U.S. flag An official website of the United States government.
Official websites use .gov

A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS

A lock ( ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

i

On the Adversarial Robustness of Camera-Based 3D Object Detection

File Language:
English


Details

  • Creators:
  • Corporate Creators:
  • Corporate Contributors:
  • Subject/TRT Terms:
  • Resource Type:
  • Right Statement:
  • Geographical Coverage:
  • Corporate Publisher:
  • Abstract:
    In recent years, camera-based 3D object detection has gained widespread attention for its ability to achieve high performance with low computational cost. However, the robustness of these methods to adversarial attacks has not been thoroughly examined, especially when considering their deployment in safety-critical domains like autonomous driving. In this study, we conduct the first comprehensive investigation of the robustness of leading camera-based 3D object detection approaches under various adversarial conditions. We systematically analyze the resilience of these models under two attack settings: white-box and black-box; focusing on two primary objectives: classification and localization. Additionally, we delve into two types of adversarial attack techniques: pixel-based and patch-based. Our experiments yield four interesting findings: (a) bird’s-eye-view-based representations exhibit stronger robustness against localization attacks; (b) depth-estimation-free approaches have the potential to show stronger robustness; (c) accurate depth estimation effectively improves robustness for depth-estimation-based methods; (d) incorporating multi-frame benign inputs can effectively mitigate adversarial attacks. We hope our findings can steer the development of future camera-based object detection models with enhanced adversarial robustness. The code is available at: https://github.com/Daniel-xsy/BEV-Attack.
  • Content Notes:
    Published in Transactions on Machine Learning Research (01/2024); Reviewed on OpenReview: https: // openreview. net/ forum? id= 6SofFlwhEv
  • Format:
    PDF
  • Collection(s):
  • Main Document Checksum:
    urn:sha-512:f15ad8b030a3865b1191ad27adf1b1b6a3167469fe6259ff81c7c5eb22c787296765959067fc859c708245b75ad6a239307ae9cedcc2d57cec4d5d407c4d0ed0
  • Download URL:
  • File Type:
    Filetype[PDF - 2.65 MB ]
File Language:
English
ON THIS PAGE
 Found an issue?
Send us an email at:
ROSA P serves as an archival repository of USDOT-published products including scientific findings, journal articles, guidelines, recommendations, or other information authored or co-authored by USDOT or funded partners. As a repository, ROSA P retains documents in their original published format to ensure public access to scientific information.