Invisible Perturbations: Physical Adversarial Examples Exploiting the Rolling Shutter Effect
Athena Sayles, Ashish Hooda, Mohit Gupta, Rahul Chatterjee, Earlence Fernandes
摘要
Physical adversarial examples for camera-based computer vision have so far been achieved through visible artifacts -a sticker on a Stop sign, colorful borders around eyeglasses or a 3D printed object with a colorful texture. An implicit assumption here is that the perturbations must be visible so that a camera can sense them. By contrast, we contribute a procedure to generate, for the first time, physical adversarial examples that are invisible to human eyes. Rather than modifying the victim object with visible artifacts, we modify light that illuminates the object. We demonstrate how an attacker can craft a modulated light signal that adversarially illuminates a scene and causes targeted misclassifications on a state-of-the-art ImageNet deep learning model. Concretely, we exploit the radiometric rolling shutter effect in commodity cameras to create precise striping patterns that appear on images. To human eyes, it appears like the object is illuminated, but the camera creates an image with stripes that will cause ML models to output the attacker-desired classification. We conduct a range of simulation and physical experiments with LEDs, demonstrating targeted attack rates up to 84%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural PhenomenonYiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang 等CVPR 2022 · 被引用 148 次
- RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical WorldDonghua Wang, Wen Yao, Tingsong Jiang, Chao Li 等ICCV 2023 · 被引用 47 次
- That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality ApplicationsCarter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree 等USENIX Security 2024 · 被引用 21 次
- The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign RecognitionShuai Yuan, Xingshuo Han, Hongwei Li, Guowen Xu 等NeurIPS 2025 · 被引用 9 次
- pi-Jack: Physical-World Adversarial Attack on Monocular Depth Estimation with Perspective HijackingTianyue Zheng, Jingzhi Hu, Rui Tan, Yinqian Zhang 等USENIX Security 2024 · 被引用 8 次
它引用的顶会 Paper3
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- From Two Rolling Shutters to One Global ShutterCenek Albl, Zuzana Kukelova, Viktor Larsson, Michal Polic 等CVPR 2020
相关 Paper
- CamPI: Physical Adversarial Examples through Camera Power Signal InjectionYanze Ren, Mingyuan Lv, Qinhong Jiang, Yan Jiang 等CVPR 2026
- Adversarial Camouflage: Hiding Physical-World Attacks With Natural StylesRanjie Duan, Xingjun Ma, Yisen Wang, James Bailey 等CVPR 2020
- Rolling Colors: Adversarial Laser Exploits against Traffic Light RecognitionChen Yan, Zhijian Xu, Zhanyuan Yin, Xiaoyu Ji 等USENIX Security 2022
- Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a BlinkRanjie Duan, Xiaofeng Mao, A. K. Qin, Yuefeng Chen 等CVPR 2021
- SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image ClassifiersBingyao Huang, Haibin LingIEEE VR 2022 · 被引用 16 次
