A Novel Physical World Adversarial Patch Attack for Infrared Pedestrian Detector

Zichen Liu, Jiaxin Dai, Jie Geng

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

As deep learning continues to evolve, infrared pedestrian detection technology has experienced significant advancements.However, infrared pedestrian detectors remain susceptible to adversarial attacks, potentially causing detection failures.To address the challenges of implementing physical world adversarial patch attacks on infrared images, such as difficult implementation, poor naturalness, and complex content, a novel physical world adversarial patch attack for infrared pedestrian detectors is developed.An expectation over transformation of the infrared image is added to the input image, and the naturalness of the adversarial patch is improved by adding nonlinear transformation and brightness transformation in the training process.Subsequently, mask regularization is designed in the training process to reduce content complexity and enhance practicality.Considering the deformation problem of the adversarial patch in the physical world, thin-plate spline interpolation is introduced in the training process to make the trained adversarial patch more suitable for the physical world.The experimental results show that the proposed method solves the problems of high complexity and poor naturalness of the adversarial patch effectively, and realizes effective counterattack in the physical world.

Original languageEnglish
Title of host publicationProceedings of 2024 IEEE International Conference on Unmanned Systems, ICUS 2024
EditorsRong Song
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1363-1368
Number of pages6
ISBN (Electronic)9798350384185
DOIs
StatePublished - 2024
Event2024 IEEE International Conference on Unmanned Systems, ICUS 2024 - Nanjing, China
Duration: 18 Oct 202420 Oct 2024

Publication series

NameProceedings of 2024 IEEE International Conference on Unmanned Systems, ICUS 2024

Conference

Conference2024 IEEE International Conference on Unmanned Systems, ICUS 2024
Country/TerritoryChina
CityNanjing
Period18/10/2420/10/24

Keywords

  • infrared image
  • object detection
  • physical world attack
  • thin-plate spline interpolation

Fingerprint

Dive into the research topics of 'A Novel Physical World Adversarial Patch Attack for Infrared Pedestrian Detector'. Together they form a unique fingerprint.

Cite this