Autonomous flying robots, e.g. multirotors, often rely on a neural network that makes predictions based on a camera image. These deep learning (DL) models can compute surprising results if applied to input images outside the training domain. Adversarial attacks exploit this fault, for example, by computing small images, so-called adversarial patches, that can be placed in the environment to manipulate the neural network's prediction. We introduce flying adversarial patches, where an image is mounted on another flying robot and therefore can be placed anywhere in the field of view of a victim multirotor. For an effective attack, we compare three methods that simultaneously optimize the adversarial patch and its position in the input image. We perform an empirical validation on a publicly available DL model and dataset for autonomous multirotors. Ultimately, our attacking multirotor would be able to gain full control over the motions of the victim multirotor.
翻译:自主飞行机器人(如多旋翼飞行器)常依赖基于摄像头图像进行预测的神经网络。这些深度学习模型在应用于训练域外的输入图像时,可能产生出人意料的结果。对抗性攻击利用这一缺陷,例如通过计算小型图像(即所谓的对抗补丁),将其置于环境中以操控神经网络的预测。我们提出飞行对抗补丁的概念:将图像附着在另一架飞行机器人上,从而使其能够被置于目标多旋翼飞行器视野中的任意位置。为实现高效攻击,我们比较了三种同时优化对抗补丁及其在输入图像中位置的方法。针对公开可用的自主多旋翼深度学习模型与数据集,我们开展了实证验证。最终,攻击方多旋翼飞行器将能够完全控制目标多旋翼飞行器的运动轨迹。