错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ADV-POST: Physically Realistic Adversarial Poster for Attacking Semantic Segmentation Models in Autonomous Driving

  • Huan Deng,
  • Minhuan Huang,
  • Tong Wang,
  • Hu Li,
  • Jianwen Tian,
  • Qian Yan,
  • Xiaohui Kuang

摘要

In recent years, deep neural networks have gained significant popularity in real-time semantic segmentation tasks, particularly in the domain of autonomous driving. However, these networks are susceptible to adversarial examples, which pose a serious threat to the safety of autonomous driving systems. Existing adversarial attacks on semantic segmentation models primarily focus on the digital space and lack validation in real-world scenarios, or they generate meaningless and visually unnatural examples. To address this gap, we propose a method called Adversarial Poster (ADV-POST), which generates physically plausible adversarial patches to preserve semantic information and visual naturalness by adding small-scale noise to posters. Specifically, we introduce a dynamic regularization method that balances the effectiveness and intensity of the generated patches. Moreover, we conduct comprehensive evaluations of the attack effectiveness in both digital and physical environments. Our experimental results demonstrate the successful misguidedness of real-time semantic segmentation models in the context of autonomous driving, resulting in inaccurate semantic segmentation results.