arXiv:2607.23292cs.CRcs.CV2026-07

提出可伪装的物理对抗贴纸,有效干扰双模态人脸识别

Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection

论文配图:Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection
图 1 · 摘自论文原文
  • 联合优化可见光与红外图像的渐变色遮蔽贴纸
  • 数字与物理域攻击成功率均超90%
  • 贴纸外观自然,人眼难以察觉,适合真实场景攻击

基于深度学习的可见光-红外融合人脸检测模型在各类应用中日益普及,但仍易受对抗贴纸攻击。以往多数攻击仅针对可见光或红外单模态,在数字域进行,难以在物理世界对融合模型生效。此外,许多方法生成的贴纸图案明显异常,缺乏现实感。本文提出VIPatch(Visual-Infrared Patch),一种新型物理对抗贴纸攻击方法,可生成外观自然、难以察觉的贴纸。VIPatch同时在可见光和红外图像上设计渐变色遮蔽区域与创可贴样式贴纸,并联合优化二者;生成的数字贴纸进一步指导物理贴纸的制作。实验表明,VIPatch在数字与物理域均实现超过90%的攻击成功率,且贴纸对人类观察者几乎不可见。

原文摘要 · Abstract (English)

Deep learning-based visual-infrared fused face detection models are increasingly deployed across a wide range of applications, yet they remain susceptible to adversarial patch attacks. Most prior attacks target either the visual or the infrared image alone in the digital domain, which renders them ineffective against fused models in the physical world. Moreover, many of these methods are readily noticeable, as their patch patterns deviate substantially from those seen in the real world. In this paper, we introduce VIPatch (Visual-Infrared Patch), a novel physical adversarial patch attack that produces inconspicuous, realistic, and natural-looking patches for facial images. Specifically, VIPatch crafts a gradient-color mask together with a band-aid sticker across both the visual and infrared images, and jointly optimizes these two elements; the resulting digital patches further guide the fabrication of their physical counterparts. Experimental results show that VIPatch achieves competitive attack success rates (over 90%) in both the digital and physical domains, while keeping the patches unobtrusive to human observers.

对抗攻击双模态检测物理攻击人脸检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。