In the physical world, light affects the performance of deep neural networks. Nowadays, many products based on deep neural network have been put into daily life. There are few researches on the effect of light on the performance of deep neural network models. However, the adversarial perturbations generated by light may have extremely dangerous effects on these systems. In this work, we propose an attack method called adversarial neon beam (AdvNB), which can execute the physical attack by obtaining the physical parameters of adversarial neon beams with very few queries. Experiments show that our algorithm can achieve advanced attack effect in both digital test and physical test. In the digital environment, 99.3% attack success rate was achieved, and in the physical environment, 100% attack success rate was achieved. Compared with the most advanced physical attack methods, our method can achieve better physical perturbation concealment. In addition, by analyzing the experimental data, we reveal some new phenomena brought about by the adversarial neon beam attack.
翻译:在物理世界中,光照会影响深度神经网络的性能。如今,许多基于深度神经网络的产品已融入日常生活。目前关于光照对深度神经网络模型性能影响的研究较少。然而,由光照生成的对抗性扰动可能对这些系统产生极具危险性的影响。本研究提出一种名为对抗性霓虹光束(AdvNB)的攻击方法,该方法通过极少的查询次数获取对抗性霓虹光束的物理参数,从而执行物理攻击。实验表明,我们的算法在数字测试和物理测试中均能达到先进的攻击效果:数字环境下实现了99.3%的攻击成功率,物理环境下实现了100%的攻击成功率。与最先进的物理攻击方法相比,我们的方法能实现更好的物理扰动隐蔽性。此外,通过分析实验数据,我们揭示了对抗性霓虹光束攻击带来的一些新现象。