zhangsn-19 / PAN

Code and data for PAN and PAN-phys.
Apache License 2.0
9 stars 0 forks source link

Towards Benchmarking and Assessing Visual Naturalness of Physical World Adversarial Attacks

In this paper, we contribute the first Physical Attack Naturalness (PAN) dataset with human rating and gaze to benchmark attack naturalness.

We also introduce Dual Prior Alignment (DPA) network, which aims to embed human knowledge into model reasoning process. Specifically, DPA imitates human reasoning in naturalness assessment by rating prior alignment and mimics human gaze behavior by attentive prior alignment.

Physical Attack Naturalness (PAN) dataset

Physical attack naturalness (PAN) dataset is the first dataset to understand naturalness of physical world attacks in autonomous driving. In PAN dataset, we consider 7 baselines, 2 backgrounds, 2 illuminance, 8 pitch angles, 4 yaw angles and 3 distances, resulting in 7×2×2×8×4×3 = 2688 images. For each image, we also release its gaze saliency map, subjective naturalness ratings evaluated by MOS (Mean Opinion Score) and rating distribution.

We also collected 504 real world adversarial images, called PAN-phys with 8 pitch angles, 3 yaw angles and 3 backgrounds, resulting in 7×8×3×3 = 504 images with their gaze saliency maps, subjective naturalness ratings and rating distributions.

The dataset can be found in https://drive.google.com/drive/folders/1nGiU8cO5d3BGKxFP4Y1MlWot8UqvehwZ?usp=share_link

Example images

PAN

PAN-phys

File structure

DPA framework

Dependencies

Running

python train.py --train --eval --test 

Results will be saved in src/logs/, including: