USENIX Security2023Top-tier venue
X-Adv: Physical Adversarial Object Attacks against X-ray Prohibited Item Detection
Aishan Liu, Jun Guo, Jiakai Wang, Siyuan Liang, Renshuai Tao, Wenbo Zhou, Cong Liu, Xianglong Liu, Dacheng Tao
Abstract
Adversarial attacks are valuable for evaluating the robustness of deep learning models. Existing attacks are primarily conducted on the visible light spectrum (e.g., pixel-wise texture perturbation). However, attacks targeting texture-free X-ray images remain underexplored, despite the widespread application of X-ray imaging in safety-critical scenarios such as the X-ray detection of prohibited items. In this paper, we take the first step toward the study of adversarial attacks targeted at X-ray prohibited item detection, and reveal the serious threats posed by such attacks in this safety-critical scenario. Specifically, we posit that successful physical adversarial attacks in this scenario should be specially designed to circumvent the challenges posed by color/texture fading and complex overlapping. To this end, we propose X-adv to generate physically printable metals that act as an adversarial agent capable of deceiving X-ray detectors when placed in luggage. To resolve the issues associated with color/texture fading, we develop a differentiable converter that facilitates the generation of 3D-printable objects with adversarial shapes, using the gradients of a surrogate model rather than directly generating adversarial textures. To place the printed 3D adversarial objects in luggage with complex overlapped instances, we design a policy-based reinforcement learning strategy to find locations eliciting strong attack performance in worst-case scenarios whereby the prohibited items are heavily occluded by other items. To verify the effectiveness of the proposed X-Adv, we conduct extensive experiments in both the digital and the physical world (employing a commercial X-ray security inspection system for the latter case). Furthermore, we present the physical-world X-ray adversarial attack dataset XAD.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers16
- BiBench: Benchmarking and Analyzing Network BinarizationHaotong Qin, Mingyuan Zhang, Yifu Ding, Aoyu Li et al.ICML 2023 · 53 citations
- Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery DetectionJiawei Liang, Siyuan Liang, Aishan Liu, Xiaojun Jia et al.ICLR 2024 · 40 citations
- Byzantine Robust Cooperative Multi-Agent Reinforcement Learning as a Bayesian GameSimin Li, Jun Guo, Jingqiao Xiu, Ruixiao Xu et al.ICLR 2024 · 30 citations
- FAIRER: Fairness as Decision Rationale AlignmentTianlin Li, Qing Guo, Aishan Liu, Mengnan Du et al.ICML 2023 · 20 citations
- Detoxifying Large Language Models via Autoregressive Reward Guided Representation EditingYisong Xiao, Aishan Liu, Siyuan Liang, Zonghao Ying et al.NeurIPS 2025 · 12 citations
Builds on16
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Occluded Prohibited Items Detection: An X-ray Security Inspection Benchmark and De-occlusion Attention ModuleYanlu Wei, Renshuai Tao, Zhangjie Wu, Yuqing Ma et al.ACM MM 2020 · 264 citations
- Towards Adversarially Robust Object DetectionHaichao Zhang, Jianyu WangICCV 2019 · 152 citations
- Informative Dropout for Robust Representation Learning: A Shape-bias PerspectiveBaifeng Shi, Dinghuai Zhang, Qi Dai, Zhanxing Zhu et al.ICML 2020 · 122 citations
Related papers
- Beyond Digital Domain: Fooling Deep Learning Based Recognition System in Physical WorldKaichen Yang, Tzungyu Tsai, Honggang Yu, Tsung-Yi Ho et al.AAAI 2020 · 29 citations
- OBJVanish: Prompt-Driven Generation of Physically Realizable 3D LiDAR-Invisible ObjectsBing Li, Wuqi Wang, Yanan Zhang, Jingzheng Li et al.ICML 2026
- Meta-Attack: Class-agnostic and Model-agnostic Physical Adversarial AttackWeiwei Feng, Baoyuan Wu, Tianzhu Zhang, Yong Zhang et al.ICCV 2021 · 35 citations
- DTA: Physical Camouflage Attacks using Differentiable Transformation NetworkNaufal Suryanto, Yongsu Kim, Hyoeun Kang, Harashta Tatimma Larasati et al.CVPR 2022 · 76 citations
- Towards Real-world X-ray Security Inspection: A High-Quality Benchmark And Lateral Inhibition Module For Prohibited Items DetectionRenshuai Tao, Yanlu Wei, Xiangjian Jiang, Hainan Li et al.ICCV 2021 · 113 citations
