提出高效自适应对抗补丁,用少查询实现对目标检测器的强干扰。
Budget-Aware Adaptive Adversarial Patches for Black-Box Object Detection

- 结合上下文泰勒采样与像素更新,动态调整补丁位置、纹理和大小。
- 在少量查询下实现强抑制,对基于CNN和Transformer的检测器均有效。
- 可调节视觉足迹与攻击强度,适合研究物理世界对抗攻击的场景。
对抗补丁对现代目标检测器构成现实威胁。以往研究虽揭示了脆弱性,但存在三方面局限:(i) 缺乏在严格查询预算下,联合优化补丁位置、纹理和尺寸的基于分数的黑盒攻击;(ii) 攻击成功率常与补丁视觉足迹脱钩;(iii) 评估中常将输入输出变换(EOT)鲁棒性误作成功标准。本文提出 extit{Budget-Aware Adaptive Adversarial Patches},一种查询高效、预算自适应的黑盒攻击方法,其核心为轻量级上下文泰勒采样定位器与类NES像素更新机制,仅在进展停滞时才扩大补丁。评估基于严格的纯图像抑制测试,虽审计EOT鲁棒性但不将其作为成功替代指标;可选的外观/可打印性权重揭示了攻击强度与可见性的权衡。在YOLOv5、Faster R-CNN和YOLOS上,该方法以紧凑补丁实现对基于CNN检测器的强大抑制,并对基于Transformer的检测器产生显著干扰,相较固定尺寸与启发式基线展现出清晰的查询-足迹权衡。一次打印-捕获原型实验进一步验证了其在未见物理对象与视角间的迁移能力。
原文摘要 · Abstract (English)
Adversarial patches pose a practical threat to modern object detectors. Prior work shows vulnerability, but three gaps limit actionable insight: (i) few \emph{score-based black-box} attacks \emph{jointly} optimize patch \emph{location, texture, and size} under tight query budgets; (ii) success is rarely tied to the patch's \emph{visual footprint}; and (iii) evaluations often conflate EOT robustness with plain-view suppression. We present \method{}, a query-efficient, budget-adaptive black-box attack that couples a lightweight \emph{Contextual Thompson-Sampling} placer with NES-style pixel updates, growing the patch only when progress stalls. Reporting is anchored by a \emph{strict plain-image} suppression test; EOT is audited but never used as a substitute for success, and optional appearance/printability weights expose strength--visibility trade-offs. Across YOLOv5, Faster R-CNN, and YOLOS, \method{} achieves strong suppression on CNN-based detectors and substantial suppression on the transformer-based detector, using compact patches and exposing clear query--footprint trade-offs relative to fixed-size and heuristic baselines. A print--capture pilot further shows transfer across unseen physical objects and viewpoints.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。