Adversarial Laser Spot: Robust and Covert Physical-World Attack to DNNs

Chengyin Hu, Yilong Wang, Kalibinuer Tiliwalidi, Wen Li
Proceedings of The 14th Asian Conference on Machine Learning, PMLR 189:483-498, 2023.

Abstract

Most existing deep neural networks (DNNs) are easily disturbed by slight noise. However, there are few researches on physical attacks by deploying lighting equipment. The light-based physical attacks has excellent covertness, which brings great security risks to many vision-based applications (such as self-driving). Therefore, we propose a light-based physical attack, called adversarial laser spot (AdvLS), which optimizes the physical parameters of laser spots through genetic algorithm to perform physical attacks. It realizes robust and covert physical attack by using low-cost laser equipment. As far as we know, AdvLS is the first light-based physical attack that perform physical attacks in the daytime. A large number of experiments in the digital and physical environments show that AdvLS has excellent robustness and covertness. In addition, through in-depth analysis of the experimental data, we find that the adversarial perturbations generated by AdvLS have superior adversarial attack migration. The experimental results show that AdvLS impose serious interference to advanced DNNs, we call for the attention of the proposed AdvLS.

Cite this Paper


BibTeX
@InProceedings{pmlr-v189-hu23b, title = {Adversarial Laser Spot: Robust and Covert Physical-World Attack to DNNs}, author = {Hu, Chengyin and Wang, Yilong and Tiliwalidi, Kalibinuer and Li, Wen}, booktitle = {Proceedings of The 14th Asian Conference on Machine Learning}, pages = {483--498}, year = {2023}, editor = {Khan, Emtiyaz and Gonen, Mehmet}, volume = {189}, series = {Proceedings of Machine Learning Research}, month = {12--14 Dec}, publisher = {PMLR}, pdf = {https://proceedings.mlr.press/v189/hu23b/hu23b.pdf}, url = {https://proceedings.mlr.press/v189/hu23b.html}, abstract = {Most existing deep neural networks (DNNs) are easily disturbed by slight noise. However, there are few researches on physical attacks by deploying lighting equipment. The light-based physical attacks has excellent covertness, which brings great security risks to many vision-based applications (such as self-driving). Therefore, we propose a light-based physical attack, called adversarial laser spot (AdvLS), which optimizes the physical parameters of laser spots through genetic algorithm to perform physical attacks. It realizes robust and covert physical attack by using low-cost laser equipment. As far as we know, AdvLS is the first light-based physical attack that perform physical attacks in the daytime. A large number of experiments in the digital and physical environments show that AdvLS has excellent robustness and covertness. In addition, through in-depth analysis of the experimental data, we find that the adversarial perturbations generated by AdvLS have superior adversarial attack migration. The experimental results show that AdvLS impose serious interference to advanced DNNs, we call for the attention of the proposed AdvLS.} }
Endnote
%0 Conference Paper %T Adversarial Laser Spot: Robust and Covert Physical-World Attack to DNNs %A Chengyin Hu %A Yilong Wang %A Kalibinuer Tiliwalidi %A Wen Li %B Proceedings of The 14th Asian Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2023 %E Emtiyaz Khan %E Mehmet Gonen %F pmlr-v189-hu23b %I PMLR %P 483--498 %U https://proceedings.mlr.press/v189/hu23b.html %V 189 %X Most existing deep neural networks (DNNs) are easily disturbed by slight noise. However, there are few researches on physical attacks by deploying lighting equipment. The light-based physical attacks has excellent covertness, which brings great security risks to many vision-based applications (such as self-driving). Therefore, we propose a light-based physical attack, called adversarial laser spot (AdvLS), which optimizes the physical parameters of laser spots through genetic algorithm to perform physical attacks. It realizes robust and covert physical attack by using low-cost laser equipment. As far as we know, AdvLS is the first light-based physical attack that perform physical attacks in the daytime. A large number of experiments in the digital and physical environments show that AdvLS has excellent robustness and covertness. In addition, through in-depth analysis of the experimental data, we find that the adversarial perturbations generated by AdvLS have superior adversarial attack migration. The experimental results show that AdvLS impose serious interference to advanced DNNs, we call for the attention of the proposed AdvLS.
APA
Hu, C., Wang, Y., Tiliwalidi, K. & Li, W.. (2023). Adversarial Laser Spot: Robust and Covert Physical-World Attack to DNNs. Proceedings of The 14th Asian Conference on Machine Learning, in Proceedings of Machine Learning Research 189:483-498 Available from https://proceedings.mlr.press/v189/hu23b.html.

Related Material