Verifying Adversarial Robustness of 3D Object Detectors for Autonomous Vehicles

Verifying Adversarial Robustness of 3D Object Detectors for Autonomous Vehicles
复制标题

DOI:
10.1109/urtc56832.2022.10002253
复制
发表时间:
2022-09
期刊:
2022 IEEE MIT Undergraduate Research Technology Conference (URTC)
影响因子:
--
通讯作者:
Rebecca Dollahite;Kevin Wang;Kaidong Li;Yiqing Zhang;Ziming Zhang
Rebecca Dollahite;Kevin Wang;Kaidong Li;Yiqing Zhang;Ziming Zhang
中科院分区:
其他
文献类型:
--
作者:
Rebecca Dollahite;Kevin Wang;Kaidong Li;Yiqing Zhang;Ziming Zhang

文献摘要

相似文献

用于自动驾驶车辆的领先 3D 物体检测器(例如 PIXOR)不能可靠地解释噪声,并且容易受到对抗性攻击。现有的攻击方法不能准确地模拟自然发生的噪声,因为它们试图在离散的输入空间上连续地进行攻击。在本文中,我们提出了一种新颖的攻击方法,该方法通过进行梯度通知的离散变化来最大化损失。图像中的点子集根据原始梯度和新梯度之间的百分比变化进行移动。我们根据攻击与原始点云和数值指标的视觉相似性来衡量攻击的有效性。
Leading 3D object detectors for automated vehicles, such as PIXOR, do not robustly account for noise and are vulnerable to adversarial attacks. Existing attack methods do not accurately simulate naturally occurring noise, as they attempt to continuously on a discrete input space. In this paper, we propose a novel attack method, which maximizes loss by making gradient-informed, discrete changes. A subset of points within an image move based on a percentage change between the original and new gradient. We measure the validity of an attack based on its visual similarity to the original point cloud and numeric metrics.