3 papers
cs.CR2026
SwitchPatch: Physical Adversarial Attack Strategy with Switchable Adversarial Objectives
Hanrui Jiang, Yutong Wu, Shiyi Yao +5
Physical adversarial patch (PAP) attacks attach carefully crafted patches to physical objects to manipulate a deployed model. However, existing PAP attacks suffer from several limi…
cs.CV2025
Pixel-Optimization-Free Patch Attack on Stereo Depth Estimation
Hangcheng Liu, Xu Kuang, Xingshuo Han +6
Stereo Depth Estimation (SDE) is essential for scene perception in vision-based systems such as autonomous driving. Prior work shows SDE is vulnerable to pixel-optimization attacks…
cs.CR2025
Model Supply Chain Poisoning: Backdooring Pre-trained Models via Embedding Indistinguishability
Hao Wang, Shangwei Guo, Jialing He +3
Pre-trained models (PTMs) are widely adopted across various downstream tasks in the machine learning supply chain. Adopting untrustworthy PTMs introduces significant security risks…