CNCA: Toward Customizable and Natural Generation of Adversarial Camouflage for Vehicle Detectors

Prior works on physical adversarial camouflage against vehicle detectors mainly focus on the effectiveness and robustness of the attack. The current most successful methods optimize 3D vehicle texture at a pixel level. However, this results in conspicuous and attention-grabbing patterns in the generated camouflage, which humans can easily identify. To address this issue, we propose a Customizable and Natural Camouflage Attack (CNCA) method by leveraging an off-the-shelf pre-trained diffusion model. By sampling the optimal texture image from the diffusion model with a user-specific text prompt, our method can generate natural and customizable adversarial camouflage while maintaining high attack performance. With extensive experiments on the digital and physical worlds and user studies, the results demonstrate that our proposed method can generate significantly more natural-looking camouflage than the state-of-the-art baselines while achieving competitive attack performance. Our code is available at \href{https://anonymous.4open.science/r/CNCA-1D54}{https://anonymous.4open.science/r/CNCA-1D54}

Paper

References (28)

Scroll for more · 16 remaining

Similar papers

Peer review

Reviewer oknY5/10 · confidence 5/52024-07-02

Summary

This paper presents a novel method CNCA for generating customizable and natural adversarial camouflage of fooling vehicle detectors. This work is an interesting contribution in the field of adversarial attacks, especially improving the naturalness of the camouflage while maintaining high attack performance.

Strengths

It is interesting to apply diffusion models to physical adversarial attacks to generate natural camouflage for the first time, and it is also of practical value to generate natural adversarial camouflage with customizable styles based on text prompts.

Weaknesses

The clipping strategy lacks innovation; it has been used in PGD for a long time, and it is not worth spending too much space on it.

Questions

1. Why is there no comparison with baselines in the physical world? 2. Whether other detection models can be used as white-box to generate adversarial textures to verify the transferability of CNCA. 3. Only use the subjective evaluation may not be convincing for experimental verification, and visual observation does not seem to be more natural than previous methods. Is there a more convincing scoring rule to evaluate naturalness?

Rating

5

Confidence

5

Soundness

2

Presentation

3

Contribution

3

Limitations

The experimental results are insignificant.

Authorsrebuttal2024-08-14

Reply to Reviewer oknY

Dear Reviewer oknY, Thank you for your time and effort in reviewing our work and rebuttal. Your feedback has helped us improve. We are grateful that you raised the rating for our work after we provided the clarifications in the rebuttal! Best Regards, Authors of Submission 17110

Reviewer MuNz5/10 · confidence 2/52024-07-06

Summary

The paper introduces a interesting idea and also a novel method called Customizable and Natural Camouflage Attack (CNCA) to generate adversarial camouflage against vehicle detectors, leveraging a pre-trained diffusion model. This approach allows the generation of natural-looking and user-customizable adversarial patterns that maintain robust attack performance across various digital and physical settings. The paper's contributions include a unique application of diffusion models to adversarial camouflage, introduction of adversarial features for gradient-based generation, and a clipping strategy to balance naturalness with attack performance. Extensive experiments and user studies demonstrate the effectiveness of CNCA in producing more natural-looking camouflage with competitive attack performance.

Strengths

- The paper proposes an interesting and useful application direction, namely natural and customized adversarial camouflage. The research motivation has substantial practical significance, and the proposed method appears intuitively reasonable. - This study is the first to apply diffusion models for natural adversarial camouflage generation. It is also the first to generate various 52 styles of adversarial camouflage against vehicle detectors. - The experiments are thorough, and the results are statistically significant, indicating high-quality research. - The code is provided.

Weaknesses

- Some expressions are not clear, making it difficult for those unfamiliar with the field to understand. For example, lines 32 to 35. It would be better and easier to understand if some visual evidence were provided regarding these limits. - Figure 1 is not correctly referenced. - The experimental section would be more convincing if the effectiveness of the proposed components and methods were demonstrated through ablation experiments. - Concerning anonymity: Some comments in the provided code reveal personal information. Please be aware of this!

Questions

- I am curious about its complexity. The method involves multiple components and parameters (e.g., adversarial features, clipping strategy), which might complicate its deployment in practical applications without substantial customization and tuning. - It would be more helpful if more ablation experiments were added to individually demonstrate the functions of each component.

