An Adversarial Patch Attack for Vehicle Detectors in the Physical World

Panna Geng, Xinyang Deng

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Compared with global pixel-level adversarial samples, adversarial patches do not pursue visual concealment and are easier to achieve attack effects in the physical world. However, most of the existing adversarial patch attacks on vehicles have overlooked the influence of patch coverage position in the physical world. Some methods have not conducted real physical patch attack experiments, and the test of attack effect has been limited to the digital world. At the same time, during the patch optimization process, the attack effect when transferred to other models has not been considered. In this paper, we propose a vehicle adversarial patch attack method based on model perception and attention. Based on the model perception to high-frequency information, we use such high-frequency information of the image that the model cannot correctly classify as the initial adversarial patch to enhance the transferability. Based on the model attention patterns, the attention region of the model is obtained, and cover this region with patches as much as possible to achieve the attack more easily. Experiments demonstrate that our patch can remarkably reduce the detection accuracy of model in the digital world, while ensuring the attack effect of the adversarial patch in the physical world.

Original languageEnglish
Title of host publicationProceedings of 2023 IEEE International Conference on Unmanned Systems, ICUS 2023
EditorsRong Song
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1009-1013
Number of pages5
ISBN (Electronic)9798350316308
DOIs
StatePublished - 2023
Event2023 IEEE International Conference on Unmanned Systems, ICUS 2023 - Hefei, China
Duration: 13 Oct 202315 Oct 2023

Publication series

NameProceedings of 2023 IEEE International Conference on Unmanned Systems, ICUS 2023

Conference

Conference2023 IEEE International Conference on Unmanned Systems, ICUS 2023
Country/TerritoryChina
CityHefei
Period13/10/2315/10/23

Keywords

  • adversarial patch
  • vehicle detection

Fingerprint

Dive into the research topics of 'An Adversarial Patch Attack for Vehicle Detectors in the Physical World'. Together they form a unique fingerprint.

Cite this