Pith. sign in

REVIEW 3 cited by

Diffusion to Confusion: Naturalistic Adversarial Patch Generation Based on Diffusion Model for Object Detector

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2307.08076 v1 pith:BW3CHAY5 submitted 2023-07-16 cs.CV

classification cs.CV
keywords adversarialgenerationpatchnaturalisticdiffusionobjectattackdetectors
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Many physical adversarial patch generation methods are widely proposed to protect personal privacy from malicious monitoring using object detectors. However, they usually fail to generate satisfactory patch images in terms of both stealthiness and attack performance without making huge efforts on careful hyperparameter tuning. To address this issue, we propose a novel naturalistic adversarial patch generation method based on the diffusion models (DM). Through sampling the optimal image from the DM model pretrained upon natural images, it allows us to stably craft high-quality and naturalistic physical adversarial patches to humans without suffering from serious mode collapse problems as other deep generative models. To the best of our knowledge, we are the first to propose DM-based naturalistic adversarial patch generation for object detectors. With extensive quantitative, qualitative, and subjective experiments, the results demonstrate the effectiveness of the proposed approach to generate better-quality and more naturalistic adversarial patches while achieving acceptable attack performance than other state-of-the-art patch generation methods. We also show various generation trade-offs under different conditions.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SpaNN: Detecting Multiple Adversarial Patches on CNNs by Spanning Saliency Thresholds

    cs.CV 2025-06 conditional novelty 7.0 of 10

    SpaNN detects adversarial patches by clustering binarized first-layer feature maps across a sweep of saliency thresholds and feeding the cluster curves into a small CNN.

  2. Generalizable Targeted Data Poisoning against Varying Physical Objects

    cs.CV 2024-12 conditional novelty 6.0 of 10

    A clean-label targeted poisoning method that matches gradient magnitude as well as direction generalizes to unseen physical variations of a target object, reaching 90.13% success on multi-view cars.

  3. BadPatch: Diffusion-Based Generation of Physical Adversarial Patches

    cs.CV 2024-12 conditional novelty 6.0 of 10

    BadPatch generates naturalistic, customizable adversarial patches for evading person detectors using incomplete diffusion optimization, and it introduces the AdvT-shirt-1K physical-world dataset.

Pith tools