SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image Classifiers
Bingyao Huang, Haibin Ling
摘要
Light-based adversarial attacks use spatial augmented reality (SAR) techniques to fool image classifiers by altering the physical light condition with a controllable light source, e.g., a projector. Compared with physical attacks that place hand-crafted adversarial objects, projector-based ones obviate modifying the physical entities, and can be performed transiently and dynamically by altering the projection pattern. However, subtle light perturbations are insufficient to fool image classifiers, due to the complex environment and project-and-capture process. Thus, existing approaches focus on projecting clearly perceptible adversarial patterns, while the more interesting yet challenging goal, stealthy projector-based attack, remains open. In this paper, for the first time, we formulate this problem as an end-to-end differentiable process and propose a Stealthy Projector-based Adversarial Attack (SPAA) solution. In SPAA, we approximate the real Project-and-Capture process using a deep neural network named PCNet, then we include PCNet in the optimization of projector-based attacks such that the generated adversarial projection is physically plausible. Finally, to generate both robust and stealthy adversarial projections, we propose an algorithm that uses minimum perturbation and adversarial confidence thresholds to alternate between the adversarial loss and stealthiness loss optimization. Our experimental evaluations show that SPAA clearly outperforms other methods by achieving higher attack success rates and meanwhile being stealthier, for both targeted and untargeted attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang 等S&P 2021 · 被引用 309 次
- RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical WorldDonghua Wang, Wen Yao, Tingsong Jiang, Chao Li 等ICCV 2023 · 被引用 47 次
- When Lighting Deceives: Exposing Vision-Language Models' Illumination Vulnerability Through Illumination Transformation AttackHanqing Liu, Shouwei Ruan, Yao Huang, Shiji Zhao 等ICCV 2025 · 被引用 13 次
- LAPIG: Language Guided Projector Image Generation with Surface Adaptation and StylizationYuchen Deng, Haibin Ling, Bingyao HuangIEEE VR 2025 · 被引用 6 次
- Embodied Laser Attack: Leveraging Scene Priors to Achieve Agent-based Robust Non-contact AttacksYitong Sun, Yao Huang, Xingxing WeiACM MM 2024 · 被引用 2 次
它引用的顶会 Paper8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- A privacy-preserving approach to streaming eye-tracking dataBrendan David-John, Diane Hosfelt, Kevin R. B. Butler, Eakta JainIEEE VR 2021 · 被引用 89 次
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 被引用 70 次
- On the Design of Black-Box Adversarial Examples by Leveraging Gradient-Free Optimization and Operator Splitting MethodPu Zhao, Sijia Liu, Pin-Yu Chen, Nghia Hoang 等ICCV 2019 · 被引用 61 次
相关 Paper
- Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a BlinkRanjie Duan, Xiaofeng Mao, A. K. Qin, Yuefeng Chen 等CVPR 2021
- DeProCams: Simultaneous Relighting, Compensation and Shape Reconstruction for Projector-Camera SystemsBingyao Huang, Haibin LingIEEE VR 2021 · 被引用 30 次
- ProjAttacker: A Configurable Physical Adversarial Attack for Face Recognition via ProjectorYuanwei Liu, Hui Wei, Chengyu Jia, Ruqi Xiao 等CVPR 2025
- DPCS: Path Tracing-Based Differentiable Projector-Camera SystemsJijiang Li, Qingyue Deng, Haibin Ling, Bingyao HuangIEEE VR 2025 · 被引用 4 次
- SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial PerturbationsGiulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier 等USENIX Security 2021 · 被引用 123 次
