On the Real-World Adversarial Robustness of Real-Time Semantic Segmentation Models for Autonomous Driving
arXiv:2201.01850 · doi:10.1109/TNNLS.2023.3314512
Abstract
The existence of real-world adversarial examples (commonly in the form of patches) poses a serious threat for the use of deep learning models in safety-critical computer vision tasks such as visual perception in autonomous driving. This paper presents an extensive evaluation of the robustness of semantic segmentation models when attacked with different types of adversarial patches, including digital, simulated, and physical ones. A novel loss function is proposed to improve the capabilities of attackers in inducing a misclassification of pixels. Also, a novel attack strategy is presented to improve the Expectation Over Transformation method for placing a patch in the scene. Finally, a state-of-the-art method for detecting adversarial patch is first extended to cope with semantic segmentation models, then improved to obtain real-time performance, and eventually evaluated in real-world scenarios. Experimental results reveal that, even though the adversarial effect is visible with both digital and real-world attacks, its impact is often spatially confined to areas of the image around the patch. This opens to further questions about the spatial robustness of real-time semantic segmentation models.
References in corpus (6)
- High-Resolution Representations for Labeling Pixels and Regions
- On Physical Adversarial Patches for Object Detection
- The Vulnerability of Semantic Segmentation Networks to Adversarial Attacks in Autonomous Driving: Enhancing Extensive Environment Sensing
- Physical Adversarial Attack on Vehicle Detector in the Carla Simulator
- PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image Classifier
- AdvSPADE: Realistic Unrestricted Attacks for Semantic Segmentation
Cited by in corpus (6)
- How Deep Learning Sees the World: A Survey on Adversarial Attacks & Defenses
- Benchmarking and Improving Bird's Eye View Perception Robustness in Autonomous Driving
- Defending From Physically-Realizable Adversarial Attacks Through Internal Over-Activation Analysis
- Attention-Based Real-Time Defenses for Physical Adversarial Attacks in Vision Applications
- Benchmarking the Spatial Robustness of DNNs via Natural and Adversarial Localized Corruptions
- AM-SAM: Automated Prompting and Mask Calibration for Segment Anything Model