Towards Benchmarking and Assessing Visual Naturalness of Physical World Adversarial Attacks
Simin Li, Shuning Zhang, Gujun Chen, Dong Wang, Pu Feng, Jiakai Wang, Aishan Liu, Xin Yi, Xianglong Liu
Abstract
Physical world adversarial attack is a highly practical and threatening attack, which fools real world deep learning systems by generating conspicuous and maliciously crafted real world artifacts. In physical world attacks, evaluating naturalness is highly emphasized since human can easily detect and remove unnatural attacks. However, current studies evaluate naturalness in a case-by-case fashion, which suffers from errors, bias and inconsistencies. In this paper, we take the first step to benchmark and assess visual naturalness of physical world attacks, taking autonomous driving scenario as the first attempt. First, to benchmark attack naturalness, we contribute the first Physical Attack Naturalness (PAN) dataset with human rating and gaze. PAN verifies several insights for the first time: naturalness is (disparately) affected by contextual features (i.e., environmental and semantic variations) and correlates with behavioral feature (i.e., gaze signal). Second, to automatically assess attack naturalness that aligns with human ratings, we further introduce Dual Prior Alignment (DPA) network, which aims to embed human knowledge into model reasoning process. Specifically, DPA imitates human reasoning in naturalness assessment by rating prior alignment and mimics human gaze behavior by attentive prior alignment. We hope our work fosters researches to improve and automatically assess naturalness of physical world attacks. Our code and dataset can be found at https://github.com/zhangsn-19/PAN .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f43ae87-0c58-4937-9fd6-5ee23c97d35fCited by top-tier papers6
- ADBA: Approximation Decision Boundary Approach for Black-Box Adversarial AttacksFeiyang Wang, Xingquan Zuo, Hai Huang, Gang ChenAAAI 2025 · 14 citations
- NAPGuard: Towards Detecting Naturalistic Adversarial PatchesSiyang Wu, Jiakai Wang, Jiejie Zhao, Yazhe Wang et al.CVPR 2024 · 11 citations
- Isolation and Induction: Training Robust Deep Neural Networks against Model Stealing AttacksJun Guo, Xingyu Zheng, Aishan Liu, Siyuan Liang et al.ACM MM 2023 · 8 citations
- LanEvil: Benchmarking the Robustness of Lane Detection to Environmental IllusionsTianyuan Zhang, Lu Wang, Hainan Li, Yisong Xiao et al.ACM MM 2024 · 7 citations
- Efficient Model Stealing Defense with Noise Transition MatrixDong-Dong Wu, Chilin Fu, Weichang Wu, Wenwen Xia et al.CVPR 2024 · 2 citations
Builds on15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 217 citations
- Adversarial Examples Make Strong PoisonsLiam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping et al.NeurIPS 2021 · 185 citations
- Frequency-driven Imperceptible Adversarial Attack on Semantic SimilarityCheng Luo, Qinliang Lin, Weicheng Xie, Bizhu Wu et al.CVPR 2022 · 132 citations
Related papers
- PhysGAN: Generating Physical-World-Resilient Adversarial Examples for Autonomous DrivingZelun Kong, Junfeng Guo, Ang Li, Cong LiuCVPR 2020
- Laser Shield: a Physical Defense with Polarizer against Laser Attacks on Autonomous Driving SystemsQingjie Zhang, Lijun Chi, Di Wang, Mounira Msahli et al.DAC 2024 · 3 citations
- Dual Attention Suppression Attack: Generate Adversarial Camouflage in Physical WorldJiakai Wang, Aishan Liu, Zixin Yin, Shunchang Liu et al.CVPR 2021
- 3D Gaussian Splatting Driven Multi-View Robust Physical Adversarial Camouflage GenerationTianrui Lou, Xiaojun Jia, Siyuan Liang, Jiawei Liang et al.ICCV 2025 · 2 citations
- Legitimate Adversarial Patches: Evading Human Eyes and Detection Models in the Physical WorldJia Tan, Nan Ji, Haidong Xie, Xueshuang XiangACM MM 2021 · 44 citations
