Towards Irreversible Attack: Fooling Scene Text Recognition via Multi-Population Coevolution Search
Jingyu Li, Pengwen Dai, Mingqing Zhu, Chengwei Wang, Haolong Liu, Xiaochun Cao
Abstract
Recent work has shown that scene text recognition (STR) models are vulnerable to adversarial examples. Different from non-sequential vision tasks, the output sequence of STR models contains rich information. However, existing adversarial attacks against STR models can only lead to a few incorrect characters in the predicted text. These attack results still carry partial information about the original prediction and could be easily corrected by an external dictionary or a language model. Therefore, we propose the Multi-Population Coevolution Search (MPCS) method to attack each character in the image. We first decompose the global optimization objective into sub-objectives to solve the attack pixel concentration problem existing in previous attack methods. While this distributed optimization paradigm brings a new joint perturbation shift problem, we propose a novel coevolution energy function to solve it. Experiments on recent STR models show the superiority of our method. The code is available at https://github.com/Lee-Jingyu/MPCS .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on8
- Sparse-RS: A Versatile Framework for Query-Efficient Sparse Black-Box Adversarial AttacksFrancesco Croce, Maksym Andriushchenko, Naman D. Singh, Nicolas Flammarion et al.AAAI 2022 · 135 citations
- Sequence-to-Action: Grammatical Error Correction with Action Guided Sequence GenerationJiquan Li, Junliang Guo, Yongxin Zhu, Xin Sheng et al.AAAI 2022 · 29 citations
- Learning to Learn Transferable AttackShuman Fang, Jie Li, Xianming Lin, Rongrong JiAAAI 2022 · 26 citations
- A Theory of Transfer-Based Black-Box Attacks: Explanation and ImplicationsYanbo Chen, Weiwei LiuNeurIPS 2023 · 22 citations
- ProTegO: Protect Text Content against OCR Extraction AttackYanru He, Kejiang Chen, Guoqiang Chen, Zehua Ma et al.ACM MM 2023 · 7 citations
Related papers
- What Machines See Is Not What They Get: Fooling Scene Text Recognition Models With Adversarial Text ImagesXing Xu, Jiefu Chen, Jinhui Xiao, Lianli Gao et al.CVPR 2020
- Learning Optimization-based Adversarial Perturbations for Attacking Sequential Recognition ModelsXing Xu, Jiefu Chen, Jinhui Xiao, Zheng Wang et al.ACM MM 2020 · 18 citations
- Multi-Paradigm Collaborative Adversarial Attack Against Multi-Modal Large Language ModelsYuanbo Li, Tianyang Xu, Cong Hu, Tao Zhou et al.CVPR 2026 · 3 citations
- SceneTAP: Scene-Coherent Typographic Adversarial Planner against Vision-Language Models in Real-World EnvironmentsYue Cao, Yun Xing, Jie Zhang, Di Lin et al.CVPR 2025
- Context-Based Contrastive Learning for Scene Text RecognitionXinyun Zhang, Binwu Zhu, Xufeng Yao, Qi Sun et al.AAAI 2022 · 70 citations
