Stealthy and Effective Physical Adversarial Attacks in Autonomous Driving
Man Zhou,Wenyu Zhou,Jie Huang,Junhui Yang,Minxin Du,Qi Li
DOI: https://doi.org/10.1109/tifs.2024.3422920
IF: 7.231
2024-07-20
IEEE Transactions on Information Forensics and Security
Abstract:In autonomous assistance systems, accurate camera vision is indispensable for driving safety. Featuring this safety-critical scenario, physical adversarial examples are arguably the most threatening. However, existing physical adversarial attacks are either conspicuous or ineffective, leaving a dilemma for balancing between attack effectiveness and stealthiness. In this paper, we put forth a new type of adversarial patch attack, leveraging the behavior characteristic of high-speed shutters in autonomous driving cameras. Instead of deploying static images onto real-world objects, we embed adversarial examples into videos and cast them with projectors. By delicately deciding the frame contents and display frequencies, the adversarial frame contents are almost invisible to humans, but high-speed shutters can capture them (see our demos (https://anonymous.4open.science/r/7003)). We demonstrate the attack feasibility by fooling traffic sign detectors, altering speed limit signs to be mis-detected or undetected, and hence manipulating the driving speed of victims. We conduct extensive experiments under various conditions, confirming that our new attack is effective and robust: It can deceive state-of-the-art detector models with success rates of 99% and over 90% in untargeted and targeted manners, respectively. Our further investigations unravel the transferability of our attack to other detectors in a black-box setting.
computer science, theory & methods,engineering, electrical & electronic