We introduce OPtical ADversarial attack (OPAD). OPAD is an adversarial attack in the physical space aiming to fool image classifiers without physically touching the objects (e.g., moving or painting the objects). The principle of OPAD is to use structured illumination to alter the appearance of the target objects. The system consists of a low-cost projector, a camera, and a computer. The challenge of the problem is the non-linearity of the radiometric response of the projector and the spatially varying spectral response of the scene. Attacks generated in a conventional approach do not work in this setting unless they are calibrated to compensate for such a projector-camera model. The proposed solution incorporates the projector-camera model into the adversarial attack optimization, where a new attack formulation is derived. Experimental results prove the validity of the solution. It is demonstrated that OPAD can optically attack a real 3D object in the presence of background lighting for white-box, black-box, targeted, and untargeted attacks. Theoretical analysis is presented to quantify the fundamental performance limit of the system.
翻译:我们引入了Optic Adversarial攻击(OPAD)。OPAD是在物理空间进行对抗性攻击,目的是在不实际触动物体(例如移动或油漆物体)的情况下愚弄图像分类器。OPAD的原则是使用结构化照明来改变目标物体的外观。系统由低成本投影机、照相机和计算机组成。问题的挑战在于投影机的辐射度反应和现场空间变化的光谱反应的不线性。在常规方法下产生的攻击在本环境中是行不通的,除非它们经过校准以补偿这种投影摄像模型。拟议的解决办法将投影机模型纳入对抗性攻击优化中,以产生新的攻击配方。实验结果证明解决办法的有效性。实验结果证明,OPAD可以在白箱、黑盒、定向和无目标攻击的背景照明中以光学方式攻击一个真正的3D物体。理论分析是为了量化系统的基本性能限制。