Abstract
In autonomous driving, object detection system (ODS) plays a crucial role in ensuring the safety of autonomous vehicles. However, it is vulnerable to adversarial examples (AEs), which exploit perturbations to deceive deep neural networks (DNNs) used for object detection. Previous instances of such attacks either lack stealthiness, making them easily detectable by human observers, or are limited to static scenarios. In this paper, we propose NarAdv, a natural-style and robust physical adversarial attack on ODS, marking the first study to generate highly stealthy and robust AEs for dynamic driving environments. First, we develop a bounding box pre-selection module, incorporating the Expectation Over Transformation (EOT) technique, aiming to enhance robustness under varying distance conditions. Second, we develop a perspective alignment module to model the camera’s viewpoint shifts during vehicle movement. Finally, we camouflage AEs by converting large perturbations into natural styles that appear legitimate to human observers, ensuring both effectiveness and stealthiness in real-world scenarios. We have shown that our NarAdv crafts AEs that are well-camouflaged and highly stealthy. Extensive experiments demonstrate that NarAdv achieves high attack success rates across different driving scenarios, including varying distances, camera angles, and lighting conditions.