计算机技术与发展2026,Vol.36Issue(1):193-201,9.DOI:10.20165/j.cnki.ISSN1673-629X.2025.0218
面向可见光-红外多模态系统的对抗补丁攻击方法
Adversarial Patch Attack Method for Visible-infrared Multimodal Systems
摘要
Abstract
To address the security threats and cross-modal optimization conflicts in multimodal object detection systems for critical scenarios such as autonomous driving and security surveillance,we propose a dynamically coordinated adversarial patch generation method.By analyzing the differences in imaging characteristics between visible and infrared modalities,a framework is constructed to balance attack efficacy and physical deployability.The proposed method employs multi-segment closed Bézier curves to model patch shapes,incorporating curvature constraints and minimum linewidth limitations to ensure printability.Tailored optimizations are applied for modality-specific attributes:high-contrast color perturbations for visible light and thermal radiation distribution adjustments for infrared.Cross-modal attack coordination is achieved through dynamic weight allocation and gradient alignment strategies.Experimental results demonstrate attack success rates(ASR)of 89.2%for visible and 83.7%for infrared modalities,with the Cross-Modal Consistency Index(CMCI)reaching0.85.Physical-world simulations confirm that the generated patches meet industrial printing standards(mean curvature and minimum linewidth compliance)and maintain high attack success rates across varying angles.This work reveals the synergistic optimization mechanisms of multimodal adversarial attacks,offering novel insights for system security protection.Future efforts will focus on enhancing robustness in complex scenarios and developing lightweight real-time attack frameworks.关键词
对抗补丁/贝塞尔曲线/多模态目标检测/多模态协同攻击/可见光-红外融合Key words
adversarial patch/Bézier curve/multimodal object detection/multimodal collaborative attack/visible-infrared fusion分类
信息技术与安全科学引用本文复制引用
胡梦嘉,沈志东..面向可见光-红外多模态系统的对抗补丁攻击方法[J].计算机技术与发展,2026,36(1):193-201,9.基金项目
湖北省重点研发计划项目(2022BAA041) (2022BAA041)