We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CV

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo ScienceWISE logo

Computer Science > Computer Vision and Pattern Recognition

Title: Towards Universal Physical Attacks On Cascaded Camera-Lidar 3D Object Detection Models

Abstract: We propose a universal and physically realizable adversarial attack on a cascaded multi-modal deep learning network (DNN), in the context of self-driving cars. DNNs have achieved high performance in 3D object detection, but they are known to be vulnerable to adversarial attacks. These attacks have been heavily investigated in the RGB image domain and more recently in the point cloud domain, but rarely in both domains simultaneously - a gap to be filled in this paper. We use a single 3D mesh and differentiable rendering to explore how perturbing the mesh's geometry and texture can reduce the robustness of DNNs to adversarial attacks. We attack a prominent cascaded multi-modal DNN, the Frustum-Pointnet model. Using the popular KITTI benchmark, we showed that the proposed universal multi-modal attack was successful in reducing the model's ability to detect a car by nearly 73%. This work can aid in the understanding of what the cascaded RGB-point cloud DNN learns and its vulnerability to adversarial attacks.
Subjects: Computer Vision and Pattern Recognition (cs.CV); Image and Video Processing (eess.IV)
Journal reference: 2021 IEEE International Conference on Image Processing (ICIP)
DOI: 10.1109/ICIP42928.2021.9506016
Cite as: arXiv:2101.10747 [cs.CV]
  (or arXiv:2101.10747v2 [cs.CV] for this version)

Submission history

From: Mazen Abdelfattah Mr [view email]
[v1] Tue, 26 Jan 2021 12:40:34 GMT (473kb,D)
[v2] Sun, 31 Jan 2021 18:40:27 GMT (473kb,D)

Link back to: arXiv, form interface, contact.