Dynamic Physical Adversarial LED Patterns via Reinforcement Learning
Abstract
Physical adversarial attacks expose important limitations of modern vision systems, but most existing methods rely on static patches or textures. We introduce a new problem setting: closed-loop physical adversarial control, where an agent interacts with a real-world perception system via a physical channel and receives only detector-level feedback. We optimize LED patterns with PR-SAC in a high-dimensional continuous action space. We show that latent action parameterization with deterministic upsampling improves training stability compared to direct control of individual LEDs. Across YOLOv8, Faster R-CNN, and RetinaNet, the learned patterns reduce person-detection confidence, decrease mAP@0.5, and exhibit partial cross-model transfer. We further analyze robustness under distance and viewpoint changes, interaction with a defense mechanism, and failure modes such as Q-drift, entropy collapse, and degradation after initial improvement. Our results suggest that dynamic physical attacks should be evaluated not only by best-case attack strength, but also by stability, transferability, and robustness under real-world variation.