Investigating Physical Latency Attacks Against Camera-Based Perception
Raymond Muller, Ruoyu Song, Chenyi Wang, Yuxia Zhan, Jean-Philippe Monteuuis, Yanmao Man, Ming Li, Ryan M. Gerdes, Jonathan Petit, Z. Berkay Celik
摘要
Camera-based perception is a central component to the visual perception of autonomous systems. Recent works have investigated latency attacks against perception pipelines, which can lead to a Denial-of-Service against the autonomous system. Unfortunately, these attacks lack real-world applicability, either relying on digital perturbations or requiring large, unscalable, and highly visible patches that cover up the victim's view. In this paper, we propose Detstorm, a novel physically realizable latency attack against camera-based perception. Detstorm uses projector perturbations to cause delays in perception by creating a large number of adversarial objects. These objects are optimized on four objectives to evade filtering by multiple Non-Maximum Suppression (NMS) approaches. To maximize the number of created objects in a dynamic physical environment, Detstorm takes a unique greedy approach, segmenting the environment into “zones” containing distinct object classes and maximizing the number of created objects per zone. Detstorm adapts to changes in the environment in real time, recombining perturbation patterns via our zone stitching process into a contiguous, physically projectable image. Evaluations in both simulated and real-world experiments show that Detstorm causes a 506% increase in detected objects on average, delaying perception results by up to 8.1 seconds, and capable of causing physical consequences on real-world autonomous driving systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Latency NMS Attacks: Is It Real Life or Is It Just Fantasy?Jean-Philippe Monteuuis, Cong Chen, Jonathan PetitNeurIPS 2025 · 被引用 1 次
- From Threat to Trust: Exploiting Attention Mechanisms for Attacks and Defenses in Cooperative PerceptionChenyi Wang, Raymond Muller, Ruoyu Song, Jean-Philippe Monteuuis 等USENIX Security 2025
它引用的顶会 Paper16
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- YOLACT: Real-Time Instance SegmentationDaniel Bolya, Chong Zhou, Fanyi Xiao, Yong Jae LeeICCV 2019 · 被引用 2,075 次
- VAD: Vectorized Scene Representation for Efficient Autonomous DrivingBo Jiang, Shaoyu Chen, Qing Xu, Bencheng Liao 等ICCV 2023 · 被引用 602 次
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang 等S&P 2021 · 被引用 309 次
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 被引用 172 次
相关 Paper
- SlowPerception: Physical-World Latency Attack against Camera-based Perception in Autonomous DrivingChen Ma, Ningfei Wang, Zhengyu Zhao, Qian Wang 等CCS 2026 · 被引用 5 次
- SlowTrack: Increasing the Latency of Camera-Based Perception in Autonomous Driving Using Adversarial ExamplesChen Ma, Ningfei Wang, Qi Alfred Chen, Chao ShenAAAI 2024 · 被引用 44 次
- SlowLiDAR: Increasing the Latency of LiDAR-Based Detection Using Adversarial ExamplesHan Liu, Yuhao Wu, Zhiyuan Yu, Yevgeniy Vorobeychik 等CVPR 2023
- Overload: Latency Attacks on Object Detection for Edge DevicesErh-Chung Chen, Pin-Yu Chen, I-Hsin Chung, Che-Rung LeeCVPR 2024
- Towards Real-Time Defense against Object-Based LiDAR Attacks in Autonomous DrivingYan Zhang, Zihao Liu, Yi Zhu, Chenglin MiaoCCS 2025
