Adversarial Patch
arXiv:1712.09665
Abstract
We present a method to create universal, robust, targeted adversarial image patches in the real world. The patches are universal because they can be used to attack any scene, robust because they work under a wide variety of transformations, and targeted because they can cause a classifier to output any target class. These adversarial patches can be printed, added to any scene, photographed, and presented to image classifiers; even when the patches are small, they cause the classifiers to ignore the other items in the scene and report a chosen target class. To reproduce the results from the paper, our code is available at https://github.com/tensorflow/cleverhans/tree/master/examples/adversarial_patch
Cited by in corpus (26)
- Certifying Some Distributional Robustness with Principled Adversarial Training
- AdvHat: Real-world adversarial attack on ArcFace Face ID system
- Adversarial Examples: Opportunities and Challenges
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks
- Learning Model-Agnostic Counterfactual Explanations for Tabular Data
- Adversarial Attack Vulnerability of Medical Image Analysis Systems: Unexplored Factors
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary Attack
- RobustBench: a standardized adversarial robustness benchmark
- Inspect, Understand, Overcome: A Survey of Practical Methods for AI Safety
- Adversarial Attacks on Time-Series Intrusion Detection for Industrial Control Systems
- Robustness Verification of Quantum Classifiers
- Biometric Backdoors: A Poisoning Attack Against Unsupervised Template Updating
- PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and Masking
- ECGadv: Generating Adversarial Electrocardiogram to Misguide Arrhythmia Classification System
- Defending From Physically-Realizable Adversarial Attacks Through Internal Over-Activation Analysis
- A Little Fog for a Large Turn
- Subverting Fair Image Search with Generative Adversarial Perturbations
- Jacobian Regularization for Mitigating Universal Adversarial Perturbations
- APRICOT: A Dataset of Physical Adversarial Attacks on Object Detection
- Provable Robustness Against a Union of Adversarial Attacks
- The Efficacy of SHIELD under Different Threat Models
- DetectorGuard: Provably Securing Object Detectors against Localized Patch Hiding Attacks
- Meta Adversarial Training against Universal Patches
- Problems in AI research and how the SP System may help to solve them
- To Make Yourself Invisible with Adversarial Semantic Contours
- Information Security and Privacy in the Digital World: Some Selected Topics