paper-with-me

홈 › Papers

Invisible Perturbations: Physical Adversarial Examples Exploiting the Rolling Shutter Effect

2020-11-26 · CVPR 2021 1 · Athena Sayles, Ashish Hooda, Mohit Gupta, Rahul Chatterjee, Earlence Fernandes

Physical adversarial examples for camera-based computer vision have so far been achieved through visible artifacts -- a sticker on a Stop sign, colorful borders around eyeglasses or a 3D printed object with a colorful texture. An implicit assumption here is that the perturbations must be visible so that a camera can sense them. By contrast, we contribute a procedure to generate, for the first time, physical adversarial examples that are invisible to human eyes. Rather than modifying the victim object with visible artifacts, we modify light that illuminates the object. We demonstrate how an attacker can craft a modulated light signal that adversarially illuminates a scene and causes targeted misclassifications on a state-of-the-art ImageNet deep learning model. Concretely, we exploit the radiometric rolling shutter effect in commodity cameras to create precise striping patterns that appear on images. To human eyes, it appears like the object is illuminated, but the camera creates an image with stripes that will cause ML models to output the attacker-desired classification. We conduct a range of simulation and physical experiments with LEDs, demonstrating targeted attack rates up to 84%.

📄 PDF Abstract BibTeX arXiv:2011.13375

Code (2)

EarlMadSec/invis-perturbations 공식 구현 pytorch
earlence-security/invis-perturbations pytorch

Tasks

Object

Similar Papers 제목 키워드 기반

ITPatch: An Invisible and Triggered Physical Adversarial Patch against Traffic Sign Recognition

2024-09-19 · Shuai Yuan, Hongwei Li, Xingshuo Han, Guowen Xu 외

Physical adversarial patches have emerged as a key adversarial attack to cause misclassification of traffic sign recognition (TSR) systems in the real world. However, existing adversarial patches have poor stealthiness a…

Adversarial AttackTraffic Sign Recognition

NaturalAE: Natural and Robust Physical Adversarial Examples for Object Detectors

2020-11-27 · Mingfu Xue, Chengxiang Yuan, Can He, Jian Wang 외

In this paper, we propose a natural and robust physical adversarial example attack method targeting object detectors under real-world conditions. The generated adversarial examples are robust to various physical constrai…

Adversarial Attackobject-detectionObject Detection

Adversarial Wear and Tear: Exploiting Natural Damage for Generating Physical-World Adversarial Examples

2025-03-27 · Samra Irshad, Seungkyu Lee, Nassir Navab, Hong Joo Lee 외

The presence of adversarial examples in the physical world poses significant challenges to the deployment of Deep Neural Networks in safety-critical applications such as autonomous driving. Most existing methods for craf…

Autonomous DrivingImage-to-Image TranslationUnsupervised Image-To-Image Translation

Demiguise Attack: Crafting Invisible Semantic Adversarial Perturbations with Perceptual Similarity

2021-07-03 · Yajie Wang, Shangbo Wu, Wenyi Jiang, Shengang Hao 외

Deep neural networks (DNNs) have been found to be vulnerable to adversarial examples. Adversarial examples are malicious images with visually imperceptible perturbations. While these carefully crafted perturbations restr…

Robust Physical-World Attacks on Deep Learning Models

2017-07-27 · Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li 외

Recent studies show that the state-of-the-art deep neural networks (DNNs) are vulnerable to adversarial examples, resulting from small-magnitude perturbations added to the input. Given that that emerging physical systems…

Deep Learning