Spatiotemporal Attacks for Embodied Agents

Aishan Liu,Tairan Huang,Xianglong Liu,Yitao Xu,Yuqing Ma,Xinyun Chen,Stephen J. Maybank,Dacheng Tao
DOI: https://doi.org/10.1007/978-3-030-58520-4_8
2020-01-01
Abstract:Adversarial attacks are valuable for providing insights into the blind-spotsof deep learning models and help improve their robustness. Existing work onadversarial attacks have mainly focused on static scenes; however, it remainsunclear whether such attacks are effective against embodied agents, which couldnavigate and interact with a dynamic environment. In this work, we take thefirst step to study adversarial attacks for embodied agents. In particular, wegenerate spatiotemporal perturbations to form 3D adversarial examples, whichexploit the interaction history in both the temporal and spatial dimensions.Regarding the temporal dimension, since agents make predictions based onhistorical observations, we develop a trajectory attention module to explorescene view contributions, which further help localize 3D objects appeared withthe highest stimuli. By conciliating with clues from the temporal dimension,along the spatial dimension, we adversarially perturb the physical properties(e.g., texture and 3D shape) of the contextual objects that appeared in themost important scene views. Extensive experiments on the EQA-v1 dataset forseveral embodied tasks in both the white-box and black-box settings have beenconducted, which demonstrate that our perturbations have strong attack andgeneralization abilities.
What problem does this paper attempt to address?