Return
Consistent attack: Universal adversarial perturbation on embodied vision navigation
DOI:10.1016/j.patrec.2023.03.001.png)
Abstract
En 中文
Embodied agents in vision navigation coupled with deep neural networks have attracted increasing at-tention. However, deep neural networks have been shown vulnerable to malicious adversarial noises, which may potentially cause catastrophic failures in Embodied Vision Navigation. Among different ad-versarial noises, universal adversarial perturbations (UAP), i.e., a constant image-agnostic perturbation applied on every input frame of the agent, play a critical role in Embodied Vision Navigation since they are computation-efficient and application-practical during the attack. However, existing UAP methods ig-nore the system dynamics of Embodied Vision Navigation and might be sub-optimal. In order to ex-tend UAP to the sequential decision setting, we formulate the disturbed environment under the uni-versal noise 8, as a 8-disturbed Markov Decision Process (8-MDP). Based on the formulation, we ana-lyze the properties of 8-MDP and propose two novel Consistent Attack methods, named Reward UAP and Trajectory UAP, for attacking Embodied agents, which consider the dynamic of the MDP and calcu-late universal noises by estimating the disturbed distribution and the disturbed Q function. For various victim models, our Consistent Attack can cause a significant drop in their performance in the Point -Goal task in Habitat with different datasets and different scenes. Extensive experimental results indi-cate that there exist serious potential risks for applying Embodied Vision Navigation methods to the real world.(c) 2023 Published by Elsevier B.V.
Keywords:
Embodied agent
Vision navigation
Deep neural networks
Universal adversarial noise
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

