Pith. sign in

REVIEW 10 cited by

Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2201.08970 v1 pith:4IAX4I57 submitted 2022-01-22 cs.CV

classification cs.CV
keywords attackattackedblack-boxdetectionadversarialattacksbounding-boxobject
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Object detection has been widely used in many safety-critical tasks, such as autonomous driving. However, its vulnerability to adversarial examples has not been sufficiently studied, especially under the practical scenario of black-box attacks, where the attacker can only access the query feedback of predicted bounding-boxes and top-1 scores returned by the attacked model. Compared with black-box attack to image classification, there are two main challenges in black-box attack to detection. Firstly, even if one bounding-box is successfully attacked, another sub-optimal bounding-box may be detected near the attacked bounding-box. Secondly, there are multiple bounding-boxes, leading to very high attack cost. To address these challenges, we propose a Parallel Rectangle Flip Attack (PRFA) via random search. We explain the difference between our method with other attacks in Fig.~\ref{fig1}. Specifically, we generate perturbations in each rectangle patch to avoid sub-optimal detection near the attacked region. Besides, utilizing the observation that adversarial perturbations mainly locate around objects' contours and critical points under white-box attacks, the search space of attacked rectangles is reduced to improve the attack efficiency. Moreover, we develop a parallel mechanism of attacking multiple rectangles simultaneously to further accelerate the attack process. Extensive experiments demonstrate that our method can effectively and efficiently attack various popular object detectors, including anchor-based and anchor-free, and generate transferable adversarial examples.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 10 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. 3D Gaussian Splatting Driven Multi-View Robust Physical Adversarial Camouflage Generation

    cs.CV 2025-07 conditional novelty 7.0 of 10

    PGA uses 3D Gaussian Splatting to generate physical adversarial camouflage from a few images, improving multi-view attack robustness on vehicle detectors.

  2. Adversarial Generation and Collaborative Evolution of Safety-Critical Scenarios for Autonomous Vehicles

    cs.CV 2025-08 conditional novelty 6.0 of 10

    ScenGE generates more collision-prone autonomous driving test scenarios by combining LLM-suggested adversarial events with optimized background traffic, beating prior generators on CARLA benchmarks.

  3. No Query, No Access

    cs.CL 2025-05 conditional novelty 6.0 of 10

    A new attack scenario, Victim Data-based Attack (VDBA), generates transferable adversarial examples for text classifiers using only unlabeled victim texts, achieving over 40% attack success on several models with zero...

  4. Manipulating Multimodal Agents via Cross-Modal Prompt Injection

    cs.CV 2025-04 conditional novelty 6.0 of 10

    A coordinated attack that embeds malicious cues in both visual and textual inputs can hijack black-box multimodal agents, outperforming single-modality prompt injection attacks.

  5. Black-Box Adversarial Attack on Vision Language Models for Autonomous Driving

    cs.CV 2025-01 conditional novelty 6.0 of 10

    CAD is a transfer-based black-box attack using CLIP embeddings and ChatGPT-generated deceptive reasoning text to make vision-language autonomous driving models take unsafe actions.

  6. CogMorph: Cognitive Morphing Attacks for Text-to-Image Models

    cs.CV 2025-01 conditional novelty 6.0 of 10

    CogMorph escalates the toxicity of text-to-image outputs by contextually rewriting prompts with retrieved harmful features, claiming higher emotional harm than prior jailbreak attacks.

  7. WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features

    cs.CR 2024-12 conditional novelty 6.0 of 10

    WFCAT is a CNN-based Tor website fingerprinting attack using inter-arrival-time histograms and channel-wise attention, reaching 59% closed-world accuracy against the Surakav defense.

  8. Benchmarking the Robustness of Autonomous Driving to Environmental Illusions: A Lane Perception Perspective

    cs.CV 2026-07 conditional novelty 5.0 of 10

    Environmental illusions cause 5-7% accuracy drops in lane detection models and can trigger collisions in closed-loop simulation, with a proposed defense (MIDA) recovering ~4% robustness.

  9. Physical Adversarial Camouflage through Gradient Calibration and Regularization

    cs.CV 2025-08 conditional novelty 5.0 of 10

    Nearest Gradient Calibration and Loss-Prioritized Gradient Decorrelation reduce the AP@0.5 of a camouflaged vehicle detector from 13.19% to 2.16% with YOLOv3, and improve transfer to other detectors.

  10. Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025

    cs.CR 2025-06 conditional novelty 3.0 of 10

    The ATLAS 2025 competition demonstrates that vision-language models remain highly vulnerable to flowchart-based and cross-modal jailbreak attacks, with top scores exceeding 93%.

Pith tools