Adversarial Vulnerability of Temporal Feature Networks for Object Detection
Taking into account information across the temporal domain helps to improve environment perception in autonomous driving. However, it has not been studied so far whether temporally fused neural networks are vulnerable to deliberately generated perturbations, i.e. adversarial attacks, or whether temporal history is an inherent defense against them. In this work, we study whether temporal feature networks for object detection are vulnerable to universal adversarial attacks. We evaluate attacks of two types: imperceptible noise for the whole image and locally-bound adversarial patch. In both cases, perturbations are generated in a white-box manner using PGD. Our experiments confirm, that attacking even a portion of a temporal input suffices to fool the network. We visually assess generated perturbations to gain insights into the functioning of attacks. To enhance the robustness, we apply adversarial training using 5-PGD. Our experiments on KITTI and nuScenes datasets demonstrate, that a model robustified via K-PGD is able to withstand the studied attacks while keeping the mAP-based performance comparable to that of an unattacked model.
Code (0)
등록된 구현이 없습니다.
Tasks
Autonomous DrivingObjectobject-detectionObject DetectionSimilar Papers 제목 키워드 기반
Using Feature Alignment Can Improve Clean Average Precision and Adversarial Robustness in Object Detection
The 2D object detection in clean images has been a well studied topic, but its vulnerability against adversarial attack is still worrying. Existing work has improved robustness of object detectors by adversarial training…
2D Object DetectionAdversarial AttackAdversarial RobustnessObject+2Adversarial Attack and Defense of YOLO Detectors in Autonomous Driving Scenarios
Visual detection is a key task in autonomous driving, and it serves as a crucial foundation for self-driving planning and control. Deep neural networks have achieved promising results in various visual tasks, but they ar…
Adversarial AttackAdversarial DefenseAutonomous DrivingAutonomous Vehicles+2The Meeseeks Mesh: Spatially Consistent 3D Adversarial Objects for BEV Detector
3D object detection is a critical component in autonomous driving systems. It allows real-time recognition and detection of vehicles, pedestrians and obstacles under varying environmental conditions. Among existing metho…
3D Object DetectionAutonomous DrivingObjectobject-detection+1Learning Mutual View Information Graph for Adaptive Adversarial Collaborative Perception
Collaborative perception (CP) enables data sharing among connected and autonomous vehicles (CAVs) to enhance driving safety. However, CP systems are vulnerable to adversarial attacks where malicious agents forge false ob…
Autonomous VehiclesGraph LearningBankTweak: Adversarial Attack against Multi-Object Trackers by Manipulating Feature Banks
Multi-object tracking (MOT) aims to construct moving trajectories for objects, and modern multi-object trackers mainly utilize the tracking-by-detection methodology. Initial approaches to MOT attacks primarily aimed to d…
Adversarial AttackMulti-Object TrackingObjectObject Tracking