Towards Adversarial Patch Analysis and Certified Defense against Crowd Counting
Qiming Wu, Zhikang Zou, Pan Zhou, Xiaoqing Ye, Binghui Wang, Ang Li
Abstract
Crowd counting has drawn much attention due to its importance in safety-critical surveillance systems. Especially, deep neural network (DNN) methods have significantly reduced estimation errors for crowd counting missions. Recent studies have demonstrated that DNNs are vulnerable to adversarial attacks, i.e., normal images with human-imperceptible perturbations could mislead DNNs to make false predictions. In this work, we propose a robust attack strategy called Adversarial Patch Attack with Momentum (APAM) to systematically evaluate the robustness of crowd counting models, where the attacker's goal is to create an adversarial perturbation that severely degrades their performances, thus leading to public safety accidents (e.g., stampede accidents). Especially, the proposed attack leverages the extreme-density background information of input images to generate robust adversarial patches via a series of transformations (e.g., interpolation, rotation, etc.). We observe that by perturbing less than 6% of image pixels, our attacks severely degrade the performance of crowd counting systems, both digitally and physically. To better enhance the adversarial robustness of crowd counting models, we propose the first regression model-based Randomized Ablation (RA), which is more sufficient than Adversarial Training (ADT) (Mean Absolute Error of RA is 5 lower than ADT on clean samples and 30 lower than ADT on adversarial examples). Extensive experiments on five crowd counting models demonstrate the effectiveness and generality of the proposed method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Rethinking Spatial Invariance of Convolutional Networks for Object CountingZhi-Qi Cheng, Qi Dai, Hong Li, Jingkuan Song et al.CVPR 2022 · 119 citations
- Harnessing Perceptual Adversarial Patches for Crowd CountingShunchang Liu, Jiakai Wang, Aishan Liu, Yingwei Li et al.CCS 2022 · 26 citations
- Backdoor Attacks on Crowd CountingYuhua Sun, Tailai Zhang, Xingjun Ma, Pan Zhou et al.ACM MM 2022 · 11 citations
- Generative Adversarial Perturbations with Cross-paradigm Transferability on Localized Crowd CountingAlabi Mehzabin Anisha, Guangjing Wang, Sriram ChellappanCVPR 2026 · 1 citation
Builds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- Bayesian Loss for Crowd Count Estimation With Point SupervisionZhiheng Ma, Xing Wei, Xiaopeng Hong, Yihong GongICCV 2019 · 612 citations
- Crowd Counting With Deep Structured Scale Integration NetworkLingbo Liu, Zhilin Qiu, Guanbin Li, Shufan Liu et al.ICCV 2019 · 254 citations
Related papers
- Adversarial Pixel Masking: A Defense against Physical Attacks for Pre-trained Object DetectorsPing-Han Chiang, Chi-Shen Chan, Shan-Hung WuACM MM 2021 · 30 citations
- PatchBackdoor: Backdoor Attack against Deep Neural Networks without Model ModificationYizhen Yuan, Rui Kong, Shenghao Xie, Yuanchun Li et al.ACM MM 2023 · 12 citations
- Towards Million-Scale Adversarial Robustness Evaluation With Stronger Individual AttacksYong Xie, Weijie Zheng, Hanxun Huang, Guangnan Ye et al.CVPR 2025
- Adversarial Parameter Attack on Deep Neural NetworksLijia Yu, Yihan Wang, Xiao-Shan GaoICML 2023 · 11 citations
- Improving the Transferability of Adversarial Samples With Adversarial TransformationsWeibin Wu, Yuxin Su, Michael R. Lyu, Irwin KingCVPR 2021
