A Survey on Physical Adversarial Attack in Computer Vision

  • 2022-09-28 18:23:52
  • Donghua Wang, Wen Yao, Tingsong Jiang, Guijiang Tang, Xiaoqian Chen
  • 1

Abstract

In the past decade, deep learning has dramatically changed the traditionalhand-craft feature manner with strong feature learning capability, resulting intremendous improvement of conventional tasks. However, deep neural networkshave recently been demonstrated vulnerable to adversarial examples, a kind ofmalicious samples crafted by small elaborately designed noise, which misleadthe DNNs to make the wrong decisions while remaining imperceptible to humans.Adversarial examples can be divided into digital adversarial attacks andphysical adversarial attacks. The digital adversarial attack is mostlyperformed in lab environments, focusing on improving the performance ofadversarial attack algorithms. In contrast, the physical adversarial attackfocus on attacking the physical world deployed DNN systems, which is a morechallenging task due to the complex physical environment (i.e., brightness,occlusion, and so on). Although the discrepancy between digital adversarial andphysical adversarial examples is small, the physical adversarial examples havea specific design to overcome the effect of the complex physical environment.In this paper, we review the development of physical adversarial attacks inDNN-based computer vision tasks, including image recognition tasks, objectdetection tasks, and semantic segmentation. For the sake of completeness of thealgorithm evolution, we will briefly introduce the works that do not involvethe physical adversarial attack. We first present a categorization scheme tosummarize the current physical adversarial attacks. Then discuss the advantagesand disadvantages of the existing physical adversarial attacks and focus on thetechnique used to maintain the adversarial when applied into physicalenvironment. Finally, we point out the issues of the current physicaladversarial attacks to be solved and provide promising research directions.

 

Quick Read (beta)

loading the full paper ...