SADA: Semantic Adversarial Diagnostic Attacks for Autonomous Applications
Abdullah Hamdi, Matthias Mueller, Bernard Ghanem
Abstract
One major factor impeding more widespread adoption of deep neural networks (DNNs) is their lack of robustness, which is essential for safety-critical applications such as autonomous driving. This has motivated much recent work on adversarial attacks for DNNs, which mostly focus on pixel-level perturbations void of semantic meaning. In contrast, we present a general framework for adversarial attacks on trained agents, which covers semantic perturbations to the environment of the agent performing the task as well as pixel-level attacks. To do this, we re-frame the adversarial attack problem as learning a distribution of parameters that always fools the agent. In the semantic case, our proposed adversary (denoted as BBGAN) is trained to sample parameters that describe the environment with which the black-box agent interacts, such that the agent performs its dedicated task poorly in this environment. We apply BBGAN on three different tasks, primarily targeting aspects of autonomous navigation: object detection, self-driving, and autonomous UAV racing. On these tasks, BBGAN can generate failure cases that consistently fool a trained agent.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- MVTN: Multi-View Transformation Network for 3D Shape RecognitionAbdullah Hamdi, Silvio Giancola, Bernard GhanemICCV 2021 · 280 citations
- 3DB: A Framework for Debugging Computer Vision ModelsGuillaume Leclerc, Hadi Salman, Andrew Ilyas, Sai Vemprala et al.NeurIPS 2022 · 45 citations
- DeformRS: Certifying Input Deformations with Randomized SmoothingMotasem Alfarra, Adel Bibi, Naeemullah Khan, Philip H. S. Torr et al.AAAI 2022 · 23 citations
Builds on1
Related papers
- Natural Black-Box Adversarial Examples against Deep Reinforcement LearningMengran Yu, Shiliang SunAAAI 2022 · 15 citations
- DeepRover: A Query-Efficient Blackbox Attack for Deep Neural NetworksFuyuan Zhang, Xinwen Hu, Lei Ma, Jianjun ZhaoFSE 2023 · 7 citations
- BTUAP: Boosting the Transferability of Universal Adversarial Perturbations in the Black-box Setting under various data dependenciesJie Wan, Jianhao Fu, Ziqi Yang, Kui RenACM MM 2025
- PhysGAN: Generating Physical-World-Resilient Adversarial Examples for Autonomous DrivingZelun Kong, Junfeng Guo, Ang Li, Cong LiuCVPR 2020
- What You See is Not What the Network Infers: Detecting Adversarial Examples Based on Semantic ContradictionYijun Yang, Ruiyuan Gao, Yu Li, Qiuxia Lai et al.NDSS 2022
