Physics-Based Adversarial Attack on Near-Infrared Human Detector for Nighttime Surveillance Camera Systems
Muyao Niu, Zhuoxiao Li, Yifan Zhan, Huy H. Nguyen, Isao Echizen, Yinqiang Zheng
Abstract
Many surveillance cameras switch between daytime and nighttime modes based on illuminance levels. During the day, the camera records ordinary RGB images through an enabled IR-cut filter. At night, the filter is disabled to capture near-infrared (NIR) light emitted from NIR LEDs typically mounted around the lens. While RGB-based AI algorithm vulnerabilities have been widely reported, the vulnerabilities of NIR-based AI have rarely been investigated. In this paper, we identify fundamental vulnerabilities in NIR-based image understanding caused by color and texture loss due to the intrinsic characteristics of clothes' reflectance and cameras' spectral sensitivity in the NIR range. We further show that the nearly co-located configuration of illuminants and cameras in existing surveillance systems facilitates concealing and fully passive attacks in the physical world. Specifically, we demonstrate how retro-reflective and insulation plastic tapes can manipulate the intensity distribution of NIR images. We showcase an attack on the YOLO-based human detector using binary patterns designed in the digital space (via black-box query and searching) and then physically realized using tapes pasted onto clothes. Our attack highlights significant reliability concerns for nighttime surveillance systems, which are intended to enhance security. Codes Available: https://github.com/MyNiuuu/AdvNIR.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Adversarial Attacks on Event-Based Pedestrian Detectors: A Physical ApproachGuixu Lin, Muyao Niu, Qingtian Zhu, Zhengwei Yin et al.AAAI 2025 · 5 citations
- Motion-Aware Animatable Gaussian Avatars DeblurringMuyao Niu, Yifan Zhan, Qingtian Zhu, Zhuoxiao Li et al.CVPR 2026
- Adversarial Patch EXterminator: Zero-Shot and Patch-Agnostic Defense Framework Against Adversarial Patch AttacksJiayimei Wang, Tao Ni, Guowen Xu, Qingchuan Zhao et al.USENIX Security 2026
Builds on20
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- FMCNet: Feature-Level Modality Compensation for Visible-Infrared Person Re-IdentificationQiang Zhang, Changzhou Lai, Jianan Liu, Nianchang Huang et al.CVPR 2022 · 257 citations
- Naturalistic Physical Adversarial Patch for Object DetectorsYu-Chih-Tuan Hu, Jun-Cheng Chen, Bo-Han Kung, Kai-Lung Hua et al.ICCV 2021 · 224 citations
- FCA: Learning a 3D Full-Coverage Vehicle Camouflage for Multi-View Physical Adversarial AttackDonghua Wang, Tingsong Jiang, Jialiang Sun, Weien Zhou et al.AAAI 2022 · 149 citations
- Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural PhenomenonYiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang et al.CVPR 2022 · 148 citations
Related papers
- Fooling Thermal Infrared Pedestrian Detectors in Real World Using Small BulbsXiaopei Zhu, Xiao Li, Jianmin Li, Zheyao Wang et al.AAAI 2021 · 108 citations
- Optimal LED Spectral Multiplexing for NIR2RGB TranslationLei Liu, Yuze Chen, Junchi Yan, Yinqiang ZhengCVPR 2022 · 8 citations
- Unified Adversarial Patch for Cross-modal Attacks in the Physical WorldXingxing Wei, Yao Huang, Yitong Sun, Jie YuICCV 2023 · 44 citations
- Infrared Invisible Clothing: Hiding from Infrared Detectors at Multiple Angles in Real WorldXiaopei Zhu, Zhanhao Hu, Siyuan Huang, Jianmin Li et al.CVPR 2022 · 67 citations
- Invisible Perturbations: Physical Adversarial Examples Exploiting the Rolling Shutter EffectAthena Sayles, Ashish Hooda, Mohit Gupta, Rahul Chatterjee et al.CVPR 2021
