Physically Adversarial Infrared Patches with Learnable Shapes and Locations
Xingxing Wei, Jie Yu, Yao Huang
Abstract
Owing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are complicated to implement in practical application because of their complex transformation from digital world to physical world. To address this issue, in this paper, we propose a physically feasible infrared attack method called “adversarial infrared patches”. Considering the imaging mechanism of infrared cameras by capturing objects' thermal radiation, adversarial infrared patches conduct attacks by attaching a patch of thermal insulation materials on the target object to manipulate its thermal distribution. To enhance adversarial attacks, we present a novel aggregation regularization to guide the simultaneous learning for the patch’ shape and location on the target object. Thus, a simple gradient-based optimization can be adapted to solve for them. We verify adversarial infrared patches in different object detection tasks with various object detectors. Experimental results show that our method achieves more than 90% Attack Success Rate (ASR) versus the pedestrian detector and vehicle detector in the physical environment, where the objects are captured in different angles, distances, postures, and scenes. More importantly, adversarial infrared patch is easy to implement, and it only needs 0.5 hours to be constructed in the physical world, which verifies its effectiveness and efficiency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 93e44371-3570-4723-ba7a-fa3ed853d04eCited by top-tier papers20
- Unified Adversarial Patch for Cross-modal Attacks in the Physical WorldXingxing Wei, Yao Huang, Yitong Sun, Jie YuICCV 2023 · 44 citations
- NumbOD: A Spatial-Frequency Fusion Attack Against Object DetectorsZiqi Zhou, Bowen Li, Yufei Song, Zhifei Yu et al.AAAI 2025 · 20 citations
- Physical Backdoor: Towards Temperature-Based Backdoor Attacks in the Physical WorldWen Yin, Jian Lou, Pan Zhou, Yulai Xie et al.CVPR 2024 · 9 citations
- CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared DetectorsJiahuan Long, Wen Yao, Tingsong Jiang, Jiacheng Hou et al.ACM MM 2025 · 7 citations
- Feature-Level Adversarial Attacks and Ranking Disruption for Visible-Infrared Person Re-identificationXi Yang, Huanling Liu, De Cheng, Nannan Wang et al.NeurIPS 2024 · 6 citations
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Fooling Thermal Infrared Pedestrian Detectors in Real World Using Small BulbsXiaopei Zhu, Xiao Li, Jianmin Li, Zheyao Wang et al.AAAI 2021 · 108 citations
- Random Noise Defense Against Query-Based Black-Box AttacksZeyu Qin, Yanbo Fan, Hongyuan Zha, Baoyuan WuNeurIPS 2021 · 78 citations
Related papers
- Infrared Adversarial Car StickersXiaopei Zhu, Yuqiu Liu, Zhanhao Hu, Jianmin Li et al.CVPR 2024 · 2 citations
- Unleashing the Representational Power of Fourier Shapes for Attacking Infrared Object DetectionYixing Yong, Jian Wang, Ming Lei, Lijun He et al.ICML 2026
- Infrared Invisible Clothing: Hiding from Infrared Detectors at Multiple Angles in Real WorldXiaopei Zhu, Zhanhao Hu, Siyuan Huang, Jianmin Li et al.CVPR 2022 · 67 citations
- Targeted Physical Evasion Attacks in the Near-Infrared DomainPascal Zimmer, Simon Lachnit, Alexander Jan Zielinski, Ghassan KarameNDSS 2026
- AdvDisplay: Adversarial Display Assembled by Thermoelectric Cooler for Fooling Thermal Infrared DetectorsHao Li, Fanggao Wan, Yue Su, Yue Wu et al.AAAI 2025
