2 papers
cs.CR2026
SwitchPatch: Physical Adversarial Attack Strategy with Switchable Adversarial Objectives
Hanrui Jiang, Yutong Wu, Shiyi Yao +5
Physical adversarial patch (PAP) attacks attach carefully crafted patches to physical objects to manipulate a deployed model. However, existing PAP attacks suffer from several limi…
cs.CR2024
Towards Understanding and Enhancing Security of Proof-of-Training for DNN Model Ownership Verification
Yijia Chang, Hanrui Jiang, Chao Lin +2
The great economic values of deep neural networks (DNNs) urge AI enterprises to protect their intellectual property (IP) for these models. Recently, proof-of-training (PoT) has bee…