Invisible Pedestrians: Synthesizing Adversarial Clothing Textures to Evade Industrial Camera-Based 3D Detection

Xinlong Ding,Hongwei Yu,Jiansheng Chen,Jinlong Wang,Jintai Du,Huimin Ma
DOI: https://doi.org/10.1109/icme57554.2024.10687467
2024-01-01
Abstract:Recent studies have explored attacking perception models of autonomous driving systems and creating adversarial textures to evade 2D vision or infrared pedestrian detectors. However, purely camera-based 3D detectors remain to be explored, especially in complex real-world traffic scenarios and road conditions where pedestrians are prevalent. In this paper, we propose a pipeline that accurately renders 3D human models onto 2D scenes while maintaining physical realism and spatial coordinate constraints. By leveraging this pipeline, we design a soft-weighted confidence loss to optimize adversarial textures on clothing, effectively suppressing predicted boxes near the human model. A comprehensive evaluation of adversarial textures is conducted on a test set comprising 100 scenes with complex environments. Our attack can consistently evade detection by the industrial camera-based 3D detector SMOKE across multiple viewpoints and scenes.
What problem does this paper attempt to address?