paper-with-me

홈 › Papers

Towards Powerful and Practical Patch Attacks for 2D Object Detection in Autonomous Driving

2025-08-14 · Yuxin Cao, Yedi Zhang, Wentao He, Yifan Liao, Yan Xiao, Chang Li, Zhiyong Huang, Jin Song Dong arxiv

Learning-based autonomous driving systems remain critically vulnerable to adversarial patches, posing serious safety and security risks in their real-world deployment. Black-box attacks, notable for their high attack success rate without model knowledge, are especially concerning, with their transferability extensively studied to reduce computational costs compared to query-based attacks. Previous transferability-based black-box attacks typically adopt mean Average Precision (mAP) as the evaluation metric and design training loss accordingly. However, due to the presence of multiple detected bounding boxes and the relatively lenient Intersection over Union (IoU) thresholds, the attack effectiveness of these approaches is often overestimated, resulting in reduced success rates in practical attacking scenarios. Furthermore, patches trained on low-resolution data often fail to maintain effectiveness on high-resolution images, limiting their transferability to autonomous driving datasets. To fill this gap, we propose P$^3$A, a Powerful and Practical Patch Attack framework for 2D object detection in autonomous driving, specifically optimized for high-resolution datasets. First, we introduce a novel metric, Practical Attack Success Rate (PASR), to more accurately quantify attack effectiveness with greater relevance for pedestrian safety. Second, we present a tailored Localization-Confidence Suppression Loss (LCSL) to improve attack transferability under PASR. Finally, to maintain the transferability for high-resolution datasets, we further incorporate the Probabilistic Scale-Preserving Padding (PSPP) into the patch attack pipeline as a data preprocessing step. Extensive experiments show that P$^3$A outperforms state-of-the-art attacks on unseen models and unseen high-resolution datasets, both under the proposed practical IoU-based evaluation metric and the previous mAP-based metrics.

📄 PDF Abstract BibTeX arXiv:2508.10600

Code (0)

등록된 구현이 없습니다.

Tasks

2D Object DetectionAutonomous Driving

Similar Papers 제목 키워드 기반

Real-Time Robust Video Object Detection System Against Physical-World Adversarial Attacks

2022-08-19 · Husheng Han, Xing Hu, Kaidi Xu, Pucheng Dang 외

DNN-based video object detection (VOD) powers autonomous driving and video surveillance industries with rising importance and promising opportunities. However, adversarial patch attack yields huge concern in live vision …

Adversarial AttackAutonomous DrivingFeature ImportanceObject+3

Eigenpatches -- Adversarial Patches from Principal Components

2023-06-19 · Jens Bayer, Stefan Becker, David Münch, Michael Arens

Adversarial patches are still a simple yet powerful white box attack that can be used to fool object detectors by suppressing possible detections. The patches of these so-called evasion attacks are computational expensiv…

Object

DisPatch: Disarming Adversarial Patches in Object Detection with Diffusion Models

2025-09-04 · Jin Ma, Mohammed Aldeen, Christopher Salas, Feng Luo 외 arxiv

Object detection is fundamental to various real-world applications, such as security monitoring and surveillance video analysis. Despite their advancements, state-of-the-art object detectors are still vulnerable to adver…

Object Detection

Breaking the Illusion: Real-world Challenges for Adversarial Patches in Object Detection

2024-10-23 · Jakob Shack, Katarina Petrovic, Olga Saukh

Adversarial attacks pose a significant threat to the robustness and reliability of machine learning systems, particularly in computer vision applications. This study investigates the performance of adversarial patches fo…

object-detectionObject Detection

Developing Imperceptible Adversarial Patches to Camouflage Military Assets From Computer Vision Enabled Technologies

2022-02-17 · Chris Wise, Jo Plested

Convolutional neural networks (CNNs) have demonstrated rapid progress and a high level of success in object detection. However, recent evidence has highlighted their vulnerability to adversarial attacks. These attacks ar…

Objectobject-detectionObject Detection