English
Related papers

Related papers: Transferable Physical-World Adversarial Patches Ag…

200 papers

Machine learning models are known to be susceptible to adversarial perturbation. One famous attack is the adversarial patch, a sticker with a particularly crafted pattern that makes the model incorrectly predict the object it is placed on.…

Computer Vision and Pattern Recognition · Computer Science 2023-08-21 Nabeel Hingun , Chawin Sitawarin , Jerry Li , David Wagner

Physical adversarial attacks are increasingly studied in settings that resemble deployed surveillance systems rather than isolated image benchmarks. In these settings, person detection, multi-object tracking, visible--infrared sensing, and…

Computer Vision and Pattern Recognition · Computer Science 2026-04-09 Miguel A. DelaCruz , Patricia Mae Santos , Rafael T. Navarro

Developing reliable defenses against patch attacks on object detectors has attracted increasing interest. However, we identify that existing defense evaluations lack a unified and comprehensive framework, resulting in inconsistent and…

Computer Vision and Pattern Recognition · Computer Science 2025-08-08 Junhao Zheng , Jiahao Sun , Chenhao Lin , Zhengyu Zhao , Chen Ma , Chong Zhang , Cong Wang , Qian Wang , Chao Shen

Deep neural networks used for human detection are highly vulnerable to adversarial manipulation, creating safety and privacy risks in real surveillance environments. Wearable attacks offer a realistic threat model, yet existing approaches…

Computer Vision and Pattern Recognition · Computer Science 2025-12-16 Dingkun Zhou , Patrick P. K. Chan , Hengxu Wu , Shikang Zheng , Ruiqi Huang , Yuanjie Zhao

Modern automated surveillance techniques are heavily reliant on deep learning methods. Despite the superior performance, these learning systems are inherently vulnerable to adversarial attacks - maliciously crafted inputs that are designed…

Computer Vision and Pattern Recognition · Computer Science 2023-10-17 Kien Nguyen , Tharindu Fernando , Clinton Fookes , Sridha Sridharan

We consider universal adversarial patches for faces -- small visual elements whose addition to a face image reliably destroys the performance of face detectors. Unlike previous work that mostly focused on the algorithmic design of…

Computer Vision and Pattern Recognition · Computer Science 2020-07-20 Xiao Yang , Fangyun Wei , Hongyang Zhang , Jun Zhu

Artistic crosswalks featuring asphalt art, introduced by different organizations in recent years, aim to enhance the visibility and safety of pedestrians. However, their visual complexity may interfere with surveillance systems that rely on…

Computer Vision and Pattern Recognition · Computer Science 2026-04-03 Jin Ma , Abyad Enan , Long Cheng , Mashrur Chowdhury

Neural network-based visuomotor policies enable robots to perform manipulation tasks but remain susceptible to perceptual attacks. For example, conventional 2D adversarial patches are effective under fixed-camera setups, where appearance is…

Robotics · Computer Science 2026-03-06 Chanmi Lee , Minsung Yoon , Woojae Kim , Sebin Lee , Sung-eui Yoon

To assess the vulnerability of deep learning in the physical world, recent works introduce adversarial patches and apply them on different tasks. In this paper, we propose another kind of adversarial patch: the Meaningful Adversarial…

Computer Vision and Pattern Recognition · Computer Science 2022-12-20 Xingxing Wei , Ying Guo , Jie Yu

Despite modifying only a small localized input region, adversarial patches can drastically change the prediction of computer vision models. However, prior methods either cannot perform satisfactorily under targeted attack scenarios or fail…

Computer Vision and Pattern Recognition · Computer Science 2025-07-10 Subrat Kishore Dutta , Xiao Zhang

Adversarial attacks against monocular depth estimation (MDE) systems pose significant challenges, particularly in safety-critical applications such as autonomous driving. Existing patch-based adversarial attacks for MDE are confined to the…

Computer Vision and Pattern Recognition · Computer Science 2024-07-25 Chenxing Zhao , Yang Li , Shihao Wu , Wenyi Tan , Shuangju Zhou , Quan Pan

Deep neural networks have been widely used in many computer vision tasks. However, it is proved that they are susceptible to small, imperceptible perturbations added to the input. Inputs with elaborately designed perturbations that can fool…

Computer Vision and Pattern Recognition · Computer Science 2020-10-29 Yusheng Zhao , Huanqian Yan , Xingxing Wei

Local feature extractors are the cornerstone of many computer vision tasks. However, their vulnerability to adversarial attacks can significantly compromise their effectiveness. This paper discusses approaches to attack sophisticated local…

Computer Vision and Pattern Recognition · Computer Science 2024-06-13 Yu Wen Pao , Li Chang Lai , Hong-Yi Lin

Compared with transferable untargeted attacks, transferable targeted adversarial attacks could specify the misclassification categories of adversarial samples, posing a greater threat to security-critical tasks. In the meanwhile, 3D…

Computer Vision and Pattern Recognition · Computer Science 2024-06-11 Yao Huang , Yinpeng Dong , Shouwei Ruan , Xiao Yang , Hang Su , Xingxing Wei

Adversarial patch attacks pose a severe threat to deep neural networks, yet most existing approaches rely on unrealistic white-box assumptions, untargeted objectives, or produce visually conspicuous patches that limit real-world…

Computer Vision and Pattern Recognition · Computer Science 2025-12-30 Roie Kazoom , Alon Goldberg , Hodaya Cohen , Ofer Hadar

Pedestrian Attribute Recognition (PAR) is an indispensable task in human-centered research and has made great progress in recent years with the development of deep neural networks. However, the potential vulnerability and anti-interference…

Computer Vision and Pattern Recognition · Computer Science 2025-05-30 Weizhe Kong , Xiao Wang , Ruichong Gao , Chenglong Li , Yu Zhang , Xing Yang , Yaowei Wang , Jin Tang

Adversarial attack on skeletal motion is a hot topic. However, existing researches only consider part of dynamic features when measuring distance between skeleton graph sequences, which results in poor imperceptibility. To this end, we…

Computer Vision and Pattern Recognition · Computer Science 2024-07-01 Feng Liu , Qing Xu , Qijian Zheng

Previous studies have shown the vulnerability of vision transformers to adversarial patches, but these studies all rely on a critical assumption: the attack patches must be perfectly aligned with the patches used for linear projection in…

Computer Vision and Pattern Recognition · Computer Science 2023-07-11 Mingzhen Shao

Adversarial attacks pose a significant threat to deep learning models, particularly in safety-critical applications like healthcare and autonomous driving. Recently, patch based attacks have demonstrated effectiveness in real-time inference…

Computer Vision and Pattern Recognition · Computer Science 2025-02-25 Prashant Shekhar , Bidur Devkota , Dumindu Samaraweera , Laxima Niure Kandel , Manoj Babu

Recently, some research show that deep neural networks are vulnerable to the adversarial attacks, the well-trainned samples or patches could be used to trick the neural network detector or human visual perception. However, these adversarial…

Computer Vision and Pattern Recognition · Computer Science 2023-12-29 Xianyi Chen , Fazhan Liu , Dong Jiang , Kai Yan