A survey of physical-domain adversarial attack methods against object detection models
Hongbo Yan, Xing Yang, Haoqi Gao, Haiyuan Yu, Zhiyang Hu, Hanpei Xiao · 2024
The emergence of adversarial examples has confirmed the significant vulnerabilities of deep learning models. By introducing subtle perturbations, these examples can easily cause a drastic decline or even complete failure in the performance of well-trained models. Recent studies have indicated that these perturbations pose not only theoretical threats but also substantial risks and impacts in real-world scenarios. This study focuses on the issue of physical adversarial attacks against object detection models, providing a clear and precise definition of the concept. From multiple perspectives of target detection systems, including faces, pedestrians, vehicles, and traffic signboards, we delved deeply into and summarized a series of physical adversarial attack methods and their characteristics against object detection network models in recent years. Finally, we discussed the severe challenges faced by physical adversarial attacks, particularly the limitations of adversarial training and its inadequacies in practical applications. Based on current research progress, we envision possible future development directions and vast application prospects in this field, aiming to provide valuable references and insights for enhancing the security and robustness of deep learning models.