| Item type |
Symposium(1) |
| 公開日 |
2025-10-20 |
| タイトル |
|
|
言語 |
ja |
|
タイトル |
ヘッドライト光の反射を悪用した標識認識への攻撃:商用車両を用いた影響評価と対策の提案* |
| タイトル |
|
|
言語 |
en |
|
タイトル |
Adversarial Retroreflective Patch Attacks against Traffic Sign Recognition Systems: Impact for Commercial Vehicles and Defenses |
| 言語 |
|
|
言語 |
jpn |
| キーワード |
|
|
主題Scheme |
Other |
| 資源タイプ |
|
|
資源タイプ識別子 |
http://purl.org/coar/resource_type/c_5794 |
|
資源タイプ |
conference paper |
| 著者所属 |
|
|
|
早稲田大学/産総研 |
| 著者所属 |
|
|
|
慶應義塾大学 |
| 著者所属 |
|
|
|
カリフォルニア大学アーバイン校 |
| 著者所属 |
|
|
|
早稲田大学/デロイトトーマツサイバー合同会社 |
| 著者所属 |
|
|
|
早稲田大学 |
| 著者所属 |
|
|
|
早稲田大学/デロイトトーマツサイバー合同会社 |
| 著者所属 |
|
|
|
早稲田大学/情報通信研究機構/理研AIP |
| 著者所属(英) |
|
|
|
Waseda University / AIST |
| 著者所属(英) |
|
|
|
Keio University |
| 著者所属(英) |
|
|
|
UC Irvine |
| 著者所属(英) |
|
|
|
Waseda University / Deloitte Tohmatsu Cyber |
| 著者所属(英) |
|
|
|
Waseda University |
| 著者所属(英) |
|
|
|
Waseda University / Deloitte Tohmatsu Cyber |
| 著者所属(英) |
|
|
|
Waseda University / NICT / RIKEN |
| 著者名 |
鶴岡,豪
佐藤,貴海
Qi, Alfred Chen
野本,一輝
小林,竜之輔
田中,優奈
森,達哉
|
| 著者名(英) |
Go Tsuruoka
Takami Sato
Qi Alfred Chen
Kazuki Nomoto
Ryunosuke Kobayashi
Yuna Tanaka
Tatsuya Mori
|
| 論文抄録 |
|
|
内容記述タイプ |
Other |
|
内容記述 |
すべての道路利用者は交通標識を遵守しなければならず,自動運転車においても同様である.近年の研究では,交通標識認識システムが敵対的攻撃に対して脆弱であることが知られており,小さなステッカーの適用やレーザ・光の投影を用いた攻撃手法が提案されてきた.しかし,これらの攻撃には,それぞれステルス性と実現可能性に大きな制約がある.この制約に対処するため,我々は新しい攻撃ベクトルとして,敵対的反射パッチ (ARP) 攻撃を提案する.この手法はパッチ攻撃の持つ実現可能性と,レーザ・光投影攻撃の持つステルス性を兼ね備えている.ARP 攻撃は再帰反射素材の特性を利用して,夜間に攻撃対象車両のヘッドライトなどの強い光があたったときのみに動作する,非常にステルス性の高い攻撃パッチを生成する.効果的な ARP 攻撃を生成するため,我々は脅威モデルを定式化した.また,3D シェーディングシミュレータ上で再帰反射素材を再現する新しい手法を設計し,ブラックボックス最適化を用いてシミュレーション上で攻撃の効果を最大化した.この ARP 攻撃を実際の商用車両に搭載された標識認識システムに対して評価をし,最大 75% の攻撃成功率を達成し,実社会への脅威を明らかにした.また,ARP 攻撃に対する防御策として,反射現象の背景にある物理現象に着目し,DPR シールドという二枚の偏光板を用いた効果的な防御手法を設計し,75% 以上の防御成功率を記録した. |
| 論文抄録(英) |
|
|
内容記述タイプ |
Other |
|
内容記述 |
Traffic signs provide critical traffic rules for all road users—pedestrians and motor vehicles alike—and these rules apply equally to autonomous vehicles. Recent studies have revealed that vision-based traffic sign recognition systems are vulnerable to adversarial attacks, with methods such as small-sticker perturbations and laser or light projections having been proposed. However, these prior works suffer from significant trade-offs between deployability and stealth. To overcome these limitations, we introduce a novel attack vector, the Adversarial Retroreflective Patch (ARP) attack, which combines the practical deployability of patch-based attacks with the high stealth of laser-projection attacks. The ARP attack exploits the properties of retroreflective materials to create highly stealthy patches that activate only under strong illumination—such as the headlights of a victim vehicle at night. To generate effective ARP attacks, we formulate a precise threat model, design a novel method for simulating retroreflective materials within a state-of-the-art 3D shading simulator, and employ a black-box optimization approach to maximize attack effectiveness in simulation. We evaluate the ARP attack against commercial-grade traffic sign recognition systems installed on real vehicles, achieving an attack success rate of over 60% and demonstrating a concrete threat to real-world deployments. Finally, as a defense against ARP attacks, we propose and evaluate DPR Shield, which is an effective countermeasure that leverages the underlying physics of retroreflection through the use of dual polarizing filters. We demonstrate the defense success rate of over 75%. |
| 書誌情報 |
コンピュータセキュリティシンポジウム2025論文集
p. 408-415,
発行日 2025-10-20
|
| 出版者 |
|
|
言語 |
ja |
|
出版者 |
情報処理学会 |