Adversarial Camouflage: Hiding Physical-World Attacks With Natural Styles
Ranjie Duan, Xingjun Ma, Yisen Wang, James Bailey, A. K. Qin, Yun Yang
Abstract
Deep neural networks (DNNs) are known to be vulnerable to adversarial examples. Existing works have mostly focused on either digital adversarial examples created via small and imperceptible perturbations, or physical-world adversarial examples created with large and less realistic distortions that are easily identified by human observers. In this paper, we propose a novel approach, called Adversarial Camouflage (AdvCam), to craft and camouflage physicalworld adversarial examples into natural styles that appear legitimate to human observers. Specifically, AdvCam transfers large adversarial perturbations into customized styles, which are then "hidden" on-target object or off-target background. Experimental evaluation shows that, in both digital and physical-world scenarios, adversarial examples crafted by AdvCam are well camouflaged and highly stealthy, while remaining effective in fooling state-of-the-art DNN image classifiers. Hence, AdvCam is a flexible approach that can help craft stealthy attacks to evaluate the robustness of DNNs. AdvCam can also be used to protect private information from being detected by deep learning systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0ec39d9e-8877-4736-bafe-c7a173dd793bCited by top-tier papers44
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural NetworksYige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu et al.ICLR 2021 · 548 citations
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey et al.ICLR 2021 · 255 citations
- Naturalistic Physical Adversarial Patch for Object DetectorsYu-Chih-Tuan Hu, Jun-Cheng Chen, Bo-Han Kung, Kai-Lung Hua et al.ICCV 2021 · 224 citations
- Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural PhenomenonYiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang et al.CVPR 2022 · 148 citations
- Revisiting Adversarial Robustness Distillation: Robust Soft Labels Make Student BetterBojia Zi, Shihao Zhao, Xingjun Ma, Yu-Gang JiangICCV 2021 · 136 citations
Builds on5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNetsDongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey et al.ICLR 2020 · 357 citations
- Hilbert-Based Generative Defense for Adversarial ExamplesYang Bai, Yan Feng, Yisen Wang, Tao Dai et al.ICCV 2019 · 62 citations
Related papers
- Dual Attention Suppression Attack: Generate Adversarial Camouflage in Physical WorldJiakai Wang, Aishan Liu, Zixin Yin, Shunchang Liu et al.CVPR 2021
- Universal Physical Camouflage Attacks on Object DetectorsLifeng Huang, Chengying Gao, Yuyin Zhou, Cihang Xie et al.CVPR 2020
- DTA: Physical Camouflage Attacks using Differentiable Transformation NetworkNaufal Suryanto, Yongsu Kim, Hyoeun Kang, Harashta Tatimma Larasati et al.CVPR 2022 · 76 citations
- Unnoticed Yet Effective: A Hybrid Physical Camouflage Framework Against DNNs and Human PerceptionMingye Xie, Jiacheng Ruan, Xian Gao, Ting Liu et al.AAAI 2026
- CNCA: Toward Customizable and Natural Generation of Adversarial Camouflage for Vehicle DetectorsLinye Lyu, Jiawei Zhou, Daojing He, Yu LiNeurIPS 2024 · 8 citations
