This work proposes the first diffusion-based unrestricted adversarial attack against 2D range-image segmentation, using adversarial guidance from a segmentation loss, and offers a distinct effectiveness-realism trade-off, achieving controllable white-box and transfer degradation while maintaining competitive distributional and visual realism.
Abstract
LiDAR semantic segmentation is a key perception task in autonomous driving, where false predictions can affect downstream planning and safety-critical decision-making. Although adversarial attacks, and specifically adversarial examples, have been widely studied for image classification and 3D point cloud segmentation, unrestricted adversarial examples remain largely unexplored in the space of 2D range images, which are projections of 3D point clouds. The proposed method is, to the best of our knowledge, the first diffusion-based unrestricted adversarial attack against 2D range-image segmentation, using adversarial guidance from a segmentation loss. By applying guidance directly during sampling, the method produces unrestricted adversarial examples that remain close to the learned LiDAR data manifold while inducing structured segmentation errors. Experiments on the SemanticKITTI dataset using RangeNet++ and CENet segmentation networks demonstrate that the attack provides adjustable degradation across guidance strengths and transfers across segmentation architectures. Compared with norm-bounded FGSM and SegPGD baselines, the proposed attack offers a distinct effectiveness-realism trade-off, achieving controllable white-box and transfer degradation while maintaining competitive distributional and visual realism.
Deep learning has boosted remote sensing (RS) scene classification, but adversarial examples can still cause high-confidence misclassification with imperceptible perturbations. Adversarial purification (AP) offers a practical test-time defense without retraining the classifier. However, most existing methods are confined to pixel-space restoration, which may leave residual adversarial effects that persist and amplify through feature extraction, ultimately biasing the prediction. To address these issues, a dual-domain AP (DDAP) framework is proposed to mitigate adversarial effects at both the pixel and feature levels in a unified pipeline. In the pixel domain, a pixel-domain frequency-aware diffusion purification (PFDP) module performs diffusion-based restoration through a frequency-aware dual-stream U-Net (FD-UNet). By integrating adaptive spectral filtering with multidomain consistency constraints, PFDP reduces adversarial-perturbation-dominated high-frequency responses while preserving structural details and semantic information in RS imagery. In the feature domain, an adversarial vulnerable channel dropout (AVCD) strategy models unshifted shallow-feature statistics with a Gaussian mixture model (GMM) and adaptively assigns channelwise dropout probabilities based on a samplewise shift score and channel vulnerability, thereby suppressing residual adversarial influence before downstream classification. Extensive experiments on UC Merced (UCM) and aerial image dataset (AID) across multiple backbones and attack types demonstrate that DDAP consistently improves robustness while maintaining a favorable clean–robust balance compared with representative baselines.
Yuru Su, Shaohui Mei, Mingyang Ma et al.· IEEE Transactions on Geoscie...· 0 citations
Focusing on zero-shot classification, this study demonstrates that 3D vision-language models exhibit heightened sensitivity to small coordinate perturbations, highlighting the need for a more rigorous security evaluation of 3D vision-language models.
Xuanxiang Lin, Yan Huang, Longkun Zou et al.· IEEE Access· 0 citations
This research investigates the adversarial robustness of lane detection for Autonomous Vehicles (AVs) under challenging driving conditions using Generative Adversarial Networks (GANs). In this work, the term adversarial refers to the adversarial training mechanism of GANs and to robustness under naturally adverse driving conditions, particularly illumination variation, rather than to defence against deliberate pixel-level perturbation attacks such as FGSM or PGD. Lane detection is a crucial component for safe navigation, but it often fails under poor lighting or adverse weather. To solve this, a U-Net model is trained on the Berkeley DeepDrive (BDD100K) dataset as a baseline. Then, Conditional GAN (CGAN) is used with the Cityscapes dataset to learn the mapping between RGB images and lane masks, which improves structural consistency. To handle illumination changes, CycleGAN is used to simulate Day-to-Night and Night-to-Day translations using BDD100K datasets, creating a more diverse training set. Preprocessing involves resizing images to 512×512 to ensure training efficiency on limited GPU hardware. The experiments are conducted using TensorFlow in a GPU-accelerated environment. Results show that the U-Net + CycleGAN model achieves a Precision of 65.41% and an F1-Score of 63.79%, which outperforms previous studies. The CGAN model also shows high performance with 92.55% F1-Score. This research proves that using GANs for data augmentation and domain translation can enhance the adversarial robustness and reliability of lane detection systems in real-world scenarios.
Brian Lee Chong Ming, Thinesh Ganesan· International Conference on...· 0 citations
MAIG-Net combines a target-label-free ground-sampling-distance rule, an intermediate domain constructed by Fourier domain adaptation (FDA) that transfers only low-frequency target appearance onto labeled source images while preserving the complete source phase and road labels, and Domain-Invariant Feature Alignment modules that perform reliability-weighted, topology-conditioned adversarial alignment at three encoder depths.
Chengqi Bao, Guangwu Chen, Wenbo Jin et al.· Italian National Conference...· 0 citations
AdvSerial is proposed, a dynamic 2D--3D joint optimization framework for generating continuous high-angle physical adversarial patches against pedestrian detectors in infrastructure-based scenarios and the results reveal persistent, temporally consistent failure modes under high-angle surveillance, and motivate the design of motion-aware and 3D-aware defenses for security-critical infrastructure deployments.
Yuanhao Huang, Yi-Long Ren, Jinlei Wang et al.· Computer-Aided Civil and Inf...· 1 citation