A black-box physical attack that optimizes pure-color patch positions and colors with differential evolution, guided by finite-difference key-region localization, outperforms Bbox-Att on three remote sensing detectors.
Distillation-Enhanced Physical Adversarial Attacks
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
The study of physical adversarial patches is crucial for identifying vulnerabilities in AI-based recognition systems and developing more robust deep learning models. While recent research has focused on improving patch stealthiness for greater practical applicability, achieving an effective balance between stealth and attack performance remains a significant challenge. To address this issue, we propose a novel physical adversarial attack method that leverages knowledge distillation. Specifically, we first define a stealthy color space tailored to the target environment to ensure smooth blending. Then, we optimize an adversarial patch in an unconstrained color space, which serves as the 'teacher' patch. Finally, we use an adversarial knowledge distillation module to transfer the teacher patch's knowledge to the 'student' patch, guiding the optimization of the stealthy patch. Experimental results show that our approach improves attack performance by 20%, while maintaining stealth, highlighting its practical value.
citation-role summary
citation-polarity summary
fields
cs.CV 1years
2026 1verdicts
CONDITIONAL 1roles
background 1polarities
unclear 1representative citing papers
citing papers explorer
-
ColorFD: A Finite-Difference Guided Black-Box Physical Adversarial Attack for Remote Sensing Object Detection
A black-box physical attack that optimizes pure-color patch positions and colors with differential evolution, guided by finite-difference key-region localization, outperforms Bbox-Att on three remote sensing detectors.