2022
DOI: 10.48550/arxiv.2205.09592
|View full text |Cite
Preprint
|
Sign up to set email alerts
|

Transferable Physical Attack against Object Detection with Separable Attention

Abstract: Transferable adversarial attack is always in the spotlight since deep learning models have been demonstrated to be vulnerable to adversarial samples. However, existing physical attack methods do not pay enough attention on transferability to unseen models, thus leading to the poor performance of black-box attack. In this paper, we put forward a novel method of generating physically realizable adversarial camouflage to achieve transferable attack against detection models. More specifically, we first introduce m… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
5
0

Year Published

2022
2022
2023
2023

Publication Types

Select...
2

Relationship

0
2

Authors

Journals

citations
Cited by 2 publications
(5 citation statements)
references
References 27 publications
0
5
0
Order By: Relevance
“…In the virtual simulation environment, several adversarial attack algorithms for vehicle recognition scenarios have been proposed [14,32,49,50] and shown to be effective. The CARLA simulator [51] has been widely used in these studies due to its versatility and availability.…”
Section: Adversarial Robustness Benchmarkmentioning
confidence: 99%
See 2 more Smart Citations
“…In the virtual simulation environment, several adversarial attack algorithms for vehicle recognition scenarios have been proposed [14,32,49,50] and shown to be effective. The CARLA simulator [51] has been widely used in these studies due to its versatility and availability.…”
Section: Adversarial Robustness Benchmarkmentioning
confidence: 99%
“…Simulators developed based on the Unity engine, such as LGSVL [52], and those developed based on the Unreal engine, such as Airsim [53] and CARLA [51], all support camera simulation. Among them, the Airsim simulator focuses more on drone-related research, while compared with LGSVL, current research on adversarial security is more focused on the CARLA simulator [32,49,50]. CARLA is equipped with scenes and high-precision maps made by RoadRunner and provides options for map editing.…”
Section: Virtual Environment Of Vehicle Detectionmentioning
confidence: 99%
See 1 more Smart Citation
“…The researchers design and realize the first physical backdoor attacks on such systems. Zhang et al [197] propose a novel approach for producing physically feasible adversarial camouflage to achieve transferable attacks on detection models. Study [198] explores a new category of optical adversarial examples, generated by a commonly occurring natural phenomenon, shadows.…”
Section: Black-box Attacksmentioning
confidence: 99%
“…In paper [95], the authors conduct the first investigation towards adversarial attacks that are directed at X-ray prohibited item detection and demonstrate the grave hazards posed by such attacks in this context of paramount safety significance. Finally, we summarize physical attacks against object detection ( [65], [76], [94]- [96], [105]- [107], [160], [184]- [190], [192]- [194], [197], [201]- [204]) in Table VI.…”
Section: Black-box Attacksmentioning
confidence: 99%