Rating

5

Confidence

2

Soundness

3

Presentation

2

Contribution

3

Limitations

Refer to the “Questions” section.

Authorsrebuttal2024-08-14

Friendly Reminder: Follow-Up on Rebuttal for Submission 17110

Dear Reviewer MuNz, We are writing to follow up on the rebuttal we submitted regarding your review comments for our paper. We appreciate your time and effort in reviewing our work and providing valuable feedback. We have made a sincere effort to address each of your comments and questions in the rebuttal. We believe the clarifications and improvements we made in response to your suggestions have strengthened the paper significantly. We kindly request that you review our rebuttal as soon as possible ( today is the final day for discussion ) and consider increasing your rating for our paper with the provided changes and clarifications. Thank you again for your dedication to the review process; we look forward to hearing from you! Best Regards, Authors of Submission 17110

Reviewer MuNz2024-08-14

The author addressed most of my concerns, I will rise the score.

Reviewer guSy4/10 · confidence 5/52024-07-11

Summary

The manuscript presents a novel approach to generating physical adversarial camouflage against vehicle detectors, leveraging a pre-trained diffusion model. The proposed method, called Customizable and Natural Camouflage Attack (CNCA), aims to produce adversarial camouflage that is both natural-looking and customizable via user-specific text prompts. This approach addresses the limitations of previous methods that produced conspicuous and unnatural camouflage, maintaining effectiveness in adversarial attacks while enhancing the camouflage's appearance to blend seamlessly into its surroundings.

Strengths

CNCA introduces a novel application of diffusion models for generating physical adversarial camouflage, a significant shift from the traditional pixel-level optimization methods. The method allows for the generation of camouflage that is not only effective in evading detection but also customizable and more natural-looking, meeting specific user requirements. The manuscript provides a comprehensive evaluation of the CNCA approach, including both digital and physical world tests and user studies, demonstrating its effectiveness and practical applicability.

Weaknesses

The approach involves complex integration of diffusion models with adversarial attack frameworks, which may increase the computational overhead and complexity compared to more straightforward adversarial techniques. Although the manuscript includes extensive testing, the evaluations focus primarily on vehicle detection in controlled settings. The performance and practicality of CNCA in more varied or less controlled environments remain to be fully explored.

Questions

See strength and weakness above.

Rating

4

Confidence

5

Soundness

3

Presentation

3

Contribution

2

Limitations

No. While the paper discusses potential positive impacts, such as improving AI robustness, the technique could also be used maliciously to evade surveillance, posing ethical and security concerns.

Authorsrebuttal2024-08-14

Request for a higher Rating from Reviewer guSy

Dear Reviewer guSy, Thanks for taking the time to review and reply to our rebuttal. We are grateful for your feedback, which has helped us to improve our work. We understand and respect your decision to maintain your current rating. However, we kindly ask you to consider whether our clarifications justify a higher rating. We believe the enhancements made during the rebuttal, specifically the extended ablation studies for each component in our pipeline and both indoor and outdoor physical evaluations with previous methods, have strengthened the quality and clarity of our work. We appreciate your understanding and consideration of this request. We would like to provide further clarification if there are any issues you would like us to address. Thanks again for your time and effort in reviewing our paper! Best Regards, Authors of Submission 17110

Reviewer TBRf6/10 · confidence 4/52024-07-17

Summary

The paper introduces a novel framework, CNCA, for generating customizable and natural adversarial camouflage for vehicle detectors using a diffusion model. This work addresses critical limitations in current adversarial camouflage techniques by focusing on naturalness and customizability, which are often neglected in favor of attack performance. While the paper presents a significant advancement in adversarial camouflage, several areas require improvement to enhance rigor and presentation. The proposed CNCA framework holds substantial promise, but further validation and detailed comparison are essential to establish its superiority and practical relevance.

Strengths

1. The use of a diffusion model for generating natural and customizable adversarial camouflage is novel. 2. The extensive experiments, including both digital and physical settings, provide strong evidence of the method's effectiveness.

