Harnessing Perceptual Adversarial Patches for Crowd Counting
Shunchang Liu, Jiakai Wang, Aishan Liu, Yingwei Li, Yijie Gao, Xianglong Liu, Dacheng Tao
Abstract
Crowd counting, which has been widely adopted for estimating the number of people in safety-critical scenes, is shown to be vulnerable to adversarial examples in the physical world (e.g., adversarial patches). Though harmful, adversarial examples are also valuable for evaluating and better understanding model robustness. However, existing adversarial example generation methods for crowd counting lack strong transferability among different black-box models, which limits their practicability for real-world systems. Motivated by the fact that attacking transferability is positively correlated to the model-invariant characteristics, this paper proposes the Perceptual Adversarial Patch (PAP) generation framework to tailor the adversarial perturbations for crowd counting scenes using the model-shared perceptual features. Specifically, we handcraft an adaptive crowd density weighting approach to capture the invariant scale perception features across various models and utilize the density guided attention to capture the model-shared position perception. Both of them are demonstrated to improve the attacking transferability of our adversarial patches. Extensive experiments show that our PAP could achieve state-of-the-art attacking performance in both the digital and physical world, and outperform previous proposals by large margins (at most +685.7 MAE and +699.5 MSE). Besides, we empirically demonstrate that adversarial training with our PAP can benefit the performance of vanilla models in alleviating several practical challenges in crowd counting scenarios, including generalization across datasets (up to -376.0 MAE and -354.9 MSE) and robustness towards complex backgrounds (up to -10.3 MAE and -16.4 MSE).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fccccedc-f291-48c8-9386-66424eb4d88dCited by top-tier papers14
- PTQ4SAM: Post-Training Quantization for Segment AnythingChengtao Lv, Hong Chen, Jinyang Guo, Yifu Ding et al.CVPR 2024 · 22 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- NAPGuard: Towards Detecting Naturalistic Adversarial PatchesSiyang Wu, Jiakai Wang, Jiejie Zhao, Yazhe Wang et al.CVPR 2024 · 11 citations
- Exploring Inconsistent Knowledge Distillation for Object Detection with Data AugmentationJiawei Liang, Siyuan Liang, Aishan Liu, Ke Ma et al.ACM MM 2023 · 8 citations
- Isolation and Induction: Training Robust Deep Neural Networks against Model Stealing AttacksJun Guo, Xingyu Zheng, Aishan Liu, Siyuan Liang et al.ACM MM 2023 · 8 citations
Builds on15
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- Nesterov Accelerated Gradient and Scale Invariance for Adversarial AttacksJiadong Lin, Chuanbiao Song, Kun He, Liwei Wang et al.ICLR 2020 · 765 citations
- Bayesian Loss for Crowd Count Estimation With Point SupervisionZhiheng Ma, Xing Wei, Xiaopeng Hong, Yihong GongICCV 2019 · 612 citations
- Distribution Matching for Crowd CountingBoyu Wang, Huidong Liu, Dimitris Samaras, Minh Hoai NguyenNeurIPS 2020 · 443 citations
Related papers
- Towards Adversarial Patch Analysis and Certified Defense against Crowd CountingQiming Wu, Zhikang Zou, Pan Zhou, Xiaoqing Ye et al.ACM MM 2021 · 2 citations
- Generative Adversarial Perturbations with Cross-paradigm Transferability on Localized Crowd CountingAlabi Mehzabin Anisha, Guangjing Wang, Sriram ChellappanCVPR 2026 · 1 citation
- Improving Transferability of Adversarial Patches on Face Recognition With Generative ModelsZihao Xiao, Xianfeng Gao, Chilin Fu, Yinpeng Dong et al.CVPR 2021
- Dual Attention Suppression Attack: Generate Adversarial Camouflage in Physical WorldJiakai Wang, Aishan Liu, Zixin Yin, Shunchang Liu et al.CVPR 2021
- Generating Transferable Adversarial Examples against Vision TransformersYuxuan Wang, Jiakai Wang, Zixin Yin, Ruihao Gong et al.ACM MM 2022 · 25 citations
