Towards Physically Realizable Adversarial Attacks in Embodied Vision Navigation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Meng, Tu, Jiawei, Qi, Chao, Dang, Yonghao, Zhou, Feng, Wei, Wei, Yin, Jianqin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909737244688384
author Chen, Meng
Tu, Jiawei
Qi, Chao
Dang, Yonghao
Zhou, Feng
Wei, Wei
Yin, Jianqin
author_facet Chen, Meng
Tu, Jiawei
Qi, Chao
Dang, Yonghao
Zhou, Feng
Wei, Wei
Yin, Jianqin
contents The significant advancements in embodied vision navigation have raised concerns about its susceptibility to adversarial attacks exploiting deep neural networks. Investigating the adversarial robustness of embodied vision navigation is crucial, especially given the threat of 3D physical attacks that could pose risks to human safety. However, existing attack methods for embodied vision navigation often lack physical feasibility due to challenges in transferring digital perturbations into the physical world. Moreover, current physical attacks for object detection struggle to achieve both multi-view effectiveness and visual naturalness in navigation scenarios. To address this, we propose a practical attack method for embodied navigation by attaching adversarial patches to objects, where both opacity and textures are learnable. Specifically, to ensure effectiveness across varying viewpoints, we employ a multi-view optimization strategy based on object-aware sampling, which optimizes the patch's texture based on feedback from the vision-based perception model used in navigation. To make the patch inconspicuous to human observers, we introduce a two-stage opacity optimization mechanism, in which opacity is fine-tuned after texture optimization. Experimental results demonstrate that our adversarial patches decrease the navigation success rate by an average of 22.39%, outperforming previous methods in practicality, effectiveness, and naturalness. Code is available at: https://github.com/chen37058/Physical-Attacks-in-Embodied-Nav
format Preprint
id arxiv_https___arxiv_org_abs_2409_10071
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Towards Physically Realizable Adversarial Attacks in Embodied Vision Navigation
Chen, Meng
Tu, Jiawei
Qi, Chao
Dang, Yonghao
Zhou, Feng
Wei, Wei
Yin, Jianqin
Computer Vision and Pattern Recognition
Robotics
The significant advancements in embodied vision navigation have raised concerns about its susceptibility to adversarial attacks exploiting deep neural networks. Investigating the adversarial robustness of embodied vision navigation is crucial, especially given the threat of 3D physical attacks that could pose risks to human safety. However, existing attack methods for embodied vision navigation often lack physical feasibility due to challenges in transferring digital perturbations into the physical world. Moreover, current physical attacks for object detection struggle to achieve both multi-view effectiveness and visual naturalness in navigation scenarios. To address this, we propose a practical attack method for embodied navigation by attaching adversarial patches to objects, where both opacity and textures are learnable. Specifically, to ensure effectiveness across varying viewpoints, we employ a multi-view optimization strategy based on object-aware sampling, which optimizes the patch's texture based on feedback from the vision-based perception model used in navigation. To make the patch inconspicuous to human observers, we introduce a two-stage opacity optimization mechanism, in which opacity is fine-tuned after texture optimization. Experimental results demonstrate that our adversarial patches decrease the navigation success rate by an average of 22.39%, outperforming previous methods in practicality, effectiveness, and naturalness. Code is available at: https://github.com/chen37058/Physical-Attacks-in-Embodied-Nav
title Towards Physically Realizable Adversarial Attacks in Embodied Vision Navigation
topic Computer Vision and Pattern Recognition
Robotics
url https://arxiv.org/abs/2409.10071