paper-with-me

Papers

SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image Classifiers

2020-12-10 · Bingyao Huang, Haibin Ling

Light-based adversarial attacks use spatial augmented reality (SAR) techniques to fool image classifiers by altering the physical light condition with a controllable light source, e.g., a projector. Compared with physical attacks that place hand-crafted adversarial objects, projector-based ones obviate modifying the physical entities, and can be performed transiently and dynamically by altering the projection pattern. However, subtle light perturbations are insufficient to fool image classifiers, due to the complex environment and project-and-capture process. Thus, existing approaches focus on projecting clearly perceptible adversarial patterns, while the more interesting yet challenging goal, stealthy projector-based attack, remains open. In this paper, for the first time, we formulate this problem as an end-to-end differentiable process and propose a Stealthy Projector-based Adversarial Attack (SPAA) solution. In SPAA, we approximate the real Project-and-Capture process using a deep neural network named PCNet, then we include PCNet in the optimization of projector-based attacks such that the generated adversarial projection is physically plausible. Finally, to generate both robust and stealthy adversarial projections, we propose an algorithm that uses minimum perturbation and adversarial confidence thresholds to alternate between the adversarial loss and stealthiness loss optimization. Our experimental evaluations show that SPAA clearly outperforms other methods by achieving higher attack success rates and meanwhile being stealthier, for both targeted and untargeted attacks.

📄 PDF Abstract BibTeX arXiv:2012.05858

Code (1)

bingyaohuang/spaa 공식 구현 pytorch

Tasks

Adversarial Attack

Similar Papers 제목 키워드 기반

Enhancing Targeted Adversarial Attacks on Large Vision-Language Models via Intermediate Projector

2025-08-19 · Yiming Cao, Yanjie Li, Kaisheng Liang, Bin Xiao arxiv

The growing deployment of Large Vision-Language Models (VLMs) raises safety concerns, as adversaries may exploit model vulnerabilities to induce harmful outputs, with targeted black-box adversarial attacks posing a parti…

Adversarial Catoptric Light: An Effective, Stealthy and Robust Physical-World Attack to DNNs

2022-09-19 · Chengyin Hu, Weiwen Shi

Deep neural networks (DNNs) have demonstrated exceptional success across various tasks, underscoring the need to evaluate the robustness of advanced DNNs. However, traditional methods using stickers as physical perturbat…

Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon

2022-03-08 · CVPR 2022 1 · Yiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang 외

Estimating the risk level of adversarial examples is essential for safely deploying machine learning models in the real world. One popular approach for physical-world attacks is to adopt the "sticker-pasting" strategy, w…

Adversarial AttackTraffic Sign Recognitionvalid

BppAttack: Stealthy and Efficient Trojan Attacks against Deep Neural Networks via Image Quantization and Contrastive Adversarial Learning

2022-05-26 · CVPR 2022 1 · Zhenting Wang, Juan Zhai, Shiqing Ma

Deep neural networks are vulnerable to Trojan attacks. Existing attacks use visible patterns (e.g., a patch or image transformations) as triggers, which are vulnerable to human inspection. In this paper, we propose steal…

Contrastive LearningQuantization

Semantically Stealthy Adversarial Attacks against Segmentation Models

2021-04-05 · Zhenhua Chen, Chuhua Wang, David J. Crandall

Segmentation models have been found to be vulnerable to targeted and non-targeted adversarial attacks. However, the resulting segmentation outputs are often so damaged that it is easy to spot an attack. In this paper, we…

Adversarial AttackSegmentation