Adversarial Imaging Pipelines
Buu Phan, Fahim Mannan, Felix Heide
Abstract
Adversarial attacks play a critical role in understanding deep neural network predictions and improving their robustness. Existing attack methods aim to deceive convolutional neural network (CNN)-based classifiers by manipulating RGB images that are fed directly to the classifiers. However, these approaches typically neglect the influence of the camera optics and image processing pipeline (ISP) that produce the network inputs. ISPs transform RAW measurements to RGB images and traditionally are assumed to preserve adversarial patterns. In fact, these low-level pipelines can destroy, introduce or amplify adversarial patterns that can deceive a downstream detector. As a result, optimized patterns can become adversarial for the classifier after being transformed by a certain camera ISP or optical lens system but not for others. In this work, we examine and develop such an attack that deceives a specific camera ISP while leaving others intact, using the same downstream classifier. We frame this camera-specific attack as a multi-task optimization problem, relying on a differentiable approximation for the ISP itself. We validate the proposed method using recent state-of-the-art automotive hardware ISPs, achieving 92% fooling rate when attacking a specific ISP. We demonstrate physical optics attacks with 90% fooling rate for a specific camera lens.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 48328d22-a896-4d89-8632-86206b58ebceCited by top-tier papers3
- What Sketch Explainability Really Means for Downstream Tasks?Hmrishav Bandyopadhyay, Pinaki Nath Chowdhury, Ayan Kumar Bhunia, Aneeshan Sain et al.CVPR 2024
- Targeted Physical Evasion Attacks in the Near-Infrared DomainPascal Zimmer, Simon Lachnit, Alexander Jan Zielinski, Ghassan KarameNDSS 2026
- Learning to Exploit the Sequence-Specific Prior Knowledge for Image Processing Pipelines OptimizationHaina Qin, Longfei Han, Weihua Xiong, Juan Wang et al.CVPR 2023
Builds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Just Pick a Sign: Optimizing Deep Multitask Models with Gradient Sign DropoutZhao Chen, Jiquan Ngiam, Yanping Huang, Thang Luong et al.NeurIPS 2020 · 313 citations
- Black-Box Adversarial Attack with Transferable Model-based EmbeddingZhichao Huang, Tong ZhangICLR 2020 · 131 citations
- A Frank-Wolfe Framework for Efficient and Effective Adversarial AttacksJinghui Chen, Dongruo Zhou, Jinfeng Yi, Quanquan GuAAAI 2020 · 78 citations
Related papers
- Revisiting Adversarial Patches for Designing Camera-Agnostic Attacks against Person DetectionHui Wei, Zhixiang Wang, Kewei Zhang, Jiaqi Hou et al.NeurIPS 2024 · 22 citations
- The Differentiable Lens: Compound Lens Search over Glass Surfaces and Materials for Object DetectionGeoffroi Côté, Fahim Mannan, Simon Thibault, Jean-François Lalonde et al.CVPR 2023
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- The Translucent Patch: A Physical and Universal Attack on Object DetectorsAlon Zolfi, Moshe Kravchik, Yuval Elovici, Asaf ShabtaiCVPR 2021
- SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image ClassifiersBingyao Huang, Haibin LingIEEE VR 2022 · 16 citations
