PatchDEMUX extends any certified single-label patch defense to multi-label classifiers by per-class certification and a location-aware procedure that tightens bounds when the attacker can plant only one patch.
Certified Defenses for Adversarial Patches
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Adversarial patch attacks are among one of the most practical threat models against real-world computer vision systems. This paper studies certified and empirical defenses against patch attacks. We begin with a set of experiments showing that most existing defenses, which work by pre-processing input images to mitigate adversarial patches, are easily broken by simple white-box adversaries. Motivated by this finding, we propose the first certified defense against patch attacks, and propose faster methods for its training. Furthermore, we experiment with different patch shapes for testing, obtaining surprisingly good robustness transfer across shapes, and present preliminary results on certified defense against sparse attacks. Our complete implementation can be found on: https://github.com/Ping-C/certifiedpatchdefense.
citation-role summary
citation-polarity summary
fields
cs.CR 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
background 1representative citing papers
citing papers explorer
-
PatchDEMUX: A Certifiably Robust Framework for Multi-label Classifiers Against Adversarial Patches
PatchDEMUX extends any certified single-label patch defense to multi-label classifiers by per-class certification and a location-aware procedure that tightens bounds when the attacker can plant only one patch.