FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking Systems
Shaoyuan Xie, Mohamad Habib Fakih, Junchi Lu, Fayzah Alshammari, Ningfei Wang, Takami Sato, Halima Bouzidi, Mohammad Abdullah Al Faruque, Qi Alfred Chen
Abstract
Autonomous Target Tracking (ATT) systems, especially ATT drones, are widely used in applications such as surveillance, border control, and law enforcement, while also being misused in stalking and destructive actions. Thus, the security of ATT is highly critical for real-world applications. Under the scope, we present a new type of attack: distance-pulling attacks (DPA) and a systematic study of it, which exploits vulnerabilities in ATT systems to dangerously reduce tracking distances, leading to drone capturing, increased susceptibility to sensor attacks, or even physical collisions. To achieve these goals, we present Fly-Trap, a novel physical-world attack framework that employs an adversarial umbrella as a deployable and domain-specific attack vector. FlyTrap is specifically designed to meet key desired objectives in attacking ATT drones: physical deployability, closed-loop effectiveness, and spatial-temporal consistency. Through novel progressive distance-pulling strategy and controllable spatialtemporal consistency designs, FlyTrap manipulates ATT drones in real-world setups to achieve significant system-level impacts. Our evaluations include new datasets, metrics, and closed-loop experiments on real-world white-box and even commercial ATT drones, including DJI and HoverAir. Results demonstrate Fly-Trap's ability to reduce tracking distances within the range to be captured, sensor attacked, or even directly crashed, highlighting urgent security risks and practical implications for the safe deployment of ATT systems. Video demonstrations and code can be found at https://sites.google.com/view/av-ioat-sec/flytrap .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a38948c4-46ee-4359-a6ab-aa5bdeab3361Cited by top-tier papers1
Ask how each one uses itBuilds on34
- MixFormer: End-to-End Tracking with Iterative Mixed AttentionYutao Cui, Cheng Jiang, Limin Wang, Gangshan WuCVPR 2022 · 746 citations
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Seeing isn't Believing: Towards More Robust Adversarial Attack Against Real World Object DetectorsYue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen et al.CCS 2019 · 239 citations
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 172 citations
Related papers
- Laser Shield: a Physical Defense with Polarizer against Laser Attacks on Autonomous Driving SystemsQingjie Zhang, Lijun Chi, Di Wang, Mounira Msahli et al.DAC 2024 · 3 citations
- Physical Hijacking Attacks against Object TrackersRaymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li et al.CCS 2022 · 12 citations
- On the Realism of LiDAR Spoofing Attacks against Autonomous Driving Vehicle at High Speed and Long DistanceTakami Sato, Ryo Suzuki, Yuki Hayakawa, Kazuma Ikeda et al.NDSS 2025
- L-HAWK: A Controllable Physical Adversarial Patch Against a Long-Distance TargetTaifeng Liu, Yang Liu, Zhuo Ma, Tong Yang et al.NDSS 2025
- TRAP: Hijacking VLA CoT-Reasoning via Adversarial PatchesZhengxian Huang, Wenjun Zhu, Haoxuan Qiu, Xiaoyu Ji et al.ICML 2026 · 5 citations
