X-Adv: Physical Adversarial Object Attacks against X-ray Prohibited Item Detection
Aishan Liu, Jun Guo, Jiakai Wang, Siyuan Liang, Renshuai Tao, Wenbo Zhou, Cong Liu, Xianglong Liu, Dacheng Tao
摘要
Adversarial attacks are valuable for evaluating the robustness of deep learning models. Existing attacks are primarily conducted on the visible light spectrum (e.g., pixel-wise texture perturbation). However, attacks targeting texture-free X-ray images remain underexplored, despite the widespread application of X-ray imaging in safety-critical scenarios such as the X-ray detection of prohibited items. In this paper, we take the first step toward the study of adversarial attacks targeted at X-ray prohibited item detection, and reveal the serious threats posed by such attacks in this safety-critical scenario. Specifically, we posit that successful physical adversarial attacks in this scenario should be specially designed to circumvent the challenges posed by color/texture fading and complex overlapping. To this end, we propose X-adv to generate physically printable metals that act as an adversarial agent capable of deceiving X-ray detectors when placed in luggage. To resolve the issues associated with color/texture fading, we develop a differentiable converter that facilitates the generation of 3D-printable objects with adversarial shapes, using the gradients of a surrogate model rather than directly generating adversarial textures. To place the printed 3D adversarial objects in luggage with complex overlapped instances, we design a policy-based reinforcement learning strategy to find locations eliciting strong attack performance in worst-case scenarios whereby the prohibited items are heavily occluded by other items. To verify the effectiveness of the proposed X-Adv, we conduct extensive experiments in both the digital and the physical world (employing a commercial X-ray security inspection system for the latter case). Furthermore, we present the physical-world X-ray adversarial attack dataset XAD.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- BiBench: Benchmarking and Analyzing Network BinarizationHaotong Qin, Mingyuan Zhang, Yifu Ding, Aoyu Li 等ICML 2023 · 被引用 53 次
- Poisoned Forgery Face: Towards Backdoor Attacks on Face Forgery DetectionJiawei Liang, Siyuan Liang, Aishan Liu, Xiaojun Jia 等ICLR 2024 · 被引用 40 次
- Byzantine Robust Cooperative Multi-Agent Reinforcement Learning as a Bayesian GameSimin Li, Jun Guo, Jingqiao Xiu, Ruixiao Xu 等ICLR 2024 · 被引用 30 次
- FAIRER: Fairness as Decision Rationale AlignmentTianlin Li, Qing Guo, Aishan Liu, Mengnan Du 等ICML 2023 · 被引用 20 次
- Detoxifying Large Language Models via Autoregressive Reward Guided Representation EditingYisong Xiao, Aishan Liu, Siyuan Liang, Zonghao Ying 等NeurIPS 2025 · 被引用 12 次
它引用的顶会 Paper16
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou 等CCS 2019 · 被引用 626 次
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang 等S&P 2021 · 被引用 309 次
- Occluded Prohibited Items Detection: An X-ray Security Inspection Benchmark and De-occlusion Attention ModuleYanlu Wei, Renshuai Tao, Zhangjie Wu, Yuqing Ma 等ACM MM 2020 · 被引用 264 次
- Towards Adversarially Robust Object DetectionHaichao Zhang, Jianyu WangICCV 2019 · 被引用 152 次
- Informative Dropout for Robust Representation Learning: A Shape-bias PerspectiveBaifeng Shi, Dinghuai Zhang, Qi Dai, Zhanxing Zhu 等ICML 2020 · 被引用 122 次
相关 Paper
- Beyond Digital Domain: Fooling Deep Learning Based Recognition System in Physical WorldKaichen Yang, Tzungyu Tsai, Honggang Yu, Tsung-Yi Ho 等AAAI 2020 · 被引用 29 次
- OBJVanish: Prompt-Driven Generation of Physically Realizable 3D LiDAR-Invisible ObjectsBing Li, Wuqi Wang, Yanan Zhang, Jingzheng Li 等ICML 2026
- Meta-Attack: Class-agnostic and Model-agnostic Physical Adversarial AttackWeiwei Feng, Baoyuan Wu, Tianzhu Zhang, Yong Zhang 等ICCV 2021 · 被引用 35 次
- DTA: Physical Camouflage Attacks using Differentiable Transformation NetworkNaufal Suryanto, Yongsu Kim, Hyoeun Kang, Harashta Tatimma Larasati 等CVPR 2022 · 被引用 76 次
- Towards Real-world X-ray Security Inspection: A High-Quality Benchmark And Lateral Inhibition Module For Prohibited Items DetectionRenshuai Tao, Yanlu Wei, Xiangjian Jiang, Hainan Li 等ICCV 2021 · 被引用 113 次
