[Paper Review] Physical Adversarial Attacks For Camera-based Smart Systems: Current Trends, Categorization, Applications, Research Challenges, and Future Outlook
This paper provides a comprehensive survey of physical adversarial attacks on camera-based smart systems, categorizing attack methods by application task (e.g., object detection, face recognition, depth estimation) and analyzing their effectiveness, stealthiness, and robustness under real-world distortions. It identifies key challenges in physical attack design and calls for standardized benchmarks and stronger defenses to ensure trustworthy AI in safety-critical domains.
In this paper, we present a comprehensive survey of the current trends focusing specifically on physical adversarial attacks. We aim to provide a thorough understanding of the concept of physical adversarial attacks, analyzing their key characteristics and distinguishing features. Furthermore, we explore the specific requirements and challenges associated with executing attacks in the physical world. Our article delves into various physical adversarial attack methods, categorized according to their target tasks in different applications, including classification, detection, face recognition, semantic segmentation and depth estimation. We assess the performance of these attack methods in terms of their effectiveness, stealthiness, and robustness. We examine how each technique strives to ensure the successful manipulation of DNNs while mitigating the risk of detection and withstanding real-world distortions. Lastly, we discuss the current challenges and outline potential future research directions in the field of physical adversarial attacks. We highlight the need for enhanced defense mechanisms, the exploration of novel attack strategies, the evaluation of attacks in different application domains, and the establishment of standardized benchmarks and evaluation criteria for physical adversarial attacks. Through this comprehensive survey, we aim to provide a valuable resource for researchers, practitioners, and policymakers to gain a holistic understanding of physical adversarial attacks in computer vision and facilitate the development of robust and secure DNN-based systems.
Motivation & Objective
- To provide a systematic understanding of physical adversarial attacks in real-world computer vision applications.
- To categorize and analyze attack methods based on target tasks such as classification, detection, segmentation, and depth estimation.
- To examine the challenges of robustness, stealthiness, and real-world deployment in physical adversarial attacks.
- To identify research gaps and propose future directions, including standardized benchmarks and improved defense mechanisms.
- To highlight ethical considerations and responsible research practices in developing and evaluating physical adversarial attacks.
Proposed method
- Surveying over 190 papers and analyzing 94 distinct adversarial attack methods across diverse computer vision tasks.
- Categorizing attacks into patch-based, sticker-based, camouflage, light manipulation, and imaging device manipulation techniques.
- Evaluating attack performance based on effectiveness, stealthiness, and robustness to real-world distortions such as lighting, viewpoint changes, and motion.
- Applying the Expectation Over Transformation (EOT) method to enhance physical attack robustness by simulating real-world variations during optimization.
- Analyzing temporal consistency in video-based attacks to maintain effectiveness across consecutive frames.
- Investigating transferability of attacks across different tasks, including trajectory prediction, pose estimation, and action recognition.
Experimental results
Research questions
- RQ1What are the key characteristics and distinguishing features of physical adversarial attacks compared to digital counterparts?
- RQ2How do physical adversarial attacks maintain effectiveness under real-world distortions such as lighting changes, viewpoint variations, and motion blur?
- RQ3What are the most effective strategies for ensuring stealthiness and imperceptibility in physical attacks across different application domains?
- RQ4How do physical adversarial attacks perform across emerging computer vision tasks such as trajectory prediction and action recognition?
- RQ5What are the major challenges in evaluating and benchmarking physical adversarial attacks, and how can standardized criteria be established?
Key findings
- Physical adversarial attacks are highly effective in real-world settings, with printed adversarial examples successfully deceiving DNNs under varying lighting and viewing conditions.
- The Expectation Over Transformation (EOT) technique significantly improves attack robustness by simulating real-world variations during the attack generation process.
- Temporal consistency is critical for video-based attacks, as inconsistent perturbations across frames reduce attack success rates and increase detectability.
- Stealthiness remains a major challenge, with no universally accepted metric for evaluating visual naturalness in physical attacks.
- Physical adversarial attacks show transferability across tasks such as object detection, face recognition, and semantic segmentation, indicating broad model vulnerabilities.
- Despite progress, there is a lack of standardized benchmarks and evaluation protocols, hindering fair comparison and reproducibility in the field.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.