preprint Open access

GhostImage: Remote Perception Attacks against Camera-based Image\n Classification Systems

  • arXiv (Cornell University)
  • Cornell University
Research footprint

At a glance

Citations
13
References
0
Comments
0
Paper overview

Abstract

In vision-based object classification systems imaging sensors perceive the\nenvironment and machine learning is then used to detect and classify objects\nfor decision-making purposes; e.g., to maneuver an automated vehicle around an\nobstacle or to raise an alarm to indicate the presence of an intruder in\nsurveillance settings. In this work we demonstrate how the perception domain\ncan be remotely and unobtrusively exploited to enable an attacker to create\nspurious objects or alter an existing object. An automated system relying on a\ndetection/classification framework subject to our attack could be made to\nundertake actions with catastrophic results due to attacker-induced\nmisperception.\n We focus on camera-based systems and show that it is possible to remotely\nproject adversarial patterns into camera systems by exploiting two common\neffects in optical imaging systems, viz., lens flare/ghost effects and\nauto-exposure control. To improve the robustness of the attack to channel\neffects, we generate optimal patterns by integrating adversarial machine\nlearning techniques with a trained end-to-end channel model. We experimentally\ndemonstrate our attacks using a low-cost projector, on three different image\ndatasets, in indoor and outdoor environments, and with three different cameras.\nExperimental results show that, depending on the projector-camera distance,\nattack success rates can reach as high as 100% and under targeted conditions.\n

Record transparency

Publication details

DOI
10.48550/arxiv.2001.07792
OpenAlex
W3092419617
Document type
preprint
Language
EN
Source
arXiv (Cornell University)
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.