Saliuitl: Ensemble Salience Guided Recovery of Adversarial Patches against CNNs
Mauricio Byrd Victorica, György Dán, Henrik Sandberg
Abstract
Adversarial patches are capable of misleading computer vision systems based on convolutional neural networks. Existing recovery methods suffer of at least one of three fundamental shortcomings: no information about the presence of patches in the scene, inability to efficiently handle noncontiguous patch attacks, and a strong reliance on fixed saliency thresholds. We propose Saliuitl, a recovery method independent of the number of patches and their shape, which unlike prior works, explicitly detects patch attacks before attempting recovery. In our approach, detection is based on the attributes of a binarized feature map ensemble, which is generated by using an ensemble of saliency thresholds. If an attack is detected, Saliuitl recovers clean predictions locating patches guided by an ensemble of binarized feature maps and inpainting them. We evaluate Saliuitl on widely used object detection and image classification benchmarks from the adversarial patch literature, and our results show that compared to recent state-of-the-art defenses, Saliuitl achieves a recovery rate up to 97.81 and 42.63 percentage points higher at the same rate of lost predictions for image classification and object detection, respectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on10
- A ConvNet for the 2020sZhuang Liu, Hanzi Mao, Chao-Yuan Wu, Christoph Feichtenhofer et al.CVPR 2022 · 6,782 citations
- Naturalistic Physical Adversarial Patch for Object DetectorsYu-Chih-Tuan Hu, Jun-Cheng Chen, Bo-Han Kung, Kai-Lung Hua et al.ICCV 2021 · 224 citations
- Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch DetectionJiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa et al.CVPR 2022 · 99 citations
- Adversarial Pixel Masking: A Defense against Physical Attacks for Pre-trained Object DetectorsPing-Han Chiang, Chi-Shen Chan, Shan-Hung WuACM MM 2021 · 30 citations
- ScaleCert: Scalable Certified Defense against Adversarial Patches with Sparse Superficial LayersHusheng Han, Kaidi Xu, Xing Hu, Xiaobing Chen et al.NeurIPS 2021 · 27 citations
Related papers
- Jedi: Entropy-Based Localization and Removal of Adversarial PatchesBilel Tarchoun, Anouar Ben Khalifa, Mohamed Ali Mahjoub, Nael B. Abu-Ghazaleh et al.CVPR 2023
- Defending Physical Adversarial Attack on Object Detection via Adversarial Patch-Feature EnergyTaeheon Kim, Youngjoon Yu, Yong Man RoACM MM 2022 · 19 citations
- Adversarial Patch EXterminator: Zero-Shot and Patch-Agnostic Defense Framework Against Adversarial Patch AttacksJiayimei Wang, Tao Ni, Guowen Xu, Qingchuan Zhao et al.USENIX Security 2026
- PAD: Patch-Agnostic Defense against Adversarial Patch AttacksLihua Jing, Rui Wang, Wenqi Ren, Xin Dong et al.CVPR 2024
- False Positives Matter: Multidimensional Localization Evaluation and Training-Free Explainable Adversarial Patch DefenseLihua Jing, Rui Wang, Jinwen Zhong, Runbo Li et al.AAAI 2026
