论文标题
3D隐形斗篷
3D Invisible Cloak
论文作者
论文摘要
在本文中,我们提出了针对现实世界中人探测器的新型物理隐形攻击。所提出的方法会产生对抗性补丁,并将其在真实的衣服上打印以制作三维(3D)隐形斗篷。任何戴着斗篷的人都可以逃避对人探测器的检测并实现隐身。我们考虑了这些3D物理约束(即Radian,皱纹,遮挡,角度等)对人隐身攻击的影响,并提出3D转换以产生3D看不见的斗篷。我们通过在具有挑战性和复杂的3D物理场景下打印在真实衣服上的对抗斑块,在3D物理空间中发射人的隐形攻击,而不是2D平面。传统和3D转换在其优化过程中在贴片上进行。此外,我们研究了如何生成最佳的3D隐形斗篷。具体来说,我们探索如何选择具有特定形状和颜色的输入图像来生成最佳的3D隐形斗篷。此外,在成功使对象探测器错误地判断该人作为其他对象之后,我们探索了如何使一个人完全消失,即不会被检测为任何对象。最后,我们提出了一个系统的评估框架,以有条不紊地评估数字领域和物理世界中提议的攻击的性能。各种室内和室外物理场景的实验结果表明,即使在那些复杂且具有挑战性的身体状况下,拟议的人隐身攻击方法也是强大而有效的,例如斗篷皱纹,遮盖,弯曲,弯曲和不同角度。数字领域的攻击成功率(INRIA数据集)为86.56%,而物理世界中的静态和动态隐形攻击性能分别为100%和77%,其明显好于现有作品。
In this paper, we propose a novel physical stealth attack against the person detectors in real world. The proposed method generates an adversarial patch, and prints it on real clothes to make a three dimensional (3D) invisible cloak. Anyone wearing the cloak can evade the detection of person detectors and achieve stealth. We consider the impacts of those 3D physical constraints (i.e., radian, wrinkle, occlusion, angle, etc.) on person stealth attacks, and propose 3D transformations to generate 3D invisible cloak. We launch the person stealth attacks in 3D physical space instead of 2D plane by printing the adversarial patches on real clothes under challenging and complex 3D physical scenarios. The conventional and 3D transformations are performed on the patch during its optimization process. Further, we study how to generate the optimal 3D invisible cloak. Specifically, we explore how to choose input images with specific shapes and colors to generate the optimal 3D invisible cloak. Besides, after successfully making the object detector misjudge the person as other objects, we explore how to make a person completely disappeared, i.e., the person will not be detected as any objects. Finally, we present a systematic evaluation framework to methodically evaluate the performance of the proposed attack in digital domain and physical world. Experimental results in various indoor and outdoor physical scenarios show that, the proposed person stealth attack method is robust and effective even under those complex and challenging physical conditions, such as the cloak is wrinkled, obscured, curved, and from different angles. The attack success rate in digital domain (Inria data set) is 86.56%, while the static and dynamic stealth attack performance in physical world is 100% and 77%, respectively, which are significantly better than existing works.