Road Decals as Trojans: Disrupting Autonomous Vehicle Navigation with Adversarial Patterns
Wei-Jia Chen, Chia‐Yi Hsu, Wei‐Bin Lee, Chia-Mu Yu, Chun‐Ying Huang · 2024
The emergence of autonomous vehicles (AVs) represents a significant breakthrough in transportation. These vehicles use object detection algorithms to sense and interpret their environment, enabling them to navigate and make decisions autonomously. Therefore, object detection systems are essential to ensure the effectiveness and safety of AV operations. However, recent studies have shown that object detection systems based on deep neural networks are susceptible to interference from intentionally designed objects containing adversarial perturbations. In this paper, we investigate the dependability of AVs by designing physical adversarial patches (APs) to fool object detectors. To ensure that the APs work in the real-world AVs, our APs have the following designs. First, we use the Expectation Over Transformation (EOT) technique to make APs adaptive to environmental challenges such as distance, angle, and shadow. Instead of using colored APs, our APs are monochrome and their shapes are more controllable, making them more stealthy on the road. Most importantly, an object is confirmed by AVs only after the object is detected for consecutive frames; however, most existing APs can only work in static cases. Our APs overcome the above challenges and ensure attack success in dynamic cases. Our experimental results show that our AP can effectively attack YOLOv3-tiny.