Physically Realizable Adversarial Examples for LiDAR Object Detection
Modern autonomous driving systems rely heavily on deep learning models to process point cloud sensory data; meanwhile, deep models have been shown to be susceptible to adversarial attacks with visually imperceptible perturbations. Despite the fact that this poses a security concern for the self-driving industry, there has been very little exploration in terms of 3D perception, as most adversarial attacks have only been applied to 2D flat images. In this paper, we address this issue and present a method to generate universal 3D adversarial objects to fool LiDAR detectors. In particular, we demonstrate that placing an adversarial object on the rooftop of any target vehicle to hide the vehicle entirely from LiDAR detectors with a success rate of 80%. We report attack results on a suite of detectors using various input representation of point clouds. We also conduct a pilot study on adversarial defense using data augmentation. This is one step closer towards safer self-driving under unseen conditions from limited training data.
Code (0)
등록된 구현이 없습니다.
Tasks
Adversarial DefenseAutonomous DrivingData AugmentationObjectobject-detectionObject DetectionSimilar Papers 제목 키워드 기반
OBJVanish: Physically Realizable Text-to-3D Adv. Generation of LiDAR-Invisible Objects
LiDAR-based 3D object detectors are fundamental to autonomous driving, where failing to detect objects poses severe safety risks. Developing effective 3D adversarial attacks is essential for thoroughly testing these dete…
Autonomous DrivingAdversarial camera stickers: A physical camera-based attack on deep learning systems
Recent work has documented the susceptibility of deep learning systems to adversarial examples, but most such attacks directly manipulate the digital input to a classifier. Although a smaller line of work considers physi…
Exploring Adversarial Robustness of Multi-Sensor Perception Systems in Self Driving
Modern self-driving perception systems have been shown to improve upon processing complementary inputs such as LiDAR with images. In isolation, 2D images have been found to be extremely vulnerable to adversarial attacks.…
Adversarial RobustnessDenoisingSensor FusionAdv3D: Generating 3D Adversarial Examples for 3D Object Detection in Driving Scenarios with NeRF
Deep neural networks (DNNs) have been proven extremely susceptible to adversarial examples, which raises special safety-critical concerns for DNN-based autonomous driving stacks (i.e., 3D object detection). Although ther…
3D Object DetectionAutonomous DrivingData AugmentationNeRF+2Revisiting Physically Realizable Adversarial Object Attack against LiDAR-based Detection: Clarifying Problem Formulation and Experimental Protocols
Adversarial robustness in LiDAR-based 3D object detection is a critical research area due to its widespread application in real-world scenarios. While many digital attacks manipulate point clouds or meshes, they often la…
Adversarial Robustness3D Object DetectionPoint Clouds