English
Related papers

Related papers: Physically Adversarial Infrared Patches with Learn…

200 papers

Despite modifying only a small localized input region, adversarial patches can drastically change the prediction of computer vision models. However, prior methods either cannot perform satisfactorily under targeted attack scenarios or fail…

Computer Vision and Pattern Recognition · Computer Science 2025-07-10 Subrat Kishore Dutta , Xiao Zhang

Detection of military assets on the ground can be performed by applying deep learning-based object detectors on drone surveillance footage. The traditional way of hiding military assets from sight is camouflage, for example by using…

Event cameras, known for their low latency and high dynamic range, show great potential in pedestrian detection applications. However, while recent research has primarily focused on improving detection accuracy, the robustness of…

Computer Vision and Pattern Recognition · Computer Science 2025-03-04 Guixu Lin , Muyao Niu , Qingtian Zhu , Zhengwei Yin , Zhuoxiao Li , Shengfeng He , Yinqiang Zheng

In this paper, we propose a natural and robust physical adversarial example attack method targeting object detectors under real-world conditions. The generated adversarial examples are robust to various physical constraints and visually…

Computer Vision and Pattern Recognition · Computer Science 2021-03-18 Mingfu Xue , Chengxiang Yuan , Can He , Jian Wang , Weiqiang Liu

Physical adversarial attacks threaten to fool object detection systems, but reproducible research on the real-world effectiveness of physical patches and how to defend against them requires a publicly available benchmark dataset. We present…

Computer Vision and Pattern Recognition · Computer Science 2023-07-21 Anneliese Braunegg , Amartya Chakraborty , Michael Krumdick , Nicole Lape , Sara Leary , Keith Manville , Elizabeth Merkhofer , Laura Strickhart , Matthew Walmer

Adversarial examples have proven to be a concerning threat to deep learning models, particularly in the image domain. However, while many studies have examined adversarial examples in the real world, most of them relied on 2D photos of the…

Computer Vision and Pattern Recognition · Computer Science 2021-09-03 Yael Mathov , Lior Rokach , Yuval Elovici

Adversarial patch attacks can fool the face recognition (FR) models via small patches. However, previous adversarial patch attacks often result in unnatural patterns that are easily noticeable. Generating transferable and stealthy…

Computer Vision and Pattern Recognition · Computer Science 2023-10-03 Yanjie Li , Mingxing Duan , Xuelong Dai , Bin Xiao

Deep learning-based systems have been shown to be vulnerable to adversarial attacks in both digital and physical domains. While feasible, digital attacks have limited applicability in attacking deployed systems, including face recognition…

Computer Vision and Pattern Recognition · Computer Science 2020-04-20 Dinh-Luan Nguyen , Sunpreet S. Arora , Yuhang Wu , Hao Yang

Applications such as autonomous vehicles and medical screening use deep learning models to localize and identify hundreds of objects in a single frame. In the past, it has been shown how an attacker can fool these models by placing an…

Computer Vision and Pattern Recognition · Computer Science 2021-06-03 Yisroel Mirsky

While extensive research exists on physical adversarial attacks within the visible spectrum, studies on such techniques in the infrared spectrum are limited. Infrared object detectors are vital in modern technological applications but are…

Computer Vision and Pattern Recognition · Computer Science 2024-07-09 Kalibinuer Tiliwalidi , Chengyin Hu , Weiwen Shi

It is known that deep neural networks (DNNs) are vulnerable to adversarial attacks. The so-called physical adversarial examples deceive DNN-based decisionmakers by attaching adversarial patches to real objects. However, most of the existing…

Computer Vision and Pattern Recognition · Computer Science 2020-07-07 Kaidi Xu , Gaoyuan Zhang , Sijia Liu , Quanfu Fan , Mengshu Sun , Hongge Chen , Pin-Yu Chen , Yanzhi Wang , Xue Lin

Adversarial patches in computer vision can be used, to fool deep neural networks and manipulate their decision-making process. One of the most prominent examples of adversarial patches are evasion attacks for object detectors. By covering…

Computer Vision and Pattern Recognition · Computer Science 2025-04-25 Jens Bayer , Stefan Becker , David Münch , Michael Arens

Nowadays, cameras equipped with AI systems can capture and analyze images to detect people automatically. However, the AI system can make mistakes when receiving deliberately designed patterns in the real world, i.e., physical adversarial…

Computer Vision and Pattern Recognition · Computer Science 2022-08-16 Zhanhao Hu , Siyuan Huang , Xiaopei Zhu , Fuchun Sun , Bo Zhang , Xiaolin Hu

With the trend of adversarial attacks, researchers attempt to fool trained object detectors in 2D scenes. Among many of them, an intriguing new form of attack with potential real-world usage is to append adversarial patches (e.g. logos) to…

Machine Learning · Computer Science 2020-11-30 Yi Wang , Jingyang Zhou , Tianlong Chen , Sijia Liu , Shiyu Chang , Chandrajit Bajaj , Zhangyang Wang

In this paper, we present a comprehensive survey of the current trends focusing specifically on physical adversarial attacks. We aim to provide a thorough understanding of the concept of physical adversarial attacks, analyzing their key…

Cryptography and Security · Computer Science 2023-08-14 Amira Guesmi , Muhammad Abdullah Hanif , Bassem Ouni , Muhammed Shafique

Adversarial attacks in deep learning models, especially for safety-critical systems, are gaining more and more attention in recent years, due to the lack of trust in the security and robustness of AI models. Yet the more primitive…

Computer Vision and Pattern Recognition · Computer Science 2022-06-17 Abhijith Sharma , Yijun Bian , Phil Munz , Apurva Narayan

This paper discusses the attack feasibility of Remote Adversarial Patch (RAP) targeting face detectors. The RAP that targets face detectors is similar to the RAP that targets general object detectors, but the former has multiple issues in…

Computer Vision and Pattern Recognition · Computer Science 2024-12-12 Masora Okano , Koichi Ito , Masakatsu Nishigaki , Tetsushi Ohki

Physical adversarial patch attacks critically threaten pedestrian detection, causing surveillance and autonomous driving systems to miss pedestrians and creating severe safety risks. Despite their effectiveness in controlled settings,…

Computer Vision and Pattern Recognition · Computer Science 2026-04-27 Shihui Yan , Ziqi Zhou , Yufei Song , Yifan Hu , Minghui Li , Shengshan Hu

2D face recognition has been proven insecure for physical adversarial attacks. However, few studies have investigated the possibility of attacking real-world 3D face recognition systems. 3D-printed attacks recently proposed cannot generate…

Computer Vision and Pattern Recognition · Computer Science 2022-11-15 Yanjie Li , Yiquan Li , Xuelong Dai , Songtao Guo , Bin Xiao

Object detection is a crucial task in autonomous driving. While existing research has proposed various attacks on object detection, such as those using adversarial patches or stickers, the exploration of projection attacks on 3D surfaces…

Cryptography and Security · Computer Science 2024-09-27 Ce Zhou , Qiben Yan , Sijia Liu