paper-with-me

Papers

Defenses Against Multi-Sticker Physical Domain Attacks on Classifiers

2021-01-26 · Xinwei Zhao, Matthew C. Stamm

Recently, physical domain adversarial attacks have drawn significant attention from the machine learning community. One important attack proposed by Eykholt et al. can fool a classifier by placing black and white stickers on an object such as a road sign. While this attack may pose a significant threat to visual classifiers, there are currently no defenses designed to protect against this attack. In this paper, we propose new defenses that can protect against multi-sticker attacks. We present defensive strategies capable of operating when the defender has full, partial, and no prior information about the attack. By conducting extensive experiments, we show that our proposed defenses can outperform existing defenses against physical attacks when presented with a multi-sticker attack.

📄 PDF Abstract BibTeX arXiv:2101.11060

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Infrared Adversarial Car Stickers

2024-05-16 · CVPR 2024 1 · Xiaopei Zhu, Yuqiu Liu, Zhanhao Hu, Jianmin Li 외

Infrared physical adversarial examples are of great significance for studying the security of infrared AI systems that are widely used in our lives such as autonomous driving. Previous infrared physical attacks mainly fo…

Autonomous DrivingPedestrian Detection

Towards an End-to-End (E2E) Adversarial Learning and Application in the Physical World

2025-01-14 · Dudi Biton, Jacob Shams, Satoru Koda, Asaf Shabtai 외

The traditional learning process of patch-based adversarial attacks, conducted in the digital domain and then applied in the physical domain (e.g., via printed stickers), may suffer from reduced performance due to advers…

Adversarial Sticker: A Stealthy Attack Method in the Physical World

2021-04-14 · Xingxing Wei, Ying Guo, Jie Yu

To assess the vulnerability of deep learning in the physical world, recent works introduce adversarial patches and apply them on different tasks. In this paper, we propose another kind of adversarial patch: the Meaningfu…

Face RecognitionImage RetrievalPositionRetrieval+2

Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection

2026-07-25 · Qiucheng Yu, Tao Ni, Yihe Zhou, Jiayimei Wang 외 arxiv

Deep learning-based visual-infrared fused face detection models are increasingly deployed across a wide range of applications, yet they remain susceptible to adversarial patch attacks. Most prior attacks target either th…

Face Detection

Robust Attacks on Deep Learning Face Recognition in the Physical World

2020-11-27 · Meng Shen, Hao Yu, Liehuang Zhu, Ke Xu 외

Deep neural networks (DNNs) have been increasingly used in face recognition (FR) systems. Recent studies, however, show that DNNs are vulnerable to adversarial examples, which can potentially mislead the FR systems using…

Deep LearningFace Recognition