Unified Adversarial Patch for Cross-modal Attacks in the Physical World

07/15/2023
by   Xingxing Wei, et al.
0

Recently, physical adversarial attacks have been presented to evade DNNs-based object detectors. To ensure the security, many scenarios are simultaneously deployed with visible sensors and infrared sensors, leading to the failures of these single-modal physical attacks. To show the potential risks under such scenes, we propose a unified adversarial patch to perform cross-modal physical attacks, i.e., fooling visible and infrared object detectors at the same time via a single patch. Considering different imaging mechanisms of visible and infrared sensors, our work focuses on modeling the shapes of adversarial patches, which can be captured in different modalities when they change. To this end, we design a novel boundary-limited shape optimization to achieve the compact and smooth shapes, and thus they can be easily implemented in the physical world. In addition, to balance the fooling degree between visible detector and infrared detector during the optimization process, we propose a score-aware iterative evaluation, which can guide the adversarial patch to iteratively reduce the predicted scores of the multi-modal sensors. We finally test our method against the one-stage detector: YOLOv3 and the two-stage detector: Faster RCNN. Results show that our unified patch achieves an Attack Success Rate (ASR) of 73.33 importantly, we verify the effective attacks in the physical world when visible and infrared sensors shoot the objects under various settings like different angles, distances, postures, and scenes.

READ FULL TEXT

page 2

page 7

page 8

research
07/27/2023

Unified Adversarial Patch for Visible-Infrared Cross-modal Attacks in the Physical World

Physical adversarial attacks have put a severe threat to DNN-based objec...
research
03/24/2023

Physically Adversarial Infrared Patches with Learnable Shapes and Locations

Owing to the extensive application of infrared object detectors in the s...
research
11/27/2020

3D Invisible Cloak

In this paper, we propose a novel physical stealth attack against the pe...
research
06/14/2023

X-Detect: Explainable Adversarial Patch Detection for Object Detectors in Retail

Object detection models, which are widely used in various domains (such ...
research
12/26/2018

Practical Adversarial Attack Against Object Detector

In this paper, we proposed the first practical adversarial attacks again...
research
08/26/2021

Physical Adversarial Attacks on an Aerial Imagery Object Detector

Deep neural networks (DNNs) have become essential for processing the vas...
research
04/21/2023

Fooling Thermal Infrared Detectors in Physical World

Infrared imaging systems have a vast array of potential applications in ...

Please sign up or login with your details

Forgot password? Click here to reset