LiDAttack: Robust Black-box Attack on LiDAR-based Object Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Jinyin, Liao, Danxin, Xiang, Sheng, Zheng, Haibin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915003988180992
author Chen, Jinyin
Liao, Danxin
Xiang, Sheng
Zheng, Haibin
author_facet Chen, Jinyin
Liao, Danxin
Xiang, Sheng
Zheng, Haibin
contents Since DNN is vulnerable to carefully crafted adversarial examples, adversarial attack on LiDAR sensors have been extensively studied. We introduce a robust black-box attack dubbed LiDAttack. It utilizes a genetic algorithm with a simulated annealing strategy to strictly limit the location and number of perturbation points, achieving a stealthy and effective attack. And it simulates scanning deviations, allowing it to adapt to dynamic changes in real world scenario variations. Extensive experiments are conducted on 3 datasets (i.e., KITTI, nuScenes, and self-constructed data) with 3 dominant object detection models (i.e., PointRCNN, PointPillar, and PV-RCNN++). The results reveal the efficiency of the LiDAttack when targeting a wide range of object detection models, with an attack success rate (ASR) up to 90%.
format Preprint
id arxiv_https___arxiv_org_abs_2411_01889
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle LiDAttack: Robust Black-box Attack on LiDAR-based Object Detection
Chen, Jinyin
Liao, Danxin
Xiang, Sheng
Zheng, Haibin
Computer Vision and Pattern Recognition
Artificial Intelligence
Since DNN is vulnerable to carefully crafted adversarial examples, adversarial attack on LiDAR sensors have been extensively studied. We introduce a robust black-box attack dubbed LiDAttack. It utilizes a genetic algorithm with a simulated annealing strategy to strictly limit the location and number of perturbation points, achieving a stealthy and effective attack. And it simulates scanning deviations, allowing it to adapt to dynamic changes in real world scenario variations. Extensive experiments are conducted on 3 datasets (i.e., KITTI, nuScenes, and self-constructed data) with 3 dominant object detection models (i.e., PointRCNN, PointPillar, and PV-RCNN++). The results reveal the efficiency of the LiDAttack when targeting a wide range of object detection models, with an attack success rate (ASR) up to 90%.
title LiDAttack: Robust Black-box Attack on LiDAR-based Object Detection
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2411.01889