PAD: Patch-Agnostic Defense against Adversarial Patch Attacks

被引:5
|
作者
Jing, Lihua [1 ,2 ]
Wang, Rui [1 ,2 ]
Ren, Wenqi [3 ]
Dong, Xin [1 ,2 ]
Zou, Cong [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Sun Yat Sen Univ, Sch Cyber Sci & Technol, Shenzhen Campus, Shenzhen, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1109/CVPR52733.2024.02310
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial patch attacks present a significant threat to real-world object detectors due to their practical feasibility. Existing defense methods, which rely on attack data or prior knowledge, struggle to effectively address a wide range of adversarial patches. In this paper, we show two inherent characteristics of adversarial patches, semantic independence and spatial heterogeneity, independent of their appearance, shape, size, quantity, and location. Semantic independence indicates that adversarial patches operate autonomously within their semantic context, while spatial heterogeneity manifests as distinct image quality of the patch area that differs from original clean image due to the independent generation process. Based on these observations, we propose PAD, a novel adversarial patch localization and removal method that does not require prior knowledge or additional training. PAD offers patch-agnostic defense against various adversarial patches, compatible with any pre-trained object detectors. Our comprehensive digital and physical experiments involving diverse patch types, such as localized noise, printable, and naturalistic patches, exhibit notable improvements over state-of-the-art works. Our code is available at https://github.com/Lihua-Jing/PAD.
引用
收藏
页码:24472 / 24481
页数:10
相关论文
共 50 条
  • [1] ObjectSeeker: Certifiably Robust Object Detection against Patch Hiding Attacks via Patch-agnostic Masking
    Xiang, Chong
    Valtchanov, Alexander
    Mahloujifar, Saeed
    Mittal, Prateek
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 1329 - 1347
  • [2] DIFFender: Diffusion-Based Adversarial Defense Against Patch Attacks
    Kang, Caixin
    Dong, Yinpeng
    Wang, Zhengyi
    Ruan, Shouwei
    Chen, Yubo
    Su, Hang
    Wei, Xingxing
    COMPUTER VISION - ECCV 2024, PT LII, 2025, 15110 : 130 - 147
  • [3] PatchZero: Defending against Adversarial Patch Attacks by Detecting and Zeroing the Patch
    Xu, Ke
    Xiao, Yao
    Zheng, Zhaoheng
    Cai, Kaijie
    Nevatia, Ram
    2023 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2023, : 4621 - 4630
  • [4] Enhancing robustness of person detection: A universal defense filter against adversarial patch attacks
    Mao, Zimin
    Chen, Shuiyan
    Miao, Zhuang
    Li, Heng
    Xia, Beihao
    Cai, Junzhe
    Yuan, Wei
    You, Xinge
    COMPUTERS & SECURITY, 2024, 146
  • [5] Defense against Adversarial Patch Attacks for Aerial Image Semantic Segmentation by Robust Feature Extraction
    Wang, Zhen
    Wang, Buhong
    Zhang, Chuanlei
    Liu, Yaohui
    REMOTE SENSING, 2023, 15 (06)
  • [6] Jujutsu: A Two-stage Defense against Adversarial Patch Attacks on Deep Neural Networks
    Chen, Zitao
    Dash, Pritam
    Pattabiraman, Karthik
    PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 689 - 703
  • [7] Adversarial patch attacks against aerial imagery object detectors
    Tang, Guijian
    Jiang, Tingsong
    Zhou, Weien
    Li, Chao
    Yao, Wen
    Zhao, Yong
    NEUROCOMPUTING, 2023, 537 : 128 - 140
  • [8] Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch Detection
    Liu, Jiang
    Levine, Alexander
    Lau, Chun Pong
    Chellappa, Rama
    Feizi, Soheil
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 14953 - 14962
  • [9] PATCH STEGANALYSIS: A SAMPLING BASED DEFENSE AGAINST ADVERSARIAL STEGANOGRAPHY
    Qin, Chuan
    Zhao, Na
    Zhang, Weiming
    Yu, Nenghai
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 3079 - 3083
  • [10] Visually imperceptible adversarial patch attacks
    Qian, Yagua
    Wang, Jiamin
    Wang, Haijiang
    Cu, Zhaoquan
    Wang, Bin
    Zeng, Shaonin
    Swaileh, Wassim
    COMPUTERS & SECURITY, 2022, 123