The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yuan, Shuai, Han, Xingshuo, Li, Hongwei, Xu, Guowen, Jiang, Wenbo, Ni, Tao, Zhao, Qingchuan, Fang, Yuguang
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915556253237248
author Yuan, Shuai
Han, Xingshuo
Li, Hongwei
Xu, Guowen
Jiang, Wenbo
Ni, Tao
Zhao, Qingchuan
Fang, Yuguang
author_facet Yuan, Shuai
Han, Xingshuo
Li, Hongwei
Xu, Guowen
Jiang, Wenbo
Ni, Tao
Zhao, Qingchuan
Fang, Yuguang
contents Recently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%.
format Preprint
id arxiv_https___arxiv_org_abs_2409_12394
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
Yuan, Shuai
Han, Xingshuo
Li, Hongwei
Xu, Guowen
Jiang, Wenbo
Ni, Tao
Zhao, Qingchuan
Fang, Yuguang
Computer Vision and Pattern Recognition
Artificial Intelligence
Recently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%.
title The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2409.12394