Physical Domain Deception Strategy: Experimental Verification of Adversarial Attacks on Vehicle Targets
Qinghua Dai, Haoqi Gao, Xing Yang, Fanjunzhe Geng, Guoqing Wu · 2025
While digital-domain adversarial attacks against vehicle detection models have matured with diversified implementations, research on physical-domain adversarial attacks still faces critical challenges, including environmental complexity and poor attack robustness. This paper establishes a digital-physical collaborative validation framework to systematically conduct empirical studies on physical-domain adversarial attacks. The methodology follows a dual-phase approach: First, adversarial samples are meticulously designed in the digital domain, followed by comprehensive physical-domain testing under multi-dimensional complex conditions, simulating varied heights (1.05–1.55 m), camera angles (0–360°), diverse backgrounds (sandy terrain, grassy terrain, runway, and parking lot), and illumination intensities (indoor and outdoor environments). Notably, this study innovatively introduces comparative experiments with traditional smoke interference scenarios. Experimental results demonstrate that the proposed intelligent adversarial samples achieve an over 30% higher average attack success rate in physical environments compared to conventional smoke-based interference methods. The successful implementation of effective attacks against vehicle detection systems in real-world scenarios not only enriches the practical applications of adversarial attacks but also demonstrates substantial innovation in attack methodology. This research provides critical insights for enhancing the robustness of autonomous driving systems while establishing new theoretical foundations for physical-domain adversarial attack studies. Furthermore, the findings suggest that future research should focus on developing more sophisticated defense mechanisms to counteract these advanced adversarial attacks, ensuring the safety and reliability of intelligent systems in complex real-world environments.