3 ms·
If you really wanted to crash cars by altering their visual input, why would you bother with all this complexity? Why not just actually swap the road sign? Why
by dontreact 5y ago
If you really wanted to crash cars by altering their visual input, why would you bother with all this complexity? Why not just actually swap the road sign?
Why does the existence of these attacks change the threat landscape at all? If people are already not doing "dumb" attacks like just changing/removing road signs why would they start doing them?
The risk of messing with road signs and throwing off autonomous vehicles really has less to do with adversarial image attacks and more to do with envisioning an impractically brittle system where the decision to stop is based purely on presence/absence of a stop sign and not on a system that has a more general sense of collision-avoidance and situational awareness (like humans do).|
Stepping back more generally, I have still never seen a case where the undetectability of adversarial attacks actually means there is a practical difference to security or safety. If you really think through the impact in the real world, usually the risk is already there: you can just change the input to the image and get bad results, it doesn't affect much that the image is imperceptibly changed. Because the whole point of using an automated vision system is usually that you want to avoid human eyes on the problem.
- goatlover 5y ago> Why not just actually swap the road sign? Because you have to physically do it, as opposed to hacking from anywhere else on the planet. > not on a system that has a more general sense of collision-avoidance and situational awareness (like humans do). Are vision systems to that point yet when it comes to driving vehicles? > Because the whole point of using an automated vision system is usually that you want to avoid human eyes on the problem. And the point of hacking an automated system is that it's easier to do that remotely than to cause a human to crash locally.
- JoshuaDavid 5y ago> Because you have to physically do it, as opposed to hacking from anywhere else on the planet. My impression is that the adversarial image attacks in question involve physically placing a sticker on something which will be in the view of self-driving cars -- it's not a remote exploit.
- d110af5ccf 5y agoWhich crime is easier to commit - physically swapping a street sign or placing a sticker on an existing one? How long does each act take? What equipment do you have to carry on you for each task? In a given span of time, how many street signs can a single person swap out versus how many stickers can they apply? When sourcing the materials for an attack, how expensive are stickers relative to physical signs?
- mlac 5y agoWhat’s the point of the attack? A well-placed sticker for the first car that comes along with a high value target? Just kill that person an easier way, that is more certain. After one accident, the sticker will be removed. Industrial sabotage to take out one car’s camera system? Ok - but which car company will do that? It’s mutually assured destruction if the other actors retaliate, and serious legal fees if caught. High school pranks? Sure. But again, they will be identified, finger printed, the printed item will be analyzed and reviewed for which printer printed it, and the person will be ID’d.