Physical adversarial examples for camera-based computer vision have so far\nbeen achieved through visible artifacts -- a sticker on a Stop sign, colorful\nborders around eyeglasses or a 3D printed object with a colorful texture. An\nimplicit assumption here is that the perturbations must be visible so that a\ncamera can sense them. By contrast, we contribute a procedure to generate, for\nthe first time, physical adversarial examples that are invisible to human eyes.\nRather than modifying the victim object with visible artifacts, we modify light\nthat illuminates the object. We demonstrate how an attacker can craft a\nmodulated light signal that adversarially illuminates a scene and causes\ntargeted misclassifications on a state-of-the-art ImageNet deep learning model.\nConcretely, we exploit the radiometric rolling shutter effect in commodity\ncameras to create precise striping patterns that appear on images. To human\neyes, it appears like the object is illuminated, but the camera creates an\nimage with stripes that will cause ML models to output the attacker-desired\nclassification. We conduct a range of simulation and physical experiments with\nLEDs, demonstrating targeted attack rates up to 84%.\n
Paper
References (40)
Scroll for more · 28 remaining