GhostImage: Perception Domain Attacks against Vision-based Object Classification Systems

01/21/2020
by   Yanmao Man, et al.
3

In vision-based object classification systems, imaging sensors perceive the environment and then objects are detected and classified for decision-making purposes. Vulnerabilities in the perception domain enable an attacker to inject false data into the sensor which could lead to unsafe consequences. In this work, we focus on camera-based systems and propose GhostImage attacks, with the goal of either creating a fake perceived object or obfuscating the object's image that leads to wrong classification results. This is achieved by remotely projecting adversarial patterns into camera-perceived images, exploiting two common effects in optical imaging systems, namely lens flare/ghost effects, and auto-exposure control. To improve the robustness of the attack to channel perturbations, we generate optimal input patterns by integrating adversarial machine learning techniques with a trained end-to-end channel model. We realize GhostImage attacks with a projector, and conducted comprehensive experiments, using three different image datasets, in indoor and outdoor environments, and three different cameras. We demonstrate that GhostImage attacks are applicable to both autonomous driving and security surveillance scenarios. Experiment results show that, depending on the projector-camera distance, attack success rates can reach as high as 100

READ FULL TEXT

page 1

page 5

page 9

page 10

page 15

page 17

research
03/02/2023

AdvRain: Adversarial Raindrops to Attack Camera-based Smart Vision Systems

Vision-based perception modules are increasingly deployed in many applic...
research
10/02/2019

Attacking Vision-based Perception in End-to-End Autonomous Driving Models

Recent advances in machine learning, especially techniques such as deep ...
research
01/25/2021

They See Me Rollin': Inherent Vulnerability of the Rolling Shutter in CMOS Image Sensors

Cameras have become a fundamental component of vision-based intelligent ...
research
08/19/2021

Signal Injection Attacks against CCD Image Sensors

Since cameras have become a crucial part in many safety-critical systems...
research
02/27/2021

End-to-end Uncertainty-based Mitigation of Adversarial Attacks to Automated Lane Centering

In the development of advanced driver-assistance systems (ADAS) and auto...
research
10/07/2021

DoubleStar: Long-Range Attack Towards Depth Estimation based Obstacle Avoidance in Autonomous Systems

Depth estimation-based obstacle avoidance has been widely adopted by aut...
research
03/04/2019

iVOA: Introspective Vision for Obstacle Avoidance

Vision, as an inexpensive yet information rich sensor, is commonly used ...

Please sign up or login with your details

Forgot password? Click here to reset