Search papers, labs, and topics across Lattice.
This study introduces a novel approach to creating physical adversarial examples for thermal person detectors by designing infrared adversarial clothing using 3D modeling techniques. By optimizing the layout of black aerogel patches on clothing, the researchers achieved a high attack success rate of 80.11% indoors and 76.85% outdoors against the YOLOv9 detector, significantly outperforming randomly placed patches. The method also demonstrated strong transferability to unknown detectors, highlighting the potential vulnerabilities in thermal detection systems in real-world applications.
Adversarial clothing can successfully evade thermal person detectors with over 80% effectiveness, exposing critical security flaws in AI-driven surveillance systems.
Thermal Infrared detection is widely used in autonomous driving, medical AI, etc., but its security has only attracted attention recently. We propose infrared adversarial clothing designed to evade thermal person detectors in real-world scenarios. The design of the adversarial clothing is based on 3D modeling, which makes it easier to simulate multiangle scenes near the real world compared to 2D modeling. We optimized the black patch layout pattern of 3D clothing based on the adversarial example technique and made physical adversarial clothing using the aerogel. The idea is to paste a set of square aerogel patches, which display black squares in thermal images, in the inner side of clothing at specific locations with specific orientations. To enhance realism, we propose a method to build infrared 3D models with real infrared photos and develop texture maps for 3D models to simulate varied infrared characteristics over time and location. In physical attacks, we achieved an attack success rate of 80.11\% indoors and 76.85\% outdoors against YOLOv9. In contrast, randomly placed patches yielded much lower success rates (26.53\% indoors and 23.03\% outdoors). The adversarial clothing also showed good transferability to unknown detectors with an ensemble attack method, demonstrating the effectiveness of our approach.