语义特征。实验表明AdvSerial在多个检测器上有高成功率和强可转移性,揭示了高角度监控下持续的、时间上一致的故障模式,为安全关键的基础设施部署设计运动感知和3D感知防御提供了动力。
英文摘要
AI-based visual perception systems are increasingly deployed in infrastructure surveillance, including roadside monitoring units, highway cameras, and smart-city pedestrian management systems. The security vulnerability of these systems to physical adversarial attacks poses a direct threat to the reliable operation of transportation infrastructure. We propose AdvSerial, a dynamic 2D--3D joint optimization framework for generating continuous high-angle physical adversarial patches against pedestrian detectors in infrastructure-based scenarios. We UV-map a boundary-aware quilted texture onto 3D garments, combine 2D digital attacks with 3D sparse- and continuous-frame rendering, and explicitly suppress person-specific semantic features while enforcing temporal continuity. A Feature Smooth Quilting strategy reduces visible patch boundaries and bounds cross-seam feature discontinuities. A serial-frame loss encourages long uninterrupted sequences of detection failures. In physical world experiments, AdvSerial achieves a 74.8% attack success rate on YOLO-v5 and degrades mean detection confidence from 84.30% to 39.38%. Experiments spanning eight detectors with different architectures demonstrate strong transferability. Notably, it achieves an $89.71%$ attack success rate on YOLO-v2 and resists both patch-detection defenses (NapGuard) and 3D-temporal perception (Sparse4D-v3). The results reveal persistent, temporally consistent failure modes under high-angle surveillance, and motivate the design of motion-aware and 3D-aware defenses for security-critical infrastructure deployments.
发表机构
- School of Transportation Science and Engineering, Beihang University(北京航空航天大学交通科学与工程学院)
- State Key Lab of Intelligent Transportation System(智能交通系统国家重点实验室)
- Zhongguancun Laboratory(中关村实验室)
机构由 AI 辅助整理,请以论文原文为准。