English
Related papers

Related papers: Transferable Physical-World Adversarial Patches Ag…

200 papers

We present a system for generating inconspicuous-looking textures that, when displayed in the physical world as digital or printed posters, cause visual object tracking systems to become confused. For instance, as a target being tracked by…

Robotics · Computer Science 2019-09-17 Rey Reza Wiyatno , Anqi Xu

The advancement of deep object detectors has greatly affected safety-critical fields like autonomous driving. However, physical adversarial camouflage poses a significant security risk by altering object textures to deceive detectors.…

Computer Vision and Pattern Recognition · Computer Science 2025-08-08 Jiawei Liang , Siyuan Liang , Jianjie Huang , Chenxi Si , Ming Zhang , Xiaochun Cao

Adversarial patch-based attacks have shown to be a major deterrent towards the reliable use of machine learning models. These attacks involve the strategic modification of localized patches or specific image areas to deceive trained machine…

Cryptography and Security · Computer Science 2023-11-22 Nandish Chattopadhyay , Amira Guesmi , Muhammad Abdullah Hanif , Bassem Ouni , Muhammad Shafique

Deep neural networks (DNNs) have become essential for processing the vast amounts of aerial imagery collected using earth-observing satellite platforms. However, DNNs are vulnerable towards adversarial examples, and it is expected that this…

Computer Vision and Pattern Recognition · Computer Science 2021-10-22 Andrew Du , Bo Chen , Tat-Jun Chin , Yee Wei Law , Michele Sasdelli , Ramesh Rajasegaran , Dillon Campbell

With the trend of adversarial attacks, researchers attempt to fool trained object detectors in 2D scenes. Among many of them, an intriguing new form of attack with potential real-world usage is to append adversarial patches (e.g. logos) to…

Machine Learning · Computer Science 2020-11-30 Yi Wang , Jingyang Zhou , Tianlong Chen , Sijia Liu , Shiyu Chang , Chandrajit Bajaj , Zhangyang Wang

Object detectors have emerged as an indispensable module in modern computer vision systems. In this work, we propose DPatch -- a black-box adversarial-patch-based attack towards mainstream object detectors (i.e. Faster R-CNN and YOLO).…

Computer Vision and Pattern Recognition · Computer Science 2019-04-25 Xin Liu , Huanrui Yang , Ziwei Liu , Linghao Song , Hai Li , Yiran Chen

Taking into account information across the temporal domain helps to improve environment perception in autonomous driving. However, it has not been studied so far whether temporally fused neural networks are vulnerable to deliberately…

Computer Vision and Pattern Recognition · Computer Science 2022-08-24 Svetlana Pavlitskaya , Nikolai Polley , Michael Weber , J. Marius Zöllner

Gait recognition is widely used in social security applications due to its advantages in long-distance human identification. Recently, sequence-based methods have achieved high accuracy by learning abundant temporal and spatial information.…

Computer Vision and Pattern Recognition · Computer Science 2021-08-11 Ziwen He , Wei Wang , Jing Dong , Tieniu Tan

Person re-identification is an important task and has widespread applications in video surveillance for public security. In the past few years, deep learning network with triplet loss has become popular for this problem. However, the…

Computer Vision and Pattern Recognition · Computer Science 2020-12-29 Xinglu Wang

Adversarial examples present significant challenges to the security of Deep Neural Network (DNN) applications. Specifically, there are patch-based and texture-based attacks that are usually used to craft physical-world adversarial examples,…

Computer Vision and Pattern Recognition · Computer Science 2026-04-14 Wei Zhang , Xinyu Chang , Xiao Li , Yiming Zhu , Xiaolin Hu

Adversarial robustness in LiDAR-based 3D object detection is a critical research area due to its widespread application in real-world scenarios. While many digital attacks manipulate point clouds or meshes, they often lack physical…

Computer Vision and Pattern Recognition · Computer Science 2025-07-25 Luo Cheng , Hanwei Zhang , Lijun Zhang , Holger Hermanns

Adversarial examples are perturbed inputs designed to fool machine learning models. Most recent works on adversarial examples for image classification focus on directly modifying pixels with minor perturbations. A common requirement in all…

Machine Learning · Computer Science 2018-12-27 Dan Peng , Zizhan Zheng , Xiaofeng Zhang

This demonstration presents Digital-Physical Adversarial Attacks (DiPA), a new class of practical adversarial attacks against pervasive camera-based authentication systems, where an attacker displays an adversarial patch directly on a…

Computer Vision and Pattern Recognition · Computer Science 2026-03-31 Victoria Leonenkova , Ekaterina Shumitskaya , Dmitriy Vatolin , Anastasia Antsiferova

Adversarial robustness of BEV 3D object detectors is critical for autonomous driving (AD). Existing invasive attacks require altering the target vehicle itself (e.g. attaching patches), making them unrealistic and impractical for real-world…

Computer Vision and Pattern Recognition · Computer Science 2026-03-04 Aixuan Li , Mochu Xiang , Bosen Hou , Zhexiong Wan , Jing Zhang , Yuchao Dai

Perturbation-based attacks, while not physically realizable, have been the main emphasis of adversarial machine learning (ML) research. Patch-based attacks by contrast are physically realizable, yet most work has focused on 2D domain with…

Computer Vision and Pattern Recognition · Computer Science 2021-08-17 Max Lennon , Nathan Drenkow , Philippe Burlina

Traffic sign recognition plays a critical role in ensuring safe and efficient transportation of autonomous vehicles but remain vulnerable to adversarial attacks using stickers or laser projections. While existing attack vectors demonstrate…

Cryptography and Security · Computer Science 2025-11-14 Go Tsuruoka , Takami Sato , Qi Alfred Chen , Kazuki Nomoto , Ryunosuke Kobayashi , Yuna Tanaka , Tatsuya Mori

Traffic-Sign Recognition (TSR) is a critical safety component for autonomous driving. Unfortunately, however, past work has highlighted the vulnerability of TSR models to physical-world attacks, through low-cost, easily deployable…

Cryptography and Security · Computer Science 2025-09-03 Tsufit Shua , Liron David , Mahmood Sharif

In this paper, we propose a novel physical stealth attack against the person detectors in real world. The proposed method generates an adversarial patch, and prints it on real clothes to make a three dimensional (3D) invisible cloak. Anyone…

Computer Vision and Pattern Recognition · Computer Science 2025-03-04 Mingfu Xue , Can He , Zhiyu Wu , Jian Wang , Zhe Liu , Weiqiang Liu

Detecting vehicles in aerial images is difficult due to complex backgrounds, small object sizes, shadows, and occlusions. Although recent deep learning advancements have improved object detection, these models remain susceptible to…

Computer Vision and Pattern Recognition · Computer Science 2025-09-10 Mikael Yeghiazaryan , Sai Abhishek Siddhartha Namburu , Emily Kim , Stanislav Panev , Celso de Melo , Fernando De la Torre , Jessica K. Hodgins

Standard approaches for adversarial patch generation lead to noisy conspicuous patterns, which are easily recognizable by humans. Recent research has proposed several approaches to generate naturalistic patches using generative adversarial…

Computer Vision and Pattern Recognition · Computer Science 2022-07-18 Svetlana Pavlitskaya , Bianca-Marina Codău , J. Marius Zöllner