SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image Classifiers
Bingyao Huang, Haibin Ling
Abstract
Light-based adversarial attacks use spatial augmented reality (SAR) techniques to fool image classifiers by altering the physical light condition with a controllable light source, e.g., a projector. Compared with physical attacks that place hand-crafted adversarial objects, projector-based ones obviate modifying the physical entities, and can be performed transiently and dynamically by altering the projection pattern. However, subtle light perturbations are insufficient to fool image classifiers, due to the complex environment and project-and-capture process. Thus, existing approaches focus on projecting clearly perceptible adversarial patterns, while the more interesting yet challenging goal, stealthy projector-based attack, remains open. In this paper, for the first time, we formulate this problem as an end-to-end differentiable process and propose a Stealthy Projector-based Adversarial Attack (SPAA) solution. In SPAA, we approximate the real Project-and-Capture process using a deep neural network named PCNet, then we include PCNet in the optimization of projector-based attacks such that the generated adversarial projection is physically plausible. Finally, to generate both robust and stealthy adversarial projections, we propose an algorithm that uses minimum perturbation and adversarial confidence thresholds to alternate between the adversarial loss and stealthiness loss optimization. Our experimental evaluations show that SPAA clearly outperforms other methods by achieving higher attack success rates and meanwhile being stealthier, for both targeted and untargeted attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 231976d1-c0f0-4d41-9966-3eb664c3d1e0Cited by top-tier papers5
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical WorldDonghua Wang, Wen Yao, Tingsong Jiang, Chao Li et al.ICCV 2023 · 47 citations
- When Lighting Deceives: Exposing Vision-Language Models' Illumination Vulnerability Through Illumination Transformation AttackHanqing Liu, Shouwei Ruan, Yao Huang, Shiji Zhao et al.ICCV 2025 · 13 citations
- LAPIG: Language Guided Projector Image Generation with Surface Adaptation and StylizationYuchen Deng, Haibin Ling, Bingyao HuangIEEE VR 2025 · 6 citations
- Embodied Laser Attack: Leveraging Scene Priors to Achieve Agent-based Robust Non-contact AttacksYitong Sun, Yao Huang, Xingxing WeiACM MM 2024 · 2 citations
Builds on8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- A privacy-preserving approach to streaming eye-tracking dataBrendan David-John, Diane Hosfelt, Kevin R. B. Butler, Eakta JainIEEE VR 2021 · 89 citations
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
- On the Design of Black-Box Adversarial Examples by Leveraging Gradient-Free Optimization and Operator Splitting MethodPu Zhao, Sijia Liu, Pin-Yu Chen, Nghia Hoang et al.ICCV 2019 · 61 citations
Related papers
- Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a BlinkRanjie Duan, Xiaofeng Mao, A. K. Qin, Yuefeng Chen et al.CVPR 2021
- DeProCams: Simultaneous Relighting, Compensation and Shape Reconstruction for Projector-Camera SystemsBingyao Huang, Haibin LingIEEE VR 2021 · 30 citations
- ProjAttacker: A Configurable Physical Adversarial Attack for Face Recognition via ProjectorYuanwei Liu, Hui Wei, Chengyu Jia, Ruqi Xiao et al.CVPR 2025
- DPCS: Path Tracing-Based Differentiable Projector-Camera SystemsJijiang Li, Qingyue Deng, Haibin Ling, Bingyao HuangIEEE VR 2025 · 4 citations
- SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial PerturbationsGiulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier et al.USENIX Security 2021 · 123 citations