Weaknesses

1. The explanation of the adversarial feature generation and its integration with the diffusion model is somewhat convoluted. Quantitatively define the evaluation indicators of naturalness and attack performance, or provide relevant references. 2. The evaluation in the physical world is limited to small-scale models and specific conditions. Extend the evaluation to a broader range of vehicle detection models and datasets, including those used in autonomous driving (e.g., KITTI, Waymo Open Dataset). Assess the scalability of CNCA by testing on larger, more complex scenes and different environmental conditions to validate its general applicability. 3. The paper lacks ablation studies to isolate the impact of different components of the proposed framework. Conduct ablation studies to demonstrate the contribution of each component (e.g., the diffusion model, adversarial feature clipping) to the overall performance.

Questions

Experimental Statistical Significance: The authors recruited 45 participants to subjectively evaluate the naturalness of different camouflages, reporting the mean scores and standard deviations (SD) for naturalness of each type of camouflage. While this is good, merely reporting the mean scores and SD does not statistically demonstrate whether the differences in mean scores are significant. It would be more convincing to conduct t-tests or ANOVA (preferably repeated measures ANOVA with post hoc tests, based on the current experimental design) and report the relevant statistics (e.g., t and F values, as well as p values). Physical World Evaluation: In the physical world evaluation, the paper only compared two models, one for a normal and another for the generated camouflage. Have the authors considered including models with other adversarial camouflage methods for comparisons, as the authors did in the digital world?

Rating

6

Confidence

4

Soundness

4

Presentation

3

Contribution

4

Limitations

Perform a thorough comparison with state-of-the-art methods like AdvCam and UAPs that are known for their effectiveness. Discuss the differences in performance metrics such as attack success rate, naturalness, and computational efficiency. Highlight the advantages and limitations of CNCA relative to these methods.

Authorsrebuttal2024-08-14

Response to Reviewer TBRf

Dear Reviewer TBRf, We sincerely appreciate your time and effort in reviewing our work and rebuttal. We kindly ask you to **consider whether our improvements might justify a higher rating**. We believe the **extended ablation studies for each component in our pipeline and both indoor and outdoor physical evaluations with previous methods** have strengthened the quality of our work. We would be happy to provide further clarifications if you have further questions. Thanks again for your time and effort in reviewing our paper! Best Regards, Authors of Submission 17110

Area Chair KAeb2024-08-11

Dear Reviewers, The discussion period ends within 3 days. Authors made tremendous efforts on providing responses to your concerns. So, if you haven’t yet, please check responses and express your opinions whether you want to initiate discussion or accept the authors’ responses. Best, Your AC

Reviewer guSy2024-08-12

The author's response addressed some of my questions and I decided to keep my rating.

Authorsrebuttal2024-08-13

Reply to the Ethics Review Questions from Reviewer pBgC

We appreciate your time and effort in providing insightful reviews. Here are the answers to your questions: **Q1: Is the determination of "no potential risk" made by the authors themselves?** Yes, the determination of "no potential risk" is made by the authors after careful consideration of the limited evaluation time (an average of five minutes per person) and the expected minimal impact on participants. **Q2: If so, is making this determination without an IRB or equivalent permissible in their research institution or workplace?** We have confirmed that the researchers in our research institution can make an initial determination of minimal risk for studies involving surveys with limited evaluation time and negligible psychological or physical impact. However, we recognize that consulting an IRB or equivalent body would provide a more formal risk assessment, and we will take this step in future studies. **Q3: Were human subjects compensated for participating in the study?** Yes, our participants were compensated with small gifts such as (bottled water or online discount coupons) since our evaluation did not take a significant amount of time to complete (an average of five minutes). **Q4: Were human subjects screened for colorblindness or other vision impairments?** In our current survey, human subjects were not screened for colorblindness or other vision impairment. Given the evidence that colorblind individuals may have different abilities in detecting camouflage, we will include screening for color vision impairments as part of the participant selection process in future research.

Reviewer TBRf2024-08-14

The authors provided thorough explanations and additional experiments to address concerns. The integration of adversarial features has been clarified with the diffusion model and provided relevant metrics for naturalness and attack performance. Additional studies were conducted, isolating the impact of each component in the framework. The authors extended their evaluation to more complex scenarios, though they acknowledge limitations due to resource constraints. The authors have mentioned that this paper need larger-scale evaluations in future work, with more immediate tests in varied environments.

Program Chairsdecision2024-09-25

Decision

Accept (poster)

© 2026 NYSGPT2525 LLC