paper-with-me

Papers

Robust Physical-World Attacks on Deep Learning Visual Classification

2018-06-01 · CVPR 2018 6 · Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, Dawn Song

Recent studies show that the state-of-the-art deep neural networks (DNNs) are vulnerable to adversarial examples, resulting from small-magnitude perturbations added to the input. Given that that emerging physical systems are using DNNs in safety-critical situations, adversarial examples could mislead these systems and cause dangerous situations. Therefore, understanding adversarial examples in the physical world is an important step towards developing resilient learning algorithms. We propose a general attack algorithm, Robust Physical Perturbations (RP 2 ), to generate robust visual adversarial perturbations under different physical conditions. Using the real-world case of road sign classification, we show that adversarial examples generated using RP 2 achieve high targeted misclassification rates against standard-architecture road sign classifiers in the physical world under various environmental conditions, including viewpoints. Due to the current lack of a standardized testing method, we propose a two-stage evaluation methodology for robust physical adversarial examples consisting of lab and field tests. Using this methodology, we evaluate the efficacy of physical adversarial manipulations on real objects. With a perturbation in the form of only black and white stickers, we attack a real stop sign, causing targeted misclassification in 100% of the images obtained in lab settings, and in 84.8% of the captured video frames obtained on a moving vehicle (field test) for the target classifier.

📄 PDF Abstract BibTeX

Code (0)

등록된 구현이 없습니다.

Tasks

ClassificationDeep LearningGeneral Classification

Similar Papers 제목 키워드 기반

The Outline of Deception: Physical Adversarial Attacks on Traffic Signs Using Edge Patches

2025-11-30 · Haojie Ji, Te Hu, Haowen Li, Long Jin 외 arxiv

Intelligent driving systems are vulnerable to physical adversarial attacks on traffic signs. These attacks can cause misclassification, leading to erroneous driving decisions that compromise road safety. Moreover, within…

Instance Segmentation

Challenging Vision-Language Models with Physically Deployable Multimodal Semantic Lighting Attacks

2026-04-14 · Yingying Zhao, Chengyin Hu, Qike Zhang, Xin Li 외 arxiv

Vision-Language Models (VLMs) have shown remarkable performance, yet their security remains insufficiently understood. Existing adversarial studies focus almost exclusively on the digital setting, leaving physical-world …

Visual Question AnsweringMultimodal ReasoningAdversarial AttackImage Captioning

Backdoor Attacks Against Deep Learning Systems in the Physical World

2020-06-25 · CVPR 2021 1 · Emily Wenger, Josephine Passananti, Arjun Bhagoji, Yuanshun Yao 외

Backdoor attacks embed hidden malicious behaviors into deep learning models, which only activate and cause misclassifications on model inputs containing a specific trigger. Existing works on backdoor attacks and defenses…

Deep LearningTransfer Learning

Towards Benchmarking and Assessing Visual Naturalness of Physical World Adversarial Attacks

2023-05-22 · CVPR 2023 1 · Simin Li, Shuing Zhang, Gujun Chen, Dong Wang 외

Physical world adversarial attack is a highly practical and threatening attack, which fools real world deep learning systems by generating conspicuous and maliciously crafted real world artifacts. In physical world attac…

Adversarial AttackAutonomous DrivingBenchmarking

Visually Adversarial Attacks and Defenses in the Physical World: A Survey

2022-11-03 · Xingxing Wei, Bangzheng Pu, Jiefan Lu, Baoyuan Wu

Although Deep Neural Networks (DNNs) have been widely applied in various real-world scenarios, they are vulnerable to adversarial examples. The current adversarial attacks in computer vision can be divided into digital a…

Adversarial RobustnessSurvey