Vision-based perception modules are increasingly deployed in many applications, especially autonomous vehicles and intelligent robots. These modules are being used to acquire information about the surroundings and identify obstacles. Hence, accurate detection and classification are essential to reach appropriate decisions and take appropriate and safe actions at all times. Current studies have demonstrated that "printed adversarial attacks", known as physical adversarial attacks, can successfully mislead perception models such as object detectors and image classifiers. However, most of these physical attacks are based on noticeable and eye-catching patterns for generated perturbations making them identifiable/detectable by human eye or in test drives. In this paper, we propose a camera-based inconspicuous adversarial attack (\textbf{AdvRain}) capable of fooling camera-based perception systems over all objects of the same class. Unlike mask based fake-weather attacks that require access to the underlying computing hardware or image memory, our attack is based on emulating the effects of a natural weather condition (i.e., Raindrops) that can be printed on a translucent sticker, which is externally placed over the lens of a camera. To accomplish this, we provide an iterative process based on performing a random search aiming to identify critical positions to make sure that the performed transformation is adversarial for a target classifier. Our transformation is based on blurring predefined parts of the captured image corresponding to the areas covered by the raindrop. We achieve a drop in average model accuracy of more than $45\%$ and $40\%$ on VGG19 for ImageNet and Resnet34 for Caltech-101, respectively, using only $20$ raindrops.
翻译:基于视觉的感知模块越来越多地部署在各类应用中,尤其是自动驾驶车辆与智能机器人。这些模块被用于获取周围环境信息并识别障碍物。因此,准确的检测与分类对于在各类情况下做出恰当决策、采取适当且安全的行动至关重要。现有研究表明,“打印式对抗攻击”(即物理对抗攻击)能够成功误导物体检测器、图像分类器等感知模型。然而,这些物理攻击大多采用显眼且引人注目的扰动模式,使其易于被肉眼识别或在测试驾驶中被察觉。本文提出一种基于摄像头的不显眼对抗攻击(**AdvRain**),能够欺骗基于摄像头的感知系统,使其无法正确识别同一类别的所有物体。与需要访问底层计算硬件或图像存储器的基于掩码的伪天气攻击不同,我们的攻击基于模拟自然天气条件(即雨滴)的效果,这些雨滴可打印在透明贴纸上,并外部置于摄像头的镜头之上。为实现这一目标,我们提供了一种基于随机搜索的迭代过程,旨在识别关键位置,确保所执行的变换对目标分类器具有对抗性。我们的变换基于模糊捕获图像中对应雨滴覆盖区域的预定义部分。仅使用20个雨滴,我们便在VGG19模型(ImageNet数据集)和ResNet34模型(Caltech-101数据集)上分别实现了平均模型精度下降超过45%和40%的效果。