Physically Real-time Infrared Attack against Optical Flow Estimation Networks

📄 arXiv: 2607.26651v1 📥 PDF

作者: Shen You, Wei Jiang, Jiarui Liu, Yijian Ye, Qiuzhen Lin, Xiangtao Li, Ka-Chun Wong

分类: cs.CV, cs.AI

发布日期: 2026-07-29


💡 一句话要点

提出物理实时红外攻击以增强光流估计网络的鲁棒性

🎯 匹配领域: 支柱三:空间感知与语义 (Perception & Semantics)

关键词: 光流估计 对抗样本 红外攻击 深度学习 安全性 自动驾驶 鲁棒性

📋 核心要点

  1. 现有的光流估计网络在面对物理世界中的攻击时,鲁棒性不足,容易受到对抗样本的影响。
  2. 本文提出了一种基于红外光的实时攻击方法,通过动态生成对抗样本,能够在不修改受害系统的情况下进行精准攻击。
  3. 实验结果显示,该方法在多种光照条件和物体运动状态下,成功降低了光流估计网络的准确性,验证了其有效性。

📝 摘要(中文)

随着深度神经网络在图像任务中的优异表现,诸如自动驾驶和运动检测等现实应用日益成熟。光流估计网络(OFENs)作为上游模型,在多个领域中扮演着关键角色,其输出被广泛应用于下游任务,因此测试其鲁棒性至关重要。本文提出了一种针对OFENs的物理实时攻击方法,利用红外光的隐蔽性,通过提前生成大量对抗样本(AEs),实时计算并动态展示这些样本,从而实现精确和有针对性的攻击,而无需修改受害系统。与以往的数字到物理攻击技术不同,本方法直接在物理世界中攻击受害模型,克服了对抗样本效果不佳的局限性。实验结果表明,该方法在不同光照条件、物体运动速度和位置下有效破坏了OFENs的光流估计能力。

🔬 方法详解

问题定义:本文旨在解决光流估计网络在物理环境中遭受攻击时的鲁棒性不足问题。现有方法在物理世界中应用对抗样本时,效果往往不理想,难以实现有效攻击。

核心思路:本研究的核心思路是利用红外光的隐蔽性,通过实时生成和展示对抗样本,达到对光流估计网络的精准攻击。该设计旨在提高攻击的隐蔽性和有效性。

技术框架:整体架构包括对抗样本的预生成、实时计算和动态展示三个主要模块。首先,提前生成大量对抗样本;然后,在攻击过程中实时计算并展示这些样本,以便于针对特定目标进行攻击。

关键创新:本研究的主要创新在于直接在物理世界中对光流估计网络进行攻击,克服了以往数字到物理攻击方法的局限性,能够有效地影响网络的输出。

关键设计:关键设计包括对抗样本的生成策略、实时计算的算法优化,以及动态展示的技术实现,确保攻击的实时性和精准性。

🖼️ 关键图片

fig_0
fig_1
fig_2

📊 实验亮点

实验结果表明,提出的方法在不同光照条件下成功降低了光流估计网络的准确性,尤其在高速度运动物体的情况下,攻击成功率显著提升,验证了方法的有效性和实用性。

🎯 应用场景

该研究的潜在应用领域包括自动驾驶、监控系统和机器人导航等,能够帮助提升这些系统在面对恶意攻击时的安全性和鲁棒性。通过增强光流估计网络的防御能力,能够有效降低安全事故的发生率,具有重要的实际价值和社会影响。

📄 摘要(原文)

With the promising performance of deep neural networks on image-based tasks, different real-world applications such as autonomous driving and motion detection have become increasingly mature and relevant to human lives. In particular, Optical Flow Estimation Networks (OFENs), as upstream models, play a critical role in different domains. Its outputs are heavily assumed and adopted for different downstream tasks, and it is essential to test its robustness to prevent safety accidents. We present an approach for real-time attacks on OFENs in the physical world, leveraging infrared lights for their stealthiness. By generating a large number of Adversarial Examples in advance, our approach computes AEs in real time and dynamically displays them, which allows our method to facilitate precise and targeted attacks without modifying the victim system. Unlike previous digital-to-physical attack techniques, our method directly attacks victim models within the physical world, thereby overcoming the limitations associated with the ineffectiveness of AEs. Experimental results demonstrate the efficacy of our approach in compromising OFENs across diverse lighting conditions, varying object motion velocities, and different object placements, ultimately impairing the network's ability to accurately estimate optical flow.