Unified Adversarial Patch for Cross-modal Attacks in the Physical World
Xingxing Wei, Yao Huang, Yitong Sun, Jie Yu
摘要
Recently, physical adversarial attacks have been presented to evade DNNs-based object detectors. To ensure the security, many scenarios are simultaneously deployed with visible sensors and infrared sensors, leading to the failures of these single-modal physical attacks. To show the potential risks under such scenes, we propose a unified adversarial patch to perform cross-modal physical attacks, i.e., fooling visible and infrared object detectors at the same time via a single patch. Considering different imaging mechanisms of visible and infrared sensors, our work focuses on modeling the shapes of adversarial patches, which can be captured in different modalities when they change. To this end, we design a novel boundary-limited shape optimization to achieve the compact and smooth shapes, and thus they can be easily implemented in the physical world. In addition, to balance the fooling degree between visible detector and infrared detector during the optimization process, we propose a score-aware iterative evaluation, which can guide the adversarial patch to iteratively reduce the predicted scores of the multi-modal sensors. We finally test our method against the one-stage detector: YOLOv3 and the two-stage detector: Faster RCNN. Results show that our unified patch achieves an Attack Success Rate (ASR) of 73.33% and 69.17%, respectively. More importantly, we verify the effective attacks in the physical world when visible and infrared sensors shoot the objects under various settings like different angles, distances, postures, and scenes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared DetectorsJiahuan Long, Wen Yao, Tingsong Jiang, Jiacheng Hou 等ACM MM 2025 · 被引用 7 次
- Feature-Level Adversarial Attacks and Ranking Disruption for Visible-Infrared Person Re-identificationXi Yang, Huanling Liu, De Cheng, Nannan Wang 等NeurIPS 2024 · 被引用 6 次
- Towards Efficient Training and Evaluation of Robust Models against l0 Bounded Adversarial PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuICML 2024 · 被引用 3 次
- Thermally Activated Dual-Modal Adversarial Clothing against AI Surveillance SystemsJiahuan Long, Tingsong Jiang, Hanqing Liu, Chao Ma 等CVPR 2026 · 被引用 3 次
- Embodied Laser Attack: Leveraging Scene Priors to Achieve Agent-based Robust Non-contact AttacksYitong Sun, Yao Huang, Xingxing WeiACM MM 2024 · 被引用 2 次
它引用的顶会 Paper9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Fooling Thermal Infrared Pedestrian Detectors in Real World Using Small BulbsXiaopei Zhu, Xiao Li, Jianmin Li, Zheyao Wang 等AAAI 2021 · 被引用 108 次
- ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial ViewpointsYinpeng Dong, Shouwei Ruan, Hang Su, Caixin Kang 等NeurIPS 2022 · 被引用 72 次
相关 Paper
- Physically Adversarial Infrared Patches with Learnable Shapes and LocationsXingxing Wei, Jie Yu, Yao HuangCVPR 2023
- Infrared Adversarial Car StickersXiaopei Zhu, Yuqiu Liu, Zhanhao Hu, Jianmin Li 等CVPR 2024 · 被引用 2 次
- ACAttack: Adaptive Cross Attacking RGB-T Tracker via Multi-Modal Response DecouplingXinyu Xiang, Qinglong Yan, Hao Zhang, Jiayi MaCVPR 2025
- Unleashing the Representational Power of Fourier Shapes for Attacking Infrared Object DetectionYixing Yong, Jian Wang, Ming Lei, Lijun He 等ICML 2026
- Legitimate Adversarial Patches: Evading Human Eyes and Detection Models in the Physical WorldJia Tan, Nan Ji, Haidong Xie, Xueshuang XiangACM MM 2021 · 被引用 44 次
