Unified Adversarial Patch for Visible-Infrared Cross-modal Attacks in the Physical World

07/27/2023
by   Xingxing Wei, et al.
0

Physical adversarial attacks have put a severe threat to DNN-based object detectors. To enhance security, a combination of visible and infrared sensors is deployed in various scenarios, which has proven effective in disabling existing single-modal physical attacks. To further demonstrate the potential risks in such cases, we design a unified adversarial patch that can perform cross-modal physical attacks, achieving evasion in both modalities simultaneously with a single patch. Given the different imaging mechanisms of visible and infrared sensors, our work manipulates patches' shape features, which can be captured in different modalities when they undergo changes. To deal with challenges, we propose a novel boundary-limited shape optimization approach that aims to achieve compact and smooth shapes for the adversarial patch, making it easy to implement in the physical world. And a score-aware iterative evaluation method is also introduced to balance the fooling degree between visible and infrared detectors during optimization, which guides the adversarial patch to iteratively reduce the predicted scores of the multi-modal sensors. Furthermore, we propose an Affine-Transformation-based enhancement strategy that makes the learnable shape robust to various angles, thus mitigating the issue of shape deformation caused by different shooting angles in the real world. Our method is evaluated against several state-of-the-art object detectors, achieving an Attack Success Rate (ASR) of over 80 demonstrate the effectiveness of our approach in physical-world scenarios under various settings, including different angles, distances, postures, and scenes for both visible and infrared sensors.

READ FULL TEXT

page 1

page 3

page 4

page 8

page 9

page 10

page 11

page 12

research
07/15/2023

Unified Adversarial Patch for Cross-modal Attacks in the Physical World

Recently, physical adversarial attacks have been presented to evade DNNs...
research
03/24/2023

Physically Adversarial Infrared Patches with Learnable Shapes and Locations

Owing to the extensive application of infrared object detectors in the s...
research
08/23/2023

Aparecium: Revealing Secrets from Physical Photographs

Watermarking is a crucial tool for safeguarding copyrights and can serve...
research
06/14/2023

X-Detect: Explainable Adversarial Patch Detection for Object Detectors in Retail

Object detection models, which are widely used in various domains (such ...
research
04/21/2023

Fooling Thermal Infrared Detectors in Physical World

Infrared imaging systems have a vast array of potential applications in ...
research
05/19/2023

DAP: A Dynamic Adversarial Patch for Evading Person Detectors

In this paper, we present a novel approach for generating naturalistic a...
research
10/10/2021

Adversarial Attacks in a Multi-view Setting: An Empirical Study of the Adversarial Patches Inter-view Transferability

While machine learning applications are getting mainstream owing to a de...

Please sign up or login with your details

Forgot password? Click here to reset