arXiv:2508.00649cs.CVcs.CR2025-08ICCV被引 3

构建首个统一评测框架,揭示对抗补丁防御的真正难点。

Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New Insights

  • 设计统一评测体系,涵盖13种攻击、11种检测器与4项指标。
  • 新数据集提升防御性能15.09% [email protected],证明分布差异是核心挑战。
  • 强调目标检测精度比补丁识别率更能反映防御效果,适合研究者参考。

针对目标检测器的对抗补丁防御研究日益受到关注,但现有评估缺乏统一框架,导致结果不一致且不完整。为此,我们重新审视了11种代表性防御方法,提出首个补丁防御基准,包含2种攻击目标、13种补丁攻击、11种目标检测器和4种多样指标。构建了包含94类补丁和94,000张图像的大规模对抗补丁数据集。综合分析揭示新见解:(1)自然风格补丁的防御难点在于数据分布差异,而非高频成分;新数据集可使现有防御提升15.09% [email protected]。(2)被攻击目标的平均精度比补丁检测准确率更一致地反映防御性能。(3)自适应攻击可显著绕过现有防御,而采用复杂/随机模型或通用补丁特性的防御更具鲁棒性。代码与数据集已在GitHub公开,将持续更新。

原文摘要 · Abstract (English)

Developing reliable defenses against patch attacks on object detectors has attracted increasing interest. However, we identify that existing defense evaluations lack a unified and comprehensive framework, resulting in inconsistent and incomplete assessments of current methods. To address this issue, we revisit 11 representative defenses and present the first patch defense benchmark, involving 2 attack goals, 13 patch attacks, 11 object detectors, and 4 diverse metrics. This leads to the large-scale adversarial patch dataset with 94 types of patches and 94,000 images. Our comprehensive analyses reveal new insights: (1) The difficulty in defending against naturalistic patches lies in the data distribution, rather than the commonly believed high frequencies. Our new dataset with diverse patch distributions can be used to improve existing defenses by 15.09% [email protected]. (2) The average precision of the attacked object, rather than the commonly pursued patch detection accuracy, shows high consistency with defense performance. (3) Adaptive attacks can substantially bypass existing defenses, and defenses with complex/stochastic models or universal patch properties are relatively robust. We hope that our analyses will serve as guidance on properly evaluating patch attacks/defenses and advancing their design. Code and dataset are available at https://github.com/Gandolfczjh/APDE, where we will keep integrating new attacks/defenses.

对抗防御目标检测评测基准补丁攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。