Adversarial Attacks Against Traffic Sign Detection for Autonomous Driving

Feiyang Xu,Ying Li,Chao Yang,Weida Wang,Bin Xu
DOI: https://doi.org/10.1109/cvci59596.2023.10397303
2023-01-01
Abstract:Deep neural networks play a crucial role in 2D object detection based on visual data, but they are also vulnerable to adversarial samples. Attackers manipulate low-resolution images to execute data poisoning attacks. This paper introduces a method to generate realistic high-resolution adversarial samples aimed at compromising traffic sign detection models. Specifically, we propose a high-resolution adversarial sample framework built upon generative adversarial networks. Subsequently, an adversarial traffic sign detection model is developed to investigate the impact of data poisoning. To enhance the model’s robustness, we conduct adversarial training. Experimental results demonstrate the efficacy of our data poisoning approach in misleading the detection model. Furthermore, the detection model exhibits improved robustness against such attacks following adversarial training.
What problem does this paper attempt to address?