RED learns per-class colorful grid patterns for road sign backgrounds that make any small patch class-discriminative, sharply reducing vulnerability to patch attacks.
LaVAN: Localized and Visible Adversarial Noise
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Most works on adversarial examples for deep-learning based image classifiers use noise that, while small, covers the entire image. We explore the case where the noise is allowed to be visible but confined to a small, localized patch of the image, without covering any of the main object(s) in the image. We show that it is possible to generate localized adversarial noises that cover only 2% of the pixels in the image, none of them over the main object, and that are transferable across images and locations, and successfully fool a state-of-the-art Inception v3 model with very high success rates.
fields
cs.CV 1years
2024 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
RED: Robust Environmental Design
RED learns per-class colorful grid patterns for road sign backgrounds that make any small patch class-discriminative, sharply reducing vulnerability to patch attacks.