English
Related papers

Related papers: AdvReal: Physical Adversarial Patch Generation Fra…

200 papers

Object detection plays a crucial role in many security-sensitive applications. However, several recent studies have shown that object detectors can be easily fooled by physically realizable attacks, \eg, adversarial patches and recent…

Computer Vision and Pattern Recognition · Computer Science 2025-07-10 Xiao Li , Yiming Zhu , Yifan Huang , Wei Zhang , Yingzhe He , Jie Shi , Xiaolin Hu

The advent of adversarial patches poses a significant challenge to the robustness of AI models, particularly in the domain of computer vision tasks such as object detection. In contradistinction to traditional adversarial examples, these…

Computer Vision and Pattern Recognition · Computer Science 2025-09-03 Wonho Lee , Hyunsik Na , Jisu Lee , Daeseon Choi

Face recognition systems have been shown to be vulnerable to adversarial examples resulting from adding small perturbations to probe images. Such adversarial images can lead state-of-the-art face recognition systems to falsely reject a…

Computer Vision and Pattern Recognition · Computer Science 2019-08-15 Debayan Deb , Jianbang Zhang , Anil K. Jain

Infrared physical adversarial examples are of great significance for studying the security of infrared AI systems that are widely used in our lives such as autonomous driving. Previous infrared physical attacks mainly focused on 2D infrared…

Computer Vision and Pattern Recognition · Computer Science 2024-05-17 Xiaopei Zhu , Yuqiu Liu , Zhanhao Hu , Jianmin Li , Xiaolin Hu

Modern autonomous driving systems rely heavily on deep learning models to process point cloud sensory data; meanwhile, deep models have been shown to be susceptible to adversarial attacks with visually imperceptible perturbations. Despite…

Computer Vision and Pattern Recognition · Computer Science 2020-04-03 James Tu , Mengye Ren , Siva Manivasagam , Ming Liang , Bin Yang , Richard Du , Frank Cheng , Raquel Urtasun

Owing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are…

Computer Vision and Pattern Recognition · Computer Science 2023-03-27 Wei Xingxing , Yu Jie , Huang Yao

Compared with traditional machine learning models, deep neural networks perform better, especially in image classification tasks. However, they are vulnerable to adversarial examples. Adding small perturbations on examples causes a…

Computer Vision and Pattern Recognition · Computer Science 2020-06-24 Zifei Zhang , Kai Qiao , Lingyun Jiang , Linyuan Wang , Bin Yan

Adversarial attacks in the physical world can harm the robustness of detection models. Evaluating the robustness of detection models in the physical world can be challenging due to the time-consuming and labor-intensive nature of many…

Computer Vision and Pattern Recognition · Computer Science 2023-04-12 Tianyuan Zhang , Yisong Xiao , Xiaoya Zhang , Hao Li , Lu Wang

The existence of real-world adversarial examples (commonly in the form of patches) poses a serious threat for the use of deep learning models in safety-critical computer vision tasks such as visual perception in autonomous driving. This…

Computer Vision and Pattern Recognition · Computer Science 2025-09-10 Giulio Rossolini , Federico Nesti , Gianluca D'Amico , Saasha Nair , Alessandro Biondi , Giorgio Buttazzo

Deep neural network security is a persistent concern, with considerable research on visible light physical attacks but limited exploration in the infrared domain. Existing approaches, like white-box infrared attacks using bulb boards and QR…

Cryptography and Security · Computer Science 2023-12-25 Chengyin Hu , Weiwen Shi

Recent works have proposed to craft adversarial clothes for evading person detectors, while they are either only effective at limited viewing angles or very conspicuous to humans. We aim to craft adversarial texture for clothes based on 3D…

Computer Vision and Pattern Recognition · Computer Science 2024-11-11 Zhanhao Hu , Wenda Chu , Xiaopei Zhu , Hui Zhang , Bo Zhang , Xiaolin Hu

In this paper, we demonstrate a physical adversarial patch attack against object detectors, notably the YOLOv3 detector. Unlike previous work on physical object detection attacks, which required the patch to overlap with the objects being…

Computer Vision and Pattern Recognition · Computer Science 2019-07-01 Mark Lee , Zico Kolter

Autonomous driving systems (ADS) increasingly rely on deep learning-based perception models, which remain vulnerable to adversarial attacks. In this paper, we revisit adversarial attacks and defense methods, focusing on road sign…

Robotics · Computer Science 2025-05-26 Cheng Chen , Yuhong Wang , Nafis S Munir , Xiangwei Zhou , Xugui Zhou

Recently demonstrated physical-world adversarial attacks have exposed vulnerabilities in perception systems that pose severe risks for safety-critical applications such as autonomous driving. These attacks place adversarial artifacts in the…

Machine Learning · Computer Science 2021-06-23 Jan Hendrik Metzen , Nicole Finnie , Robin Hutmacher

Physical adversarial attacks pose a significant practical threat as it deceives deep learning systems operating in the real world by producing prominent and maliciously designed physical perturbations. Emphasizing the evaluation of…

Computer Vision and Pattern Recognition · Computer Science 2024-02-12 Amira Guesmi , Ioan Marius Bilasco , Muhammad Shafique , Ihsen Alouani

Autonomous vehicles (AVs) rely on LiDAR sensors for environmental perception and decision-making in driving scenarios. However, ensuring the safety and reliability of AVs in complex environments remains a pressing challenge. To address this…

Computer Vision and Pattern Recognition · Computer Science 2024-12-18 Shijun Zheng , Weiquan Liu , Yu Guo , Yu Zang , Siqi Shen , Cheng Wang

Stand-alone Visual Place Recognition (VPR) systems have little defence against a well-designed adversarial attack, which can lead to disastrous consequences when deployed for robot navigation. This paper extensively analyzes the effect of…

Computer Vision and Pattern Recognition · Computer Science 2025-06-23 Connor Malone , Owen Claxton , Iman Shames , Michael Milford

Stereo depth estimation is a critical task in autonomous driving and robotics, where inaccuracies (such as misidentifying nearby objects as distant) can lead to dangerous situations. Adversarial attacks against stereo depth estimation can…

Computer Vision and Pattern Recognition · Computer Science 2025-11-04 Yun Xing , Yue Cao , Nhat Chung , Jie Zhang , Ivor Tsang , Ming-Ming Cheng , Yang Liu , Lei Ma , Qing Guo

Deep neural networks have been shown vulnerable toadversarial patches, where exotic patterns can resultin models wrong prediction. Nevertheless, existing ap-proaches to adversarial patch generation hardly con-sider the contextual…

Computer Vision and Pattern Recognition · Computer Science 2021-04-28 Jinqi Luo , Tao Bai , Jun Zhao

This paper presents a novel patch-based adversarial attack pipeline that trains adversarial patches on 3D human meshes. We sample triangular faces on a reference human mesh, and create an adversarial texture atlas over those faces. The…

Computer Vision and Pattern Recognition · Computer Science 2021-04-23 Arman Maesumi , Mingkang Zhu , Yi Wang , Tianlong Chen , Zhangyang Wang , Chandrajit Bajaj