Physically Real-time Infrared Attack against Optical Flow Estimation Networks
This paper presents a novel, non-invasive physical-world attack on Optical Flow Estimation Networks that utilizes stealthy infrared lights and pre-computed adversarial examples to generate real-time, targeted disruptions across diverse environmental conditions without modifying the victim system.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the world is full of invisible eyes watching everything. These aren't human eyes, but cameras hooked up to super-smart computer brains called "Optical Flow Estimation Networks." Think of these networks as the ultimate motion detectors. They don't just see a picture; they watch how every single pixel in that picture moves from one frame to the next. If a car drives by, the network calculates exactly how fast and in what direction every part of that car is traveling. This is the secret sauce behind self-driving cars dodging obstacles and security systems tracking thieves. But here's the catch: these computer brains have a secret weakness. Just like a magician can fool a human eye with a sleight of hand, hackers can trick these networks with "adversarial examples"—tiny, almost invisible glitches that make the computer see things that aren't there or miss things that are. The big question scientists are asking is: Can we trick these motion detectors in the real world, not just on a computer screen, without anyone noticing?
This paper introduces a sneaky new way to do exactly that, using a tool that is practically invisible to us humans: infrared light. The authors, a team of researchers, propose a method they call a "Physically Real-time Infrared Attack." Instead of trying to paint a weird pattern on a car (which you could easily see and wipe off), they stick small infrared lights onto the target. To our eyes, the car looks normal. But to the camera, which can see infrared, the car is flashing a secret, chaotic code. The researchers found that by turning these lights on and off in a very specific, rapid rhythm, they can confuse the computer's motion detector. It's like if you were trying to track a runner, but every time they took a step, someone flashed a strobe light that made them look like they were teleporting or standing still. The computer gets so confused by the sudden changes in brightness that it stops tracking the object entirely.
The team didn't just guess this would work; they built a physical test track to prove it. They set up a camera, a moving object (a plastic plate with lights), and a controller. First, they used a "Genetic Algorithm"—think of it as a digital evolution simulator—to figure out the perfect pattern of light flashes. This part took time, like breeding the perfect racehorse. Once they found the winning pattern, they trained a fast, simple neural network (an "Adversarial Generative Network") to copy that pattern instantly. This allowed them to switch the lights on and off in real-time, faster than the camera could blink.
The results were quite convincing. When they tested this against two popular motion-tracking systems (RAFT and PWC-Net), the attack was highly effective. The computer's "vision" of the moving object turned into a blank, chaotic mess. In many tests, the system failed to see the object moving at all, or it saw a completely wrong path. The researchers showed that this trick worked even when the object moved at different speeds, when the room lighting changed from dim to bright, and even when the camera was moved further away. They found that the attack was most effective when the room wasn't too bright, as strong sunlight can overpower the infrared signal, but it still held its own in a wide range of conditions.
Crucially, the paper argues against older methods that tried to print sticky, visible stickers on cars or use digital simulations that don't work in the real world. The authors suggest that those methods often fail because real cameras pick up noise and because the printed patterns look too obvious to humans. Their infrared approach, however, stays hidden from human eyes while wreaking havoc on the machine's vision. They also discovered that the "flash" of the light—how different the brightness is between one frame and the next—was the most important part of the trick. Without that rapid change, the computer could still figure out the motion.
In short, the paper suggests that the security systems relying on motion tracking might be more fragile than we thought. By using a simple, invisible flashlight and a bit of smart timing, it is possible to make a moving object disappear from a computer's view. While this doesn't mean self-driving cars are about to crash tomorrow, it does suggest that the "eyes" of our automated world can be blinded by a little bit of invisible light, and that we need to build stronger defenses against these kinds of physical tricks.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.