ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial Viewpoints
Yinpeng Dong, Shouwei Ruan, Hang Su, Caixin Kang, Xingxing Wei, Jun Zhu
Abstract
Recent studies have demonstrated that visual recognition models lack robustness to distribution shift. However, current work mainly considers model robustness to 2D image transformations, leaving viewpoint changes in the 3D world less explored. In general, viewpoint changes are prevalent in various real-world applications (e.g., autonomous driving), making it imperative to evaluate viewpoint robustness. In this paper, we propose a novel method called ViewFool to find adversarial viewpoints that mislead visual recognition models. By encoding real-world objects as neural radiance fields (NeRF), ViewFool characterizes a distribution of diverse adversarial viewpoints under an entropic regularizer, which helps to handle the fluctuations of the real camera pose and mitigate the reality gap between the real objects and their neural representations. Experiments validate that the common image classifiers are extremely vulnerable to the generated adversarial viewpoints, which also exhibit high cross-model transferability. Based on ViewFool, we introduce ImageNet-V, a new out-of-distribution dataset for benchmarking viewpoint robustness of image classifiers. Evaluation results on 40 classifiers with diverse architectures, objective functions, and data augmentations reveal a significant drop in model performance when tested on ImageNet-V, which provides a possibility to leverage ViewFool as an effective data augmentation strategy to improve viewpoint robustness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext afed58b7-ef5d-4918-9fa9-4709533e961eCited by top-tier papers14
- Diffusion-Based Adversarial Sample Generation for Improved Stealthiness and ControllabilityHaotian Xue, Alexandre Araujo, Bin Hu, Yongxin ChenNeurIPS 2023 · 110 citations
- Unified Adversarial Patch for Cross-modal Attacks in the Physical WorldXingxing Wei, Yao Huang, Yitong Sun, Jie YuICCV 2023 · 44 citations
- Towards Viewpoint-Invariant Visual Recognition via Adversarial TrainingShouwei Ruan, Yinpeng Dong, Hang Su, Jianteng Peng et al.ICCV 2023 · 23 citations
- Revisiting Adversarial Patches for Designing Camera-Agnostic Attacks against Person DetectionHui Wei, Zhixiang Wang, Kewei Zhang, Jiaqi Hou et al.NeurIPS 2024 · 22 citations
- Not All Views Are Created Equal: Analyzing Viewpoint Instabilities in Vision Foundation ModelsMateusz Michalkiewicz, Sheena Bai, Mahsa Baktashmotlagh, Varun Jampani et al.ICCV 2025 · 8 citations
Builds on19
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Training data-efficient image transformers & distillation through attentionHugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa et al.ICML 2021 · 8,974 citations
- Implicit Neural Representations with Periodic Activation FunctionsVincent Sitzmann, Julien N. P. Martel, Alexander W. Bergman, David B. Lindell et al.NeurIPS 2020 · 4,008 citations
- MLP-Mixer: An all-MLP Architecture for VisionIlya O. Tolstikhin, Neil Houlsby, Alexander Kolesnikov, Lucas Beyer et al.NeurIPS 2021 · 3,862 citations
Related papers
- NeRFool: Uncovering the Vulnerability of Generalizable Neural Radiance Fields against Adversarial PerturbationsYonggan Fu, Ye Yuan, Souvik Kundu, Shang Wu et al.ICML 2023 · 13 citations
- Advancing Adversarial Robustness in GNeRFs: The IL2-NeRF AttackNicole Meng, Caleb Manicke, Ronak Sahu, Caiwen Ding et al.CVPR 2025
- Aug-NeRF: Training Stronger Neural Radiance Fields with Triple-Level Physically-Grounded AugmentationsTianlong Chen, Peihao Wang, Zhiwen Fan, Zhangyang WangCVPR 2022 · 32 citations
- ReLight My NeRF: A Dataset for Novel View Synthesis and Relighting of Real World ObjectsMarco Toschi, Riccardo De Matteo, Riccardo Spezialetti, Daniele De Gregorio et al.CVPR 2023
- PNeRFLoc: Visual Localization with Point-Based Neural Radiance FieldsBoming Zhao, Luwei Yang, Mao Mao, Hujun Bao et al.AAAI 2024 · 31 citations
