UNDREAM: Bridging Differentiable Rendering and Photorealistic Simulation for End-to-end Adversarial Attacks
Mansi Phute, Matthew Hull, Haoran Wang, Alec Helbling, ShengYun Peng, Willian Lunardi, Martin Andreoni, Wenke Lee, Duen Horng Chau
TL;DR
UNDREAM addresses the gap between non-differentiable, high-fidelity simulators and differentiable renderers to enable end-to-end adversarial optimization in realistic 3D environments. By integrating Unreal Engine with the Mitsuba differentiable renderer, it allows adversarial textures to be optimized directly within photorealistic scenes, preserving lighting and material interactions. The framework automates 3D scene transformation, supports dynamic sequences, and provides an adaptable attack pipeline, with open-source availability for reproducibility. This approach enables more faithful evaluations of attacks and defenses in applied safety-critical settings, such as autonomous systems, under varied environmental conditions.
Abstract
Deep learning models deployed in safety critical applications like autonomous driving use simulations to test their robustness against adversarial attacks in realistic conditions. However, these simulations are non-differentiable, forcing researchers to create attacks that do not integrate simulation environmental factors, reducing attack success. To address this limitation, we introduce UNDREAM, the first software framework that bridges the gap between photorealistic simulators and differentiable renderers to enable end-to-end optimization of adversarial perturbations on any 3D objects. UNDREAM enables manipulation of the environment by offering complete control over weather, lighting, backgrounds, camera angles, trajectories, and realistic human and object movements, thereby allowing the creation of diverse scenes. We showcase a wide array of distinct physically plausible adversarial objects that UNDREAM enables researchers to swiftly explore in different configurable environments. This combination of photorealistic simulation and differentiable optimization opens new avenues for advancing research of physical adversarial attacks.
