paper-with-me

Papers

ITPatch: An Invisible and Triggered Physical Adversarial Patch against Traffic Sign Recognition

2024-09-19 · Shuai Yuan, Hongwei Li, Xingshuo Han, Guowen Xu, Wenbo Jiang, Tao Ni, Qingchuan Zhao, Yuguang Fang

Physical adversarial patches have emerged as a key adversarial attack to cause misclassification of traffic sign recognition (TSR) systems in the real world. However, existing adversarial patches have poor stealthiness and attack all vehicles indiscriminately once deployed. In this paper, we introduce an invisible and triggered physical adversarial patch (ITPatch) with a novel attack vector, i.e., fluorescent ink, to advance the state-of-the-art. It applies carefully designed fluorescent perturbations to a target sign, an attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially resulting in traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of ITPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%.

📄 PDF Abstract BibTeX arXiv:2409.12394

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackTraffic Sign Recognition

Similar Papers 제목 키워드 기반

TPatch: A Triggered Physical Adversarial Patch

2023-12-30 · Wenjun Zhu, Xiaoyu Ji, Yushi Cheng, Shibo Zhang 외

Autonomous vehicles increasingly utilize the vision-based perception module to acquire information about driving environments and detect obstacles. Correct detection and classification are important to ensure safe drivin…

Autonomous Vehicles

3D Invisible Cloak

2020-11-27 · Mingfu Xue, Can He, Zhiyu Wu, Jian Wang 외

In this paper, we propose a novel physical stealth attack against the person detectors in real world. The proposed method generates an adversarial patch, and prints it on real clothes to make a three dimensional (3D) inv…

IAP: Invisible Adversarial Patch Attack through Perceptibility-Aware Localization and Perturbation Optimization

2025-07-09 · Subrat Kishore Dutta, Xiao Zhang arxiv

Despite modifying only a small localized input region, adversarial patches can drastically change the prediction of computer vision models. However, prior methods either cannot perform satisfactorily under targeted attac…

Color Constancy

When Robots Obey the Patch: Universal Transferable Patch Attacks on Vision-Language-Action Models

2025-11-26 · Hui Lu, Yi Yu, Yiming Yang, Chenyu Yi 외 arxiv

Vision-Language-Action (VLA) models are vulnerable to adversarial attacks, yet universal and transferable attacks remain underexplored, as most existing patches overfit to a single model and fail in black-box settings. T…

Imperceptible CMOS camera dazzle for adversarial attacks on deep neural networks

2023-10-22 · Zvi Stein, Adrian Stern

Despite the outstanding performance of deep neural networks, they are vulnerable to adversarial attacks. While there are many invisible attacks in the digital domain, most physical world adversarial attacks are visible. …

Adversarial Attack