{"title":"物理世界中具有可学习形状和位置的红外对抗补丁","authors":"Xingxing Wei, Jie Yu, Yao Huang","doi":"10.1007/s11263-023-01963-y","DOIUrl":null,"url":null,"abstract":"<p>Owing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are complicated to implement in practical application because of their complex transformation from the digital world to physical world. To address this issue, in this paper, we propose a physically feasible infrared attack method called “infrared adversarial patches”. Considering the imaging mechanism of infrared cameras by capturing objects’ thermal radiation, infrared adversarial patches conduct attacks by attaching a patch of thermal insulation materials on the target object to manipulate its thermal distribution. To enhance adversarial attacks, we present a novel aggregation regularization to guide the simultaneous learning for the patch’s shape and location on the target object. Thus, a simple gradient-based optimization can be adapted to solve for them. We verify infrared adversarial patches in different object detection tasks with various object detectors. Experimental results show that our method achieves more than 90% Attack Success Rate (ASR) versus the pedestrian detector and vehicle detector in the physical environment, where the objects are captured in different angles, distances, postures, and scenes. More importantly, infrared adversarial patch is easy to implement, and it only needs 0.5 h to be manufactured in the physical world, which verifies its effectiveness and efficiency. Another advantage of our infrared adversarial patches is the ability to extend to attack the visible object detector in the physical world. As a consequence, we can simultaneously perform the infrared and visible physical attacks by a unified adversarial patch, which shows the good generalization.</p>","PeriodicalId":13752,"journal":{"name":"International Journal of Computer Vision","volume":"31 1","pages":""},"PeriodicalIF":11.6000,"publicationDate":"2023-12-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Infrared Adversarial Patches with Learnable Shapes and Locations in the Physical World\",\"authors\":\"Xingxing Wei, Jie Yu, Yao Huang\",\"doi\":\"10.1007/s11263-023-01963-y\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>Owing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are complicated to implement in practical application because of their complex transformation from the digital world to physical world. To address this issue, in this paper, we propose a physically feasible infrared attack method called “infrared adversarial patches”. Considering the imaging mechanism of infrared cameras by capturing objects’ thermal radiation, infrared adversarial patches conduct attacks by attaching a patch of thermal insulation materials on the target object to manipulate its thermal distribution. To enhance adversarial attacks, we present a novel aggregation regularization to guide the simultaneous learning for the patch’s shape and location on the target object. Thus, a simple gradient-based optimization can be adapted to solve for them. We verify infrared adversarial patches in different object detection tasks with various object detectors. Experimental results show that our method achieves more than 90% Attack Success Rate (ASR) versus the pedestrian detector and vehicle detector in the physical environment, where the objects are captured in different angles, distances, postures, and scenes. More importantly, infrared adversarial patch is easy to implement, and it only needs 0.5 h to be manufactured in the physical world, which verifies its effectiveness and efficiency. Another advantage of our infrared adversarial patches is the ability to extend to attack the visible object detector in the physical world. As a consequence, we can simultaneously perform the infrared and visible physical attacks by a unified adversarial patch, which shows the good generalization.</p>\",\"PeriodicalId\":13752,\"journal\":{\"name\":\"International Journal of Computer Vision\",\"volume\":\"31 1\",\"pages\":\"\"},\"PeriodicalIF\":11.6000,\"publicationDate\":\"2023-12-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Computer Vision\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://doi.org/10.1007/s11263-023-01963-y\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Computer Vision","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.1007/s11263-023-01963-y","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE","Score":null,"Total":0}
Infrared Adversarial Patches with Learnable Shapes and Locations in the Physical World
Owing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are complicated to implement in practical application because of their complex transformation from the digital world to physical world. To address this issue, in this paper, we propose a physically feasible infrared attack method called “infrared adversarial patches”. Considering the imaging mechanism of infrared cameras by capturing objects’ thermal radiation, infrared adversarial patches conduct attacks by attaching a patch of thermal insulation materials on the target object to manipulate its thermal distribution. To enhance adversarial attacks, we present a novel aggregation regularization to guide the simultaneous learning for the patch’s shape and location on the target object. Thus, a simple gradient-based optimization can be adapted to solve for them. We verify infrared adversarial patches in different object detection tasks with various object detectors. Experimental results show that our method achieves more than 90% Attack Success Rate (ASR) versus the pedestrian detector and vehicle detector in the physical environment, where the objects are captured in different angles, distances, postures, and scenes. More importantly, infrared adversarial patch is easy to implement, and it only needs 0.5 h to be manufactured in the physical world, which verifies its effectiveness and efficiency. Another advantage of our infrared adversarial patches is the ability to extend to attack the visible object detector in the physical world. As a consequence, we can simultaneously perform the infrared and visible physical attacks by a unified adversarial patch, which shows the good generalization.
期刊介绍:
The International Journal of Computer Vision (IJCV) serves as a platform for sharing new research findings in the rapidly growing field of computer vision. It publishes 12 issues annually and presents high-quality, original contributions to the science and engineering of computer vision. The journal encompasses various types of articles to cater to different research outputs.
Regular articles, which span up to 25 journal pages, focus on significant technical advancements that are of broad interest to the field. These articles showcase substantial progress in computer vision.
Short articles, limited to 10 pages, offer a swift publication path for novel research outcomes. They provide a quicker means for sharing new findings with the computer vision community.
Survey articles, comprising up to 30 pages, offer critical evaluations of the current state of the art in computer vision or offer tutorial presentations of relevant topics. These articles provide comprehensive and insightful overviews of specific subject areas.
In addition to technical articles, the journal also includes book reviews, position papers, and editorials by prominent scientific figures. These contributions serve to complement the technical content and provide valuable perspectives.
The journal encourages authors to include supplementary material online, such as images, video sequences, data sets, and software. This additional material enhances the understanding and reproducibility of the published research.
Overall, the International Journal of Computer Vision is a comprehensive publication that caters to researchers in this rapidly growing field. It covers a range of article types, offers additional online resources, and facilitates the dissemination of impactful research.