Naturalistic Physical Adversarial Patch for Object Detectors

Yu Chih Tuan Hu, Bo Han Kung, Daniel Stanley Tan, Jun Cheng Chen, Kai Lung Hua, Wen Huang Cheng

研究成果: Conference contribution同行評審

90 引文 斯高帕斯(Scopus)

摘要

Most prior works on physical adversarial attacks mainly focus on the attack performance but seldom enforce any restrictions over the appearance of the generated adversarial patches. This leads to conspicuous and attention-grabbing patterns for the generated patches which can be easily identified by humans. To address this issue, we propose a method to craft physical adversarial patches for object detectors by leveraging the learned image manifold of a pretrained generative adversarial network (GAN) (e.g., BigGAN and StyleGAN) upon real-world images. Through sampling the optimal image from the GAN, our method can generate natural looking adversarial patches while maintaining high attack performance. With extensive experiments on both digital and physical domains and several independent subjective surveys, the results show that our proposed method produces significantly more realistic and natural looking patches than several state-of-the-art baselines while achieving competitive attack performance.

原文English
主出版物標題Proceedings - 2021 IEEE/CVF International Conference on Computer Vision, ICCV 2021
發行者Institute of Electrical and Electronics Engineers Inc.
頁面7828-7837
頁數10
ISBN(電子)9781665428125
DOIs
出版狀態Published - 2021
事件18th IEEE/CVF International Conference on Computer Vision, ICCV 2021 - Virtual, Online, 加拿大
持續時間: 11 10月 202117 10月 2021

出版系列

名字Proceedings of the IEEE International Conference on Computer Vision
ISSN(列印)1550-5499

Conference

Conference18th IEEE/CVF International Conference on Computer Vision, ICCV 2021
國家/地區加拿大
城市Virtual, Online
期間11/10/2117/10/21

指紋

深入研究「Naturalistic Physical Adversarial Patch for Object Detectors」主題。共同形成了獨特的指紋。

引用此