AdvReal: Adversarial Patch Generation Framework with Application to Adversarial Safety Evaluation of Object Detection Systems

📅 2025-05-22
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Object detection models in autonomous driving are vulnerable to physical-world adversarial attacks, posing critical safety risks. Method: This paper proposes the first 2D/3D joint adversarial training framework for generating physically deployable robust adversarial patches. It introduces a novel non-rigid surface modeling technique coupled with a geometry-material co-optimized 3D photorealistic matching mechanism to mitigate intra-class variation and environmental variability—key bottlenecks in generalization. The method integrates physical realizability constraints, multi-model collaborative training (YOLOv5/v8, Faster R-CNN, DETR), and multi-view, multi-illumination, and multi-distance robust optimization. Contribution/Results: Evaluated on eight mainstream detectors, our approach achieves state-of-the-art performance in both digital and physical experiments: a 72.1% average physical-world attack success rate—19.6% higher than prior methods—while significantly improving cross-model transferability and cross-condition robustness.

Technology Category

Application Category

📝 Abstract
Autonomous vehicles are typical complex intelligent systems with artificial intelligence at their core. However, perception methods based on deep learning are extremely vulnerable to adversarial samples, resulting in safety accidents. How to generate effective adversarial examples in the physical world and evaluate object detection systems is a huge challenge. In this study, we propose a unified joint adversarial training framework for both 2D and 3D samples to address the challenges of intra-class diversity and environmental variations in real-world scenarios. Building upon this framework, we introduce an adversarial sample reality enhancement approach that incorporates non-rigid surface modeling and a realistic 3D matching mechanism. We compare with 5 advanced adversarial patches and evaluate their attack performance on 8 object detecotrs, including single-stage, two-stage, and transformer-based models. Extensive experiment results in digital and physical environments demonstrate that the adversarial textures generated by our method can effectively mislead the target detection model. Moreover, proposed method demonstrates excellent robustness and transferability under multi-angle attacks, varying lighting conditions, and different distance in the physical world. The demo video and code can be obtained at https://github.com/Huangyh98/AdvReal.git.
Problem

Research questions and friction points this paper is trying to address.

Generate effective adversarial examples for object detection systems
Evaluate adversarial safety in real-world scenarios with environmental variations
Enhance adversarial sample reality using non-rigid modeling and 3D matching
Innovation

Methods, ideas, or system contributions that make the work stand out.

Unified joint adversarial training for 2D/3D samples
Non-rigid surface modeling enhances adversarial reality
Robust multi-angle attacks under varying conditions
🔎 Similar Papers
No similar papers found.
Y
Yuanhao Huang
School of Transportation Science and Engineering, Beihang University, Kejiyuan Rd, Haidian District, 100191, Beijing, P .R China; State Key Lab of Intelligent Transportation System, Kejiyuan Rd, Haidian District, 100191, Beijing, P .R China
Yilong Ren
Yilong Ren
Associate Professor, School of Transportation Science and Engineering, Beihang University
Cooperative vehicle infrastructure systemTraffic big dataTraffic signal control
J
Jinlei Wang
State Key Lab of Intelligent Transportation System, Kejiyuan Rd, Haidian District, 100191, Beijing, P .R China; Aviation Academy, Inner Mongolia University of Technology, Aimin Street, Hohhot, 010051, Inner Mongolia, P .R China
L
Lujia Huo
State Key Lab of Intelligent Transportation System, Kejiyuan Rd, Haidian District, 100191, Beijing, P .R China; Aviation Academy, Inner Mongolia University of Technology, Aimin Street, Hohhot, 010051, Inner Mongolia, P .R China
Xuesong Bai
Xuesong Bai
Beihang University
AI Safety and SecurityAutonomous VehicleTesting and Evaluation
Jinchuan Zhang
Jinchuan Zhang
University of Electronic Science and Technology of China
Temporal Knowledge GraphGraph Representation Learning
H
Haiyan Yu
School of Transportation Science and Engineering, Beihang University, Kejiyuan Rd, Haidian District, 100191, Beijing, P .R China; Zhongguancun Laboratory, Haidian District, 100191, Beijing, P .R China