Physical Adversarial Attack meets Computer Vision: A Decade Survey

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Wei, Hui, Tang, Hao, Jia, Xuemei, Wang, Zhixiang, Yu, Hanxun, Li, Zhubo, Satoh, Shin'ichi, Van Gool, Luc, Wang, Zheng
Format: Preprint
Publié: 2022
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866910706160369664
author Wei, Hui
Tang, Hao
Jia, Xuemei
Wang, Zhixiang
Yu, Hanxun
Li, Zhubo
Satoh, Shin'ichi
Van Gool, Luc
Wang, Zheng
author_facet Wei, Hui
Tang, Hao
Jia, Xuemei
Wang, Zhixiang
Yu, Hanxun
Li, Zhubo
Satoh, Shin'ichi
Van Gool, Luc
Wang, Zheng
contents Despite the impressive achievements of Deep Neural Networks (DNNs) in computer vision, their vulnerability to adversarial attacks remains a critical concern. Extensive research has demonstrated that incorporating sophisticated perturbations into input images can lead to a catastrophic degradation in DNNs' performance. This perplexing phenomenon not only exists in the digital space but also in the physical world. Consequently, it becomes imperative to evaluate the security of DNNs-based systems to ensure their safe deployment in real-world scenarios, particularly in security-sensitive applications. To facilitate a profound understanding of this topic, this paper presents a comprehensive overview of physical adversarial attacks. Firstly, we distill four general steps for launching physical adversarial attacks. Building upon this foundation, we uncover the pervasive role of artifacts carrying adversarial perturbations in the physical world. These artifacts influence each step. To denote them, we introduce a new term: adversarial medium. Then, we take the first step to systematically evaluate the performance of physical adversarial attacks, taking the adversarial medium as a first attempt. Our proposed evaluation metric, hiPAA, comprises six perspectives: Effectiveness, Stealthiness, Robustness, Practicability, Aesthetics, and Economics. We also provide comparative results across task categories, together with insightful observations and suggestions for future research directions.
format Preprint
id arxiv_https___arxiv_org_abs_2209_15179
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Physical Adversarial Attack meets Computer Vision: A Decade Survey
Wei, Hui
Tang, Hao
Jia, Xuemei
Wang, Zhixiang
Yu, Hanxun
Li, Zhubo
Satoh, Shin'ichi
Van Gool, Luc
Wang, Zheng
Computer Vision and Pattern Recognition
Despite the impressive achievements of Deep Neural Networks (DNNs) in computer vision, their vulnerability to adversarial attacks remains a critical concern. Extensive research has demonstrated that incorporating sophisticated perturbations into input images can lead to a catastrophic degradation in DNNs' performance. This perplexing phenomenon not only exists in the digital space but also in the physical world. Consequently, it becomes imperative to evaluate the security of DNNs-based systems to ensure their safe deployment in real-world scenarios, particularly in security-sensitive applications. To facilitate a profound understanding of this topic, this paper presents a comprehensive overview of physical adversarial attacks. Firstly, we distill four general steps for launching physical adversarial attacks. Building upon this foundation, we uncover the pervasive role of artifacts carrying adversarial perturbations in the physical world. These artifacts influence each step. To denote them, we introduce a new term: adversarial medium. Then, we take the first step to systematically evaluate the performance of physical adversarial attacks, taking the adversarial medium as a first attempt. Our proposed evaluation metric, hiPAA, comprises six perspectives: Effectiveness, Stealthiness, Robustness, Practicability, Aesthetics, and Economics. We also provide comparative results across task categories, together with insightful observations and suggestions for future research directions.
title Physical Adversarial Attack meets Computer Vision: A Decade Survey
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2209.15179