PhysGAN: Generating Physical-World-Resilient Adversarial Examples for Autonomous Driving
arXiv:1907.04449
Abstract
Although Deep neural networks (DNNs) are being pervasively used in vision-based autonomous driving systems, they are found vulnerable to adversarial attacks where small-magnitude perturbations into the inputs during test time cause dramatic changes to the outputs. While most of the recent attack methods target at digital-world adversarial scenarios, it is unclear how they perform in the physical world, and more importantly, the generated perturbations under such methods would cover a whole driving scene including those fixed background imagery such as the sky, making them inapplicable to physical world implementation. We present PhysGAN, which generates physical-world-resilient adversarial examples for mislead-ing autonomous driving systems in a continuous manner. We show the effectiveness and robustness of PhysGAN via extensive digital and real-world evaluations. Digital experiments show that PhysGAN is effective for various steer-ing models and scenes, which misleads the average steer-ing angle by up to 23.06 degrees under various scenarios. The real-world studies further demonstrate that PhysGAN is sufficiently resilient in practice, which misleads the average steering angle by up to 19.17 degrees. We compare PhysGAN with a set of state-of-the-art baseline methods including several of our self-designed ones, which further demonstrate the robustness and efficacy of our approach. We also show that PhysGAN outperforms state-of-the-art baseline methods To the best of our knowledge, PhysGANis probably the first technique of generating realistic and physical-world-resilient adversarial examples for attacking common autonomous driving scenarios.
11 pages
References in corpus (18)
- Distilling the Knowledge in a Neural Network
- Unpaired Image-to-Image Translation using Cycle-Consistent Adversarial Networks
- DeepXplore: Automated Whitebox Testing of Deep Learning Systems
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Synthesizing Robust Adversarial Examples
- Robust Physical-World Attacks on Deep Learning Models
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- Spatially Transformed Adversarial Examples
- Generating Adversarial Examples with Adversarial Networks
- NO Need to Worry about Adversarial Examples in Object Detection in Autonomous Vehicles
- Adversarial Examples that Fool both Computer Vision and Time-Limited Humans
- Virtual to Real Reinforcement Learning for Autonomous Driving
- LaVAN: Localized and Visible Adversarial Noise
- A Boundary Tilting Persepective on the Phenomenon of Adversarial Examples
- Constructing Unrestricted Adversarial Examples with Generative Models
- DeepRoad: GAN-based Metamorphic Autonomous Driving System Testing
- DeepBillboard: Systematic Physical-World Testing of Autonomous Driving Systems
- Attribute-Guided Face Generation Using Conditional CycleGAN