PAD: Patch-Agnostic Defense against Adversarial Patch Attacks

被引:5
|
作者
Jing, Lihua [1 ,2 ]
Wang, Rui [1 ,2 ]
Ren, Wenqi [3 ]
Dong, Xin [1 ,2 ]
Zou, Cong [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Sun Yat Sen Univ, Sch Cyber Sci & Technol, Shenzhen Campus, Shenzhen, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1109/CVPR52733.2024.02310
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial patch attacks present a significant threat to real-world object detectors due to their practical feasibility. Existing defense methods, which rely on attack data or prior knowledge, struggle to effectively address a wide range of adversarial patches. In this paper, we show two inherent characteristics of adversarial patches, semantic independence and spatial heterogeneity, independent of their appearance, shape, size, quantity, and location. Semantic independence indicates that adversarial patches operate autonomously within their semantic context, while spatial heterogeneity manifests as distinct image quality of the patch area that differs from original clean image due to the independent generation process. Based on these observations, we propose PAD, a novel adversarial patch localization and removal method that does not require prior knowledge or additional training. PAD offers patch-agnostic defense against various adversarial patches, compatible with any pre-trained object detectors. Our comprehensive digital and physical experiments involving diverse patch types, such as localized noise, printable, and naturalistic patches, exhibit notable improvements over state-of-the-art works. Our code is available at https://github.com/Lihua-Jing/PAD.
引用
收藏
页码:24472 / 24481
页数:10
相关论文
共 50 条
  • [21] Improving Adversarial Robustness Against Universal Patch Attacks Through Feature Norm Suppressing
    Yu, Cheng
    Chen, Jiansheng
    Wang, Yu
    Xue, Youze
    Ma, Huimin
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2025, 36 (01) : 1410 - 1424
  • [22] Text Adversarial Purification as Defense against Adversarial Attacks
    Li, Linyang
    Song, Demin
    Qiu, Xipeng
    PROCEEDINGS OF THE 61ST ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, VOL 1, 2023, : 338 - 350
  • [23] Hardening RGB-D object recognition systems against adversarial patch attacks
    Zheng, Yang
    Demetrio, Luca
    Cina, Antonio Emanuele
    Feng, Xiaoyi
    Xia, Zhaoqiang
    Jiang, Xiaoyue
    Demontis, Ambra
    Biggio, Battista
    Roli, Fabio
    INFORMATION SCIENCES, 2023, 651
  • [24] Improving Adversarial Robustness Against Universal Patch Attacks Through Feature Norm Suppressing
    Yu, Cheng
    Chen, Jiansheng
    Wang, Yu
    Xue, Youze
    Ma, Huimin
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2025, 36 (01) : 1410 - 1424
  • [25] Certified defense against patch attacks via mask-guided randomized smoothing
    Kui ZHANG
    Hang ZHOU
    Huanyu BIAN
    Weiming ZHANG
    Nenghai YU
    ScienceChina(InformationSciences), 2022, 65 (07) : 86 - 97
  • [26] Certified defense against patch attacks via mask-guided randomized smoothing
    Zhang, Kui
    Zhou, Hang
    Bian, Huanyu
    Zhang, Weiming
    Yu, Nenghai
    SCIENCE CHINA-INFORMATION SCIENCES, 2022, 65 (07)
  • [27] Certified defense against patch attacks via mask-guided randomized smoothing
    Kui Zhang
    Hang Zhou
    Huanyu Bian
    Weiming Zhang
    Nenghai Yu
    Science China Information Sciences, 2022, 65
  • [28] Robust Audio Patch Attacks Using Physical Sample Simulation and Adversarial Patch Noise Generation
    Du, Xia
    Pun, Chi-Man
    IEEE TRANSACTIONS ON MULTIMEDIA, 2022, 24 : 4381 - 4393
  • [29] Benchmarking Adversarial Patch Against Aerial Detection
    Lian, Jiawei
    Mei, Shaohui
    Zhang, Shun
    Ma, Mingyang
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2022, 60
  • [30] Attribution guided purification against adversarial patch
    Yin, Liyao
    Wang, Shen
    Wang, Zhenbang
    Wang, Changdong
    Zhan, Dechen
    DISPLAYS, 2024, 83