Physically Adversarial Infrared Patches with Learnable Shapes and Locations

03/24/2023
by   Wei Xingxing, et al.
0

Owing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are complicated to implement in practical application because of their complex transformation from digital world to physical world. To address this issue, in this paper, we propose a physically feasible infrared attack method called "adversarial infrared patches". Considering the imaging mechanism of infrared cameras by capturing objects' thermal radiation, adversarial infrared patches conduct attacks by attaching a patch of thermal insulation materials on the target object to manipulate its thermal distribution. To enhance adversarial attacks, we present a novel aggregation regularization to guide the simultaneous learning for the patch' shape and location on the target object. Thus, a simple gradient-based optimization can be adapted to solve for them. We verify adversarial infrared patches in different object detection tasks with various object detectors. Experimental results show that our method achieves more than 90% Attack Success Rate (ASR) versus the pedestrian detector and vehicle detector in the physical environment, where the objects are captured in different angles, distances, postures, and scenes. More importantly, adversarial infrared patch is easy to implement, and it only needs 0.5 hours to be constructed in the physical world, which verifies its effectiveness and efficiency.

READ FULL TEXT

page 1

page 2

page 6

page 7

page 8

research
07/15/2023

Unified Adversarial Patch for Cross-modal Attacks in the Physical World

Recently, physical adversarial attacks have been presented to evade DNNs...
research
04/21/2023

Fooling Thermal Infrared Detectors in Physical World

Infrared imaging systems have a vast array of potential applications in ...
research
02/19/2023

X-Adv: Physical Adversarial Object Attacks against X-ray Prohibited Item Detection

Adversarial attacks are valuable for evaluating the robustness of deep l...
research
07/27/2023

Unified Adversarial Patch for Visible-Infrared Cross-modal Attacks in the Physical World

Physical adversarial attacks have put a severe threat to DNN-based objec...
research
06/25/2022

Empirical Evaluation of Physical Adversarial Patch Attacks Against Overhead Object Detection Models

Adversarial patches are images designed to fool otherwise well-performin...
research
12/12/2022

HOTCOLD Block: Fooling Thermal Infrared Detectors with a Novel Wearable Design

Adversarial attacks on thermal infrared imaging expose the risk of relat...
research
06/28/2023

Distributional Modeling for Location-Aware Adversarial Patches

Adversarial patch is one of the important forms of performing adversaria...

Please sign up or login with your details

Forgot password? Click here to reset