Fooling Detection Alone is Not Enough: First Adversarial Attack against Multiple Object Tracking

Fooling Detection Alone is Not Enough: First Adversarial Attack against Multiple Object Tracking
复制标题

DOI:
--
复制
发表时间:
2019-05
期刊:
ArXiv
影响因子:
--
通讯作者:
Yunhan Jia;Yantao Lu;Junjie Shen;Qi Alfred Chen;Zhenyu Zhong;Tao Wei
Yunhan Jia;Yantao Lu;Junjie Shen;Qi Alfred Chen;Zhenyu Zhong;Tao Wei
中科院分区:
其他
文献类型:
--
作者:
Yunhan Jia;Yantao Lu;Junjie Shen;Qi Alfred Chen;Zhenyu Zhong;Tao Wei

文献摘要

被引文献

相似文献

对抗机器学习的最新工作开始着重于自动驾驶中的视觉感知,并研究了对象检测模型的对抗示例(AES)。但是,在这样的视觉感知管道中,还必须在称为多个对象跟踪(MOT)的过程中跟踪检测到的对象,以构建周围障碍物的移动轨迹。由于MOT被设计为在对象检测中的错误中具有强大的态度,因此它对盲目针对异议检测的现有攻击技术构成了一般挑战:我们发现,他们需要超过98%的成功率才能实际影响跟踪结果,A要求没有现有的攻击技术能够满足。在本文中,我们是第一个研究对抗机器学习的攻击,以针对自动驾驶中完整的视觉感知管道进行,并发现一种新颖的攻击技术,Tracker劫持,可以有效地使用AES使用AES进行对象检测。使用我们的技术,仅在一个框架上成功的AES就可以将现有对象移入或移出自动驾驶汽车的进展,从而引起潜在的安全危害。我们使用Berkeley Deep Drive数据集进行评估,并发现当3帧受到攻击时,我们的攻击能够具有近100%的成功率,而盲目靶向对象检测的攻击只有高达25%。
Recent work in adversarial machine learning started to focus on the visual perception in autonomous driving and studied Adversarial Examples (AEs) for object detection models. However, in such visual perception pipeline the detected objects must also be tracked, in a process called Multiple Object Tracking (MOT), to build the moving trajectories of surrounding obstacles. Since MOT is designed to be robust against errors in object detection, it poses a general challenge to existing attack techniques that blindly target objection detection: we find that a success rate of over 98% is needed for them to actually affect the tracking results, a requirement that no existing attack technique can satisfy. In this paper, we are the first to study adversarial machine learning attacks against the complete visual perception pipeline in autonomous driving, and discover a novel attack technique, tracker hijacking, that can effectively fool MOT using AEs on object detection. Using our technique, successful AEs on as few as one single frame can move an existing object in to or out of the headway of an autonomous vehicle to cause potential safety hazards. We perform evaluation using the Berkeley Deep Drive dataset and find that on average when 3 frames are attacked, our attack can have a nearly 100% success rate while attacks that blindly target object detection only have up to 25%.