Physically Adversarial Infrared Patches with Learnable Shapes and Locations
Xingxing Wei, Jie Yu, Yao Huang
摘要
Owing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are complicated to implement in practical application because of their complex transformation from digital world to physical world. To address this issue, in this paper, we propose a physically feasible infrared attack method called “adversarial infrared patches”. Considering the imaging mechanism of infrared cameras by capturing objects' thermal radiation, adversarial infrared patches conduct attacks by attaching a patch of thermal insulation materials on the target object to manipulate its thermal distribution. To enhance adversarial attacks, we present a novel aggregation regularization to guide the simultaneous learning for the patch’ shape and location on the target object. Thus, a simple gradient-based optimization can be adapted to solve for them. We verify adversarial infrared patches in different object detection tasks with various object detectors. Experimental results show that our method achieves more than 90% Attack Success Rate (ASR) versus the pedestrian detector and vehicle detector in the physical environment, where the objects are captured in different angles, distances, postures, and scenes. More importantly, adversarial infrared patch is easy to implement, and it only needs 0.5 hours to be constructed in the physical world, which verifies its effectiveness and efficiency.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- Unified Adversarial Patch for Cross-modal Attacks in the Physical WorldXingxing Wei, Yao Huang, Yitong Sun, Jie YuICCV 2023 · 被引用 44 次
- NumbOD: A Spatial-Frequency Fusion Attack Against Object DetectorsZiqi Zhou, Bowen Li, Yufei Song, Zhifei Yu 等AAAI 2025 · 被引用 20 次
- Physical Backdoor: Towards Temperature-Based Backdoor Attacks in the Physical WorldWen Yin, Jian Lou, Pan Zhou, Yulai Xie 等CVPR 2024 · 被引用 9 次
- CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared DetectorsJiahuan Long, Wen Yao, Tingsong Jiang, Jiacheng Hou 等ACM MM 2025 · 被引用 7 次
- Feature-Level Adversarial Attacks and Ranking Disruption for Visible-Infrared Person Re-identificationXi Yang, Huanling Liu, De Cheng, Nannan Wang 等NeurIPS 2024 · 被引用 6 次
它引用的顶会 Paper6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- Fooling Thermal Infrared Pedestrian Detectors in Real World Using Small BulbsXiaopei Zhu, Xiao Li, Jianmin Li, Zheyao Wang 等AAAI 2021 · 被引用 108 次
- Random Noise Defense Against Query-Based Black-Box AttacksZeyu Qin, Yanbo Fan, Hongyuan Zha, Baoyuan WuNeurIPS 2021 · 被引用 78 次
相关 Paper
- Infrared Adversarial Car StickersXiaopei Zhu, Yuqiu Liu, Zhanhao Hu, Jianmin Li 等CVPR 2024 · 被引用 2 次
- Unleashing the Representational Power of Fourier Shapes for Attacking Infrared Object DetectionYixing Yong, Jian Wang, Ming Lei, Lijun He 等ICML 2026
- Infrared Invisible Clothing: Hiding from Infrared Detectors at Multiple Angles in Real WorldXiaopei Zhu, Zhanhao Hu, Siyuan Huang, Jianmin Li 等CVPR 2022 · 被引用 67 次
- Targeted Physical Evasion Attacks in the Near-Infrared DomainPascal Zimmer, Simon Lachnit, Alexander Jan Zielinski, Ghassan KarameNDSS 2026
- AdvDisplay: Adversarial Display Assembled by Thermoelectric Cooler for Fooling Thermal Infrared DetectorsHao Li, Fanggao Wan, Yue Su, Yue Wu 等AAAI 2025
