Benchmarking the Physical-world Adversarial Robustness of Vehicle Detection

AI-generated keywords: Robustness Detection Models CARLA Simulator Adversarial Attacks Benchmark

AI-generated Key Points

The license of the paper does not allow us to build upon its content and the key points are generated using the paper metadata rather than the full article.

Also access our AI generated: Comprehensive summary, Lay summary, Blog-like article; or ask questions about this paper to our AI assistant.

Authors: Tianyuan Zhang, Yisong Xiao, Xiaoya Zhang, Hao Li, Lu Wang

CVPR 2023 workshop

Abstract: Adversarial attacks in the physical world can harm the robustness of detection models. Evaluating the robustness of detection models in the physical world can be challenging due to the time-consuming and labor-intensive nature of many experiments. Thus, virtual simulation experiments can provide a solution to this challenge. However, there is no unified detection benchmark based on virtual simulation environment. To address this challenge, we proposed an instant-level data generation pipeline based on the CARLA simulator. Using this pipeline, we generated the DCI dataset and conducted extensive experiments on three detection models and three physical adversarial attacks. The dataset covers 7 continuous and 1 discrete scenes, with over 40 angles, 20 distances, and 20,000 positions. The results indicate that Yolo v6 had strongest resistance, with only a 6.59% average AP drop, and ASA was the most effective attack algorithm with a 14.51% average AP reduction, twice that of other algorithms. Static scenes had higher recognition AP, and results under different weather conditions were similar. Adversarial attack algorithm improvement may be approaching its 'limitation'.

Submitted to arXiv on 11 Apr. 2023

Ask questions about this paper to our AI assistant

You can also chat with multiple papers at once here.

The license of the paper does not allow us to build upon its content and the AI assistant only knows about the paper metadata rather than the full article.

AI assistant instructions?

Results of the summarizing process for the arXiv paper: 2304.05098v1

This paper's license doesn't allow us to build upon its content and the summarizing process is here made with the paper's metadata rather than the article.

The paper titled "Benchmarking the Physical-world Adversarial Robustness of Vehicle Detection" by Tianyuan Zhang, Yisong Xiao, Xiaoya Zhang, Hao Li, and Lu Wang discusses the challenges associated with evaluating the robustness of detection models in the physical world due to its time-consuming and labor-intensive nature. To address this issue, virtual simulation experiments can provide a solution. However, there is no unified detection benchmark based on virtual simulation environment. To overcome this challenge, the authors proposed an instant-level data generation pipeline based on the CARLA simulator which resulted in the DCI dataset. This dataset covers 7 continuous and 1 discrete scenes with over 40 angles, 20 distances and 20,000 positions. Extensive experiments were conducted on three detection models and three physical adversarial attacks using this dataset. The results indicate that Yolo v6 had strongest resistance with only a 6.59% average AP drop while ASA was found to be the most effective attack algorithm with a 14.51% average AP reduction - twice that of other algorithms tested. Static scenes had higher recognition AP while results under different weather conditions were similar. Moreover, it was observed that adversarial attack algorithm improvement may be approaching its 'limitation'. Overall, this study provides valuable insights into evaluating the robustness of detection models in virtual simulation environments using instant-level data generation pipelines like CARLA simulator-based DCI dataset which could serve as a unified benchmark for future research in this area.
Created on 11 May. 2023

Assess the quality of the AI-generated content by voting

Score: 0

Why do we need votes?

Votes are used to determine whether we need to re-run our summarizing tools. If the count reaches -10, our tools can be restarted.

The previous summary was created more than a year ago and can be re-run (if necessary) by clicking on the Run button below.

The license of this specific paper does not allow us to build upon its content and the summarizing tools will be run using the paper metadata rather than the full article. However, it still does a good job, and you can also try our tools on papers with more open licenses.

Similar papers summarized with our AI tools

Navigate through even more similar papers through a

tree representation

Look for similar papers (in beta version)

By clicking on the button above, our algorithm will scan all papers in our database to find the closest based on the contents of the full papers and not just on metadata. Please note that it only works for papers that we have generated summaries for and you can rerun it from time to time to get a more accurate result while our database grows.

Disclaimer: The AI-based summarization tool and virtual assistant provided on this website may not always provide accurate and complete summaries or responses. We encourage you to carefully review and evaluate the generated content to ensure its quality and relevance to your needs.