Defending against Universal Adversarial Patches by Clipping Feature Norms
Cheng Yu, Jiansheng Chen, Youze Xue, Yuyang Liu, Weitao Wan, Jiayu Bao, Huimin Ma
Abstract
Physical-world adversarial attacks based on universal adversarial patches have been proved to be able to mislead deep convolutional neural networks (CNNs), exposing the vulnerability of real-world visual classification systems based on CNNs. In this paper, we empirically reveal and mathematically explain that the universal adversarial patches usually lead to deep feature vectors with very large norms in popular CNNs. Inspired by this, we propose a simple yet effective defending approach using a new feature norm clipping (FNC) layer which is a differentiable module that can be flexibly inserted in different CNNs to adaptively suppress the generation of large norm deep feature vectors. FNC introduces no trainable parameter and only very low computational overhead. However, experiments on multiple datasets validate that it can effectively improve the robustness of different CNNs towards white-box universal patch attacks while maintaining a satisfactory recognition accuracy for clean samples.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- NNSplitter: An Active Defense Solution for DNN Model via Automated Weight ObfuscationTong Zhou, Yukui Luo, Shaolei Ren, Xiaolin XuICML 2023 · 30 citations
- Democratic Training Against Universal Adversarial PerturbationsBing Sun, Jun Sun, Wei ZhaoICLR 2025
- PAD: Patch-Agnostic Defense against Adversarial Patch AttacksLihua Jing, Rui Wang, Wenqi Ren, Xin Dong et al.CVPR 2024
- PBCAT: Patch-Based Composite Adversarial Training Against Physically Realizable Attacks on Object DetectionXiao Li, Yiming Zhu, Yifan Huang, Wei Zhang et al.ICCV 2025
- Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign PerceptionTakami Sato, Sri Hrushikesh Varma Bhupathiraju, Michael Clifford, Takeshi Sugawara et al.NDSS 2024
Builds on6
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Certified Defenses for Adversarial PatchesPing-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu et al.ICLR 2020 · 194 citations
- Defending Against Physically Realizable Attacks on Image ClassificationTong Wu, Liang Tong, Yevgeniy VorobeychikICLR 2020 · 143 citations
- Transferable, Controllable, and Inconspicuous Adversarial Attacks on Person Re-identification With Deep Mis-RankingHongjun Wang, Guangrun Wang, Ya Li, Dongyu Zhang et al.CVPR 2020
- Universal Physical Camouflage Attacks on Object DetectorsLifeng Huang, Chengying Gao, Yuyin Zhou, Cihang Xie et al.CVPR 2020
Related papers
- I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object DetectorsZijin Lin, Yue Zhao, Kai Chen, Jinwen HeCCS 2024 · 4 citations
- A Unified, Resilient, and Explainable Adversarial Patch DetectorVishesh Kumar, Akshay AgarwalCVPR 2025
- Large Norms of CNN Layers Do Not Hurt Adversarial RobustnessYouwei Liang, Dong HuangAAAI 2021 · 13 citations
- Adversarial Pixel Masking: A Defense against Physical Attacks for Pre-trained Object DetectorsPing-Han Chiang, Chi-Shen Chan, Shan-Hung WuACM MM 2021 · 30 citations
- Improving Transferability of Adversarial Patches on Face Recognition With Generative ModelsZihao Xiao, Xianfeng Gao, Chilin Fu, Yinpeng Dong et al.CVPR 2021
