Latency NMS Attacks: Is It Real Life or Is It Just Fantasy?
Jean-Philippe Monteuuis, Cong Chen, Jonathan Petit
Abstract
“Caught in a landslide, no escape from reality" summarizes the state of the research in AI offense: an attack might work on paper but does not necessarily in practice. In the last 5 years, we have seen the rise of latency attacks against computer vision systems. Most of them targeted 2D object detection, especially its Non-Max-Suppression (NMS) block, via adversarial images. However, we uncovered that, when tested in realistic deployment settings, the NMS latency attacks, accepted to top conferences, have very limited negative effects. In this paper, we define an evaluation framework (EVADE) to assess the practicality of attacks, and apply it to state-of-the-art NMS latency attacks. Attacks were tested on different hardware platforms, and different model formats and quantization. Results show that these attacks are not able to generate the claimed latency increase, nor transfer to other models (from the same family or not). Moreover, the latency increases remain within the latency requirements of downstream tasks in our evaluation, suggesting limited practical impact under these conditions. We also tested three defenses, which were successful in mitigating the NMS latency attacks. Therefore, in their current form, NMS latency attacks are just fantasy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on4
- Overload: Latency Attacks on Object Detection for Edge DevicesErh-Chung Chen, Pin-Yu Chen, I-Hsin Chung, Che-Rung LeeCVPR 2024
- Understanding and Enhancing the Transferability of Jailbreaking AttacksRunqi Lin, Bo Han, Fengwang Li, Tongliang LiuICLR 2025
- Durable Quantization Conditioned Misalignment Attack on Large Language ModelsPeiran Dong, Haowei Li, Song GuoICLR 2025
- Investigating Physical Latency Attacks Against Camera-Based PerceptionRaymond Muller, Ruoyu Song, Chenyi Wang, Yuxia Zhan et al.S&P 2025
Related papers
- Can't Slow Me Down: Learning Robust and Hardware-Adaptive Object Detectors against Latency Attacks for Edge DevicesTianyi Wang, Zichen Wang, Cong Wang, Yuanchao Shu et al.CVPR 2025
- SlowPerception: Physical-World Latency Attack against Camera-based Perception in Autonomous DrivingChen Ma, Ningfei Wang, Zhengyu Zhao, Qian Wang et al.CCS 2026 · 5 citations
- SlowTrack: Increasing the Latency of Camera-Based Perception in Autonomous Driving Using Adversarial ExamplesChen Ma, Ningfei Wang, Qi Alfred Chen, Chao ShenAAAI 2024 · 44 citations
- On The Empirical Effectiveness of Unrealistic Adversarial Hardening Against Realistic Adversarial AttacksSalijona Dyrmishi, Salah Ghamizi, Thibault Simonetto, Yves Le Traon et al.S&P 2023
- Phantom: Physical Object Interactions as Dynamic Triggers for NMS-Exploited BackdoorsTianlin Huo, Dongchuan Ran, Ranjie Duan, Yao Zhu et al.CVPR 2026
