BadPart: Unified Black-box Adversarial Patch Attacks against Pixel-wise Regression Tasks
Zhiyuan Cheng, Zhaoyi Liu, Tengda Guo, Shiwei Feng, Dongfang Liu, Mingjie Tang, Xiangyu Zhang
Abstract
Pixel-wise regression tasks (e.g., monocular depth estimation (MDE) and optical flow estimation (OFE)) have been widely involved in our daily life in applications like autonomous driving, augmented reality and video composition. Although certain applications are security-critical or bear societal significance, the adversarial robustness of such models are not sufficiently studied, especially in the black-box scenario. In this work, we introduce the first unified black-box adversarial patch attack framework against pixel-wise regression tasks, aiming to identify the vulnerabilities of these models under query-based black-box attacks. We propose a novel square-based adversarial patch optimization framework and employ probabilistic square sampling and score-based gradient estimation techniques to generate the patch effectively and efficiently, overcoming the scalability problem of previous black-box patch attacks. Our attack prototype, named BadPart, is evaluated on both MDE and OFE tasks, utilizing a total of 7 models. BadPart surpasses 3 baseline methods in terms of both attack performance and efficiency. We also apply BadPart on the Google online service for portrait depth estimation, causing 43.5% relative distance error with 50K queries. State-of-the-art (SOTA) countermeasures cannot defend our attack effectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- TAI3: Testing Agent Integrity in Interpreting User IntentShiwei Feng, Xiangzhe Xu, Xuan Chen, Kaiyuan Zhang et al.NeurIPS 2025 · 9 citations
- AT-Field: Rethinking the Games in Adversarial TrainingYixiao Xu, Mohan Li, Zhijie Shen, Yuan Liu et al.AAAI 2026
Builds on26
- Digging Into Self-Supervised Monocular Depth EstimationClément Godard, Oisin Mac Aodha, Michael Firman, Gabriel J. BrostowICCV 2019 · 2,416 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNetsDongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey et al.ICLR 2020 · 357 citations
- Feature Importance-aware Transferable Adversarial AttacksZhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu et al.ICCV 2021 · 306 citations
- Self-Supervised Monocular Depth HintsJamie Watson, Michael Firman, Gabriel J. Brostow, Daniyar TurmukhambetovICCV 2019 · 287 citations
Related papers
- BRP: Query-Efficient Block Revert Patch for Decision-Based Black-Box Adversarial AttackZenghui Yang, Xingquan Zuo, Gang Chen, Hai Huang et al.KDD 2026
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 93 citations
- DepthCloak: Projecting Optical Camouflage Patches for Erroneous Monocular Depth Estimation of VehiclesHuixiang Wen, Shizong Yan, Shan Chang, Jie Xu et al.ACM MM 2024 · 2 citations
- Beware of Road Markings: A New Adversarial Patch Attack to Monocular Depth EstimationHangcheng Liu, Zhenhu Wu, Hao Wang, Xingshuo Han et al.NeurIPS 2024 · 13 citations
- Towards Understanding Adversarial Robustness of Optical Flow NetworksSimon Schrodi, Tonmoy Saikia, Thomas BroxCVPR 2022 · 14 citations
