Physical Adversarial Attack meets Computer Vision: A Decade Survey
arXiv:2209.15179 · doi:10.1109/TPAMI.2024.3430860
Abstract
Despite the impressive achievements of Deep Neural Networks (DNNs) in computer vision, their vulnerability to adversarial attacks remains a critical concern. Extensive research has demonstrated that incorporating sophisticated perturbations into input images can lead to a catastrophic degradation in DNNs' performance. This perplexing phenomenon not only exists in the digital space but also in the physical world. Consequently, it becomes imperative to evaluate the security of DNNs-based systems to ensure their safe deployment in real-world scenarios, particularly in security-sensitive applications. To facilitate a profound understanding of this topic, this paper presents a comprehensive overview of physical adversarial attacks. Firstly, we distill four general steps for launching physical adversarial attacks. Building upon this foundation, we uncover the pervasive role of artifacts carrying adversarial perturbations in the physical world. These artifacts influence each step. To denote them, we introduce a new term: adversarial medium. Then, we take the first step to systematically evaluate the performance of physical adversarial attacks, taking the adversarial medium as a first attempt. Our proposed evaluation metric, hiPAA, comprises six perspectives: Effectiveness, Stealthiness, Robustness, Practicability, Aesthetics, and Economics. We also provide comparative results across task categories, together with insightful observations and suggestions for future research directions.
Published at IEEE TPAMI. GitHub:https://github.com/weihui1308/PAA
References in corpus (17)
- FaceNet: A Unified Embedding for Face Recognition and Clustering
- One pixel attack for fooling deep neural networks
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- Alias-Free Generative Adversarial Networks
- DINO: DETR with Improved DeNoising Anchor Boxes for End-to-End Object Detection
- CoCa: Contrastive Captioners are Image-Text Foundation Models
- AdvHat: Real-world adversarial attack on ArcFace Face ID system
- A General Framework for Adversarial Examples with Objectives
- ShapeShifter: Robust Physical Adversarial Attack on Faster R-CNN Object Detector
- Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review
- Physical Adversarial Attack on Vehicle Detector in the Carla Simulator
- On adversarial patches: real-world attack on ArcFace-100 face recognition system
- Physical Adversarial Attacks for Surveillance: A Survey
- SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image Classifiers
- Projecting Trouble: Light Based Adversarial Attacks on Deep Learning Classifiers
- TPatch: A Triggered Physical Adversarial Patch
- Distributional Modeling for Location-Aware Adversarial Patches
Cited by in corpus (4)
- AdvReal: Physical Adversarial Patch Generation Framework for Security Evaluation of Object Detection Systems
- Higher-Order Adversarial Patches for Real-Time Object Detectors
- Understanding Adversarial Transferability in Vision-Language Models for Autonomous Driving: A Cross-Architecture Analysis
- We Can Always Catch You: Detecting Adversarial Patched Objects WITH or WITHOUT Signature