IMPACT: Irregular Multi-Patch Adversarial Composition Based on Two‑Phase Optimization
Zenghui Yang, Xingquan Zuo, Hai Huang, Gang Chen, Xinchao Zhao, Tianle Zhang
Abstract
Deep neural networks have become foundational in various applications but remain vulnerable to adversarial patch attacks. Crafting effective adversarial patches is inherently challenging due to the combinatorial complexity involved in jointly optimizing critical factors such as patch shape, location, number, and content. Existing approaches often simplify this optimization by addressing each factor independently, which limits their effectiveness. To tackle this significant challenge, we introduce a novel and flexible adversarial attack framework termed IMPACT (Irregular Multi-Patch Adversarial Composition based on Two-phase optimization). IMPACT uniquely enables comprehensive optimization of all essential patch factors using gradient-free methods. Specifically, we propose a novel dimensionality reduction encoding scheme that substantially lowers computational complexity while preserving expressive power. Leveraging this encoding, we further develop a two-phase optimization framework: phase 1 employs differential evolution for joint optimization of patch mask and content, while phase 2 refines patch content using an evolutionary strategy for enhanced precision. Additionally, we introduce a new aggregation algorithm explicitly designed to produce contiguous, irregular patches by merging localized regions, ensuring physical applicability. Extensive experiments demonstrate that our method significantly outperforms several state-of-the-art approaches, highlighting the critical benefit of jointly optimizing all patch factors in adversarial patch attacks. Our source code is available at https://yangzh216.github.io/IMPACT.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on12
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor et al.NeurIPS 2020 · 506 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and MaskingChong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, Prateek MittalUSENIX Security 2021 · 172 citations
Related papers
- SMP-Attack: Boosting the Transferability of Feature Importance-Based Adversarial Attack with Semantics-Aware Multi-Granularity PatchoutWen Yang, Guodong Liu, Di MingICCV 2025 · 1 citation
- ODDR: Outlier Detection & Dimension Reduction Based Defense Against Adversarial PatchesNandish Chattopadhyay, Amira Guesmi, Muhammad Abdullah Hanif, Bassem Ouni et al.ICCV 2025 · 3 citations
- CamoPatch: An Evolutionary Strategy for Generating Camoflauged Adversarial PatchesPhoenix Neale Williams, Ke LiNeurIPS 2023 · 22 citations
- Defending Physical Adversarial Attack on Object Detection via Adversarial Patch-Feature EnergyTaeheon Kim, Youngjoon Yu, Yong Man RoACM MM 2022 · 19 citations
- Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation CVPR ProceedingsPhoenix Neale Williams, Ke LiCVPR 2023
