发表机构
City University of Hong Kong; University of Electronic Science and Technology; Shenzhen University; Jilin University(香港城市大学; 电子科技大学; 深圳大学; 吉林大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出一种利用红外光的物理实时攻击方法,通过动态显示对抗样本破坏光流估计网络,在多种场景下均能有效削弱网络的光流估计能力。
AI 中文摘要
深度神经网络在基于图像的任务上展现出良好性能,使得自动驾驶、运动检测等不同现实应用日益成熟并与人类生活紧密相关。光流估计网络(Optical Flow Estimation Networks, OFENs)作为上游模型,在多个领域发挥关键作用,其输出被大量假设并应用于不同下游任务,因此测试其鲁棒性以预防安全事故至关重要。我们提出一种在物理世界中对OFENs实施实时攻击的方法,利用红外光实现隐蔽性。通过预先生成大量对抗样本(Adversarial Examples, AEs),我们的方法可实时计算对抗样本并动态显示,无需修改受害系统即可实现精确且有针对性的攻击。与此前的数模转换攻击技术不同,我们的方法直接在物理世界中攻击受害模型,克服了对抗样本失效的相关局限。实验结果表明,我们的方法在不同光照条件、不同物体运动速度及不同物体摆放位置下,均能有效破坏OFENs,最终削弱网络准确估计光流的能力。
英文摘要
With the promising performance of deep neural networks on image-based tasks, different real-world applications such as autonomous driving and motion detection have become increasingly mature and relevant to human lives. In particular, Optical Flow Estimation Networks (OFENs), as upstream models, play a critical role in different domains. Its outputs are heavily assumed and adopted for different downstream tasks, and it is essential to test its robustness to prevent safety accidents. We present an approach for real-time attacks on OFENs in the physical world, leveraging infrared lights for their stealthiness. By generating a large number of Adversarial Examples in advance, our approach computes AEs in real time and dynamically displays them, which allows our method to facilitate precise and targeted attacks without modifying the victim system. Unlike previous digital-to-physical attack techniques, our method directly attacks victim models within the physical world, thereby overcoming the limitations associated with the ineffectiveness of AEs. Experimental results demonstrate the efficacy of our approach in compromising OFENs across diverse lighting conditions, varying object motion velocities, and different object placements, ultimately impairing the network's ability to accurately estimate optical flow.