about
Catoptric Light Can Be Dangerous: Physical-World Attack by Natural Phenomenon (arxiv.org)
6 points by PaulHoule on Sep 26, 2022 | hide | past | pdf | 1 comment on HN

In plain words: Instead of printed patches or lasers, this attack shapes ordinary reflected light—like glare off a shiny surface—to trick image classifiers. In real-world tests it fooled them 83.5% of the time, beating the sticker baseline, and over 80% against hardened models.

Abstract · Adversarial Catoptric Light: An Effective, Stealthy and Robust Physical-World Attack to DNNs

Deep neural networks (DNNs) have demonstrated exceptional success across various tasks, underscoring the need to evaluate the robustness of advanced DNNs. However, traditional methods using stickers as physical perturbations to deceive classifiers present challenges in achieving stealthiness and suffer from printing loss. Recent advancements in physical attacks have utilized light beams such as lasers and projectors to perform attacks, where the optical patterns generated are artificial rather than natural. In this study, we introduce a novel physical attack, adversarial catoptric light (AdvCL), where adversarial perturbations are generated using a common natural phenomenon, catoptric light, to achieve stealthy and naturalistic adversarial attacks against advanced DNNs in a black-box setting. We evaluate the proposed method in three aspects: effectiveness, stealthiness, and robustness. Quantitative results obtained in simulated environments demonstrate the effectiveness of the proposed method, and in physical scenarios, we achieve an attack success rate of 83.5%, surpassing the baseline. We use common catoptric light as a perturbation to enhance the stealthiness of the method and make physical samples appear more natural. Robustness is validated by successfully attacking advanced and robust DNNs with a success rate over 80% in all cases. Additionally, we discuss defense strategy against AdvCL and put forward some light-based physical attacks.

Chengyin Hu, Weiwen Shi
arXiv:2209.11739 · cs.CV, cs.CR, cs.LG · submitted Sep 19, 2022 · updated May 23, 2023
abstract · pdf · html · arXiv admin note: substantial text overlap with arXiv:2209.09652, arXiv:2209.02430

add comment on HN

Interesting. So the text isn’t available, but I am guessing that the technique is to “project” a non- physical image on the adversary’s detector to fool the classifier? For example: a fake object, like an aircraft?

Do you have additional resources or links?

Edit: I was able to download PDF. Now I understand the technique, which is less sophisticated. But I wonder about my initial thought…?