Pith. sign in

REVIEW 1 cited by

Generative Dynamic Patch Attack

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2111.04266 v2 pith:NMTBQOQX submitted 2021-11-08 cs.CV

classification cs.CV
keywords patchattackadversarialattacksgdpadynamiclocationmodel
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial patch attack is a family of attack algorithms that perturb a part of image to fool a deep neural network model. Existing patch attacks mostly consider injecting adversarial patches at input-agnostic locations: either a predefined location or a random location. This attack setup may be sufficient for attack but has considerable limitations when using it for adversarial training. Thus, robust models trained with existing patch attacks cannot effectively defend other adversarial attacks. In this paper, we first propose an end-to-end patch attack algorithm, Generative Dynamic Patch Attack (GDPA), which generates both patch pattern and patch location adversarially for each input image. We show that GDPA is a generic attack framework that can produce dynamic/static and visible/invisible patches with a few configuration changes. Secondly, GDPA can be readily integrated for adversarial training to improve model robustness to various adversarial attacks. Extensive experiments on VGGFace, Traffic Sign and ImageNet show that GDPA achieves higher attack success rates than state-of-the-art patch attacks, while adversarially trained model with GDPA demonstrates superior robustness to adversarial patch attacks than competing methods. Our source code can be found at https://github.com/lxuniverse/gdpa.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. IAP: Invisible Adversarial Patch Attack through Perceptibility-Aware Localization and Perturbation Optimization

    cs.CV 2025-07 conditional novelty 5.0 of 10

    A perceptibility-aware placement step plus a color-preserving perturbation update produces targeted adversarial patches that evade both human observers and six published patch defenses while keeping attack success rates high.

Pith tools