Multi-view Correlation based Black-box Adversarial Attack for 3D Object Detection
Bingyu Liu, Yuhong Guo, Jianan Jiang, Jian Tang, Weihong Deng
Abstract
Deep neural networks have made tremendous progress in 3D object detection, which is an important task especially in autonomous driving scenarios. Benefited from the breakthroughs in deep learning and sensor technologies, 3D object detection methods based on different sensors, such as camera and LiDAR, have developed rapidly. Meanwhile, more and more researches notice that the abundant information contained in the multi-view data can be used to obtain more accurate understanding of the 3D surrounding environment. Therefore, many sensor-fusion 3D object detection methods have been proposed. As safety is critical in autonomous driving and the deep neural networks are known to be vulnerable to adversarial examples with visually imperceptible perturbations, it is significant to investigate adversarial attacks for 3D object detection. Recent works have shown that both image-based and LiDAR-based networks can be attacked by the adversarial examples while the attacks to the sensor-fusion models, which tend to be more robust, haven't been studied. To this end, we propose a simple multi-view correlation based adversarial attack method for the camera-LiDAR fusion 3D object detection models and focus on the black-box attack setting which is more practical in real-world systems. Specifically, we first design a generative network to generate image adversarial examples based on an auxiliary image semantic segmentation network. Then, we develop a cross-view perturbation projection method by exploiting the camera-LiDAR correlations to map each image adversarial example to the space of the point cloud data to form the point cloud adversarial examples in the LiDAR view. Extensive experiments on the KITTI dataset demonstrate the effectiveness of the proposed method.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 493c72d3-2aeb-4e1d-9796-6780c4eec7ccCited by top-tier papers3
- Benchmarking Robustness of AI-Enabled Multi-sensor Fusion Systems: Challenges and OpportunitiesXinyu Gao, Zhijie Wang, Yang Feng, Lei Ma et al.FSE 2023 · 33 citations
- On the Robustness Evaluation of 3D Obstacle Detection Against Specifications in Autonomous DrivingTri Minh-Triet Pham, Bo Yang, Jinqiu YangASE 2025 · 1 citation
- ADPerf: Investigating and Testing Performance in Autonomous Driving SystemsTri Minh-Triet Pham, Diego Elias Costa, Weiyi Shang, Jinqiu YangASE 2025
Related papers
- Fusion Is Not Enough: Single Modal Attacks on Fusion Models for 3D Object DetectionZhiyuan Cheng, Hongjun Choi, Shiwei Feng, James Chenhao Liang et al.ICLR 2024 · 32 citations
- Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous DrivingYinpeng Dong, Caixin Kang, Jinlai Zhang, Zijian Zhu et al.CVPR 2023
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Physically Realizable Adversarial Examples for LiDAR Object DetectionJames Tu, Mengye Ren, Sivabalan Manivasagam, Ming Liang et al.CVPR 2020
- Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor AttackZizhi Jin, Xuancun Lu, Bo Yang, Yushi Cheng et al.WWW 2024 · 7 citations
