paper-with-me

Papers

Physical Passive Patch Adversarial Attacks on Visual Odometry Systems

2022-07-11 · Yaniv Nemcovsky, Matan Jacoby, Alex M. Bronstein, Chaim Baskin

Deep neural networks are known to be susceptible to adversarial perturbations -- small perturbations that alter the output of the network and exist under strict norm limitations. While such perturbations are usually discussed as tailored to a specific input, a universal perturbation can be constructed to alter the model's output on a set of inputs. Universal perturbations present a more realistic case of adversarial attacks, as awareness of the model's exact input is not required. In addition, the universal attack setting raises the subject of generalization to unseen data, where given a set of inputs, the universal perturbations aim to alter the model's output on out-of-sample data. In this work, we study physical passive patch adversarial attacks on visual odometry-based autonomous navigation systems. A visual odometry system aims to infer the relative camera motion between two corresponding viewpoints, and is frequently used by vision-based autonomous navigation systems to estimate their state. For such navigation systems, a patch adversarial perturbation poses a severe security issue, as it can be used to mislead a system onto some collision course. To the best of our knowledge, we show for the first time that the error margin of a visual odometry model can be significantly increased by deploying patch adversarial attacks in the scene. We provide evaluation on synthetic closed-loop drone navigation data and demonstrate that a comparable vulnerability exists in real data. A reference implementation of the proposed method and the reported experiments is provided at https://github.com/patchadversarialattacks/patchadversarialattacks.

📄 PDF Abstract BibTeX arXiv:2207.05729

Code (1)

patchadversarialattacks/patchadversarialattacks 공식 구현 pytorch

Tasks

Autonomous NavigationDrone navigationVisual Odometry

Similar Papers 제목 키워드 기반

Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection

2026-07-25 · Qiucheng Yu, Tao Ni, Yihe Zhou, Jiayimei Wang 외 arxiv

Deep learning-based visual-infrared fused face detection models are increasingly deployed across a wide range of applications, yet they remain susceptible to adversarial patch attacks. Most prior attacks target either th…

Face Detection

Scratched Lenses, Shifted Depth: Passive Camera-Side Optical Attacks

2026-06-12 · Qinlin He, Zeming Zhuang, Yongji Wu, Lan Zhang 외 arxiv

Physical adversarial attacks on vision systems are typically studied through scene manipulation, such as adversarial patches or projections, where the adversary controls what the camera observes. Camera-side attacks usin…

Monocular 3D Object DetectionMonocular Depth Estimation

MAGIC: Mastering Physical Adversarial Generation in Context through Collaborative LLM Agents

2024-12-11 · Yun Xing, Nhat Chung, Jie Zhang, Yue Cao 외

Physical adversarial attacks in driving scenarios can expose critical vulnerabilities in visual perception models. However, developing such attacks remains challenging due to diverse real-world backgrounds and the requir…

object-detectionObject DetectionPrompt EngineeringScene Understanding

Towards Physically Realizable Adversarial Attacks in Embodied Vision Navigation

2024-09-16 · Meng Chen, Jiawei Tu, Chao Qi, Yonghao Dang 외

The significant advancements in embodied vision navigation have raised concerns about its susceptibility to adversarial attacks exploiting deep neural networks. Investigating the adversarial robustness of embodied vision…

Adversarial Robustnessobject-detectionObject Detection

Empirical Evaluation of Physical Adversarial Patch Attacks Against Overhead Object Detection Models

2022-06-25 · Gavin S. Hartnett, Li Ang Zhang, Caolionn O'Connell, Andrew J. Lohn 외

Adversarial patches are images designed to fool otherwise well-performing neural network-based computer vision models. Although these attacks were initially conceived of and studied digitally, in that the raw pixel value…

object-detectionObject Detection