Pith. sign in

REVIEW 2 cited by

Natural Adversarial Patch Generation Method Based on Latent Diffusion Model

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2312.16401 v1 pith:UK5P3RIR submitted 2023-12-27 cs.CV

classification cs.CV
keywords diffusionadversariallatentmodelnaturalpatchpatchesspace
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recently, some research show that deep neural networks are vulnerable to the adversarial attacks, the well-trainned samples or patches could be used to trick the neural network detector or human visual perception. However, these adversarial patches, with their conspicuous and unusual patterns, lack camouflage and can easily raise suspicion in the real world. To solve this problem, this paper proposed a novel adversarial patch method called the Latent Diffusion Patch (LDP), in which, a pretrained encoder is first designed to compress the natural images into a feature space with key characteristics. Then trains the diffusion model using the above feature space. Finally, explore the latent space of the pretrained diffusion model using the image denoising technology. It polishes the patches and images through the powerful natural abilities of diffusion models, making them more acceptable to the human visual system. Experimental results, both digital and physical worlds, show that LDPs achieve a visual subjectivity score of 87.3%, while still maintaining effective attack capabilities.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Hidden in Plain Sight: Diffusion-Based Unrestricted Robotic Attacks on Vision-Language-Action Models

    cs.AI 2026-08 conditional novelty 6.0 of 10

    A diffusion-based attack creates natural-looking patches that steer vision-language-action robot policies toward attacker-chosen actions in white-box and action-only black-box settings.

  2. BadPatch: Diffusion-Based Generation of Physical Adversarial Patches

    cs.CV 2024-12 conditional novelty 6.0 of 10

    BadPatch generates naturalistic, customizable adversarial patches for evading person detectors using incomplete diffusion optimization, and it introduces the AdvT-shirt-1K physical-world dataset.

Pith tools