A Paperlist of Adversarial Attack on Object Detection


  • [2021 IEEE Transactions on Industrial Informatics] Deep Learning-Based Autonomous Driving Systems: A Survey of Attacks and Defenses, PDF, Survey
  • [2019 International Journal of Computer Vision] Deep Learning for Generic Object Detection: A Survey, PDF, Survey
  • [2021 ArXiv] Adversarial Example Detection for DNN Models: A Review and Experimental Comparison, PDF, Review
  • [2018 IEEE Access] Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey, PDF, Survey

Planar Patches Attack

  • [2021 Information Sciences]Towards a physical-world adversarial patch for blinding object detection models, PDF, physical

  • [2020 arxiv] Dynamic Adversarial Patch for Evading Object Detection, PDF , physical

  • [2020 arxiv] object hider: adversarial patch attack against object detectors, PDF, physicals

  • [2020 TPS-ISA] Adversarial Objectness Gradient Attacks on Real-time Object Detection Systems, PDF, Talk, Source code, digital & physicals

  • [2020 In European Symposium on Research in Computer Security] Understanding Object Detection Through an Adversarial Lens. [PDF], [Talk] Source code, digital & physicals

  • [2021 arxiv] RPAttack: Refined Patch Attack on General Object Detectors, PDF, digital

  • [2019 CVPRworkshop] Fooling automated surveillance cameras: adversarial patches to attack person detection PDF, Source code, physicals

  • [2019 AAAI] DPatch: An Adversarial patch attack on object detectors, PDF, Source code physicals

  • [2019 ICMLworkshop]On physical adversarial patches for object detectionPDF, physicals

  • [2019 ACM CCS] Seeing isn’t Believing: Towards More Robust Adversarial Attack Against RealWorld Object Detectors, PDF, physicals

  • [2019 IJCAI] Transferable Adversarial Attacks for Image and Video Object Detection, PDF, Source code, physicals

  • [2018 WOOT] Physical Adversarial Examples for Object Detectors, PDF., physicals

Pixel-wise Attack

  • [2023 WACV] Phantom Sponges: Exploiting Non-Maximum Suppression to Attack Deep Object Detectors, PDF, digital

  • [2022 IEEE TRANSACTIONS ON CYBERNETICS] Daedalus: Breaking Nonmaximum Suppression in Object Detection via Adversarial Examples, PDF, digital & physical

  • [2021 Pattern Recognition] Relevance attack on detectors, PDF, digital

  • [2020 Pattern Recognition] Universal adversarial perturbations against object detection, PDF, digital

  • [2019 BMVC] Attacking Object Detectors via Imperceptible Patches on Background, PDF, digital

  • [2018 BMVC] Robust Adversarial Perturbation on Deep Proposal-based Models, PDF,Source code, digital

Wearable Patches Attack

  • [2022 CVPR] Adversarial Texture for Fooling Person Detectors in the Physical World, PDF, physicals
  • [2020 ECCV] Making an Invisibility Cloak: Real World Adversarial Attacks on Object Detectors, PDF, physicals
  • [2020 ECCV] Adversarial T-shit! Evading Person Detectors in A Physical World, PDF, physicals
  • [2019 ICCV] advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable Patterns, PDF, Source code, physicals
  • [ACM CCS 2016] Accessorize to a Crime: Real and Stealthy Attacks onState-of-the-Art Face Recognition, PDF, Source code, physicals

Non-Planar Patches/Painting Attack

  • [2022 CVPR] Improving the Transferability of Targeted Adversarial Examples through Object-Based Diverse Input, pdf, physicals
  • [2022 CVPR] DTA Physical Camouflage Attacks using Differentiable Transformation Network, PDF, physicals /Hu_Adversarial_Texture_for_Fooling_Person_Detectors_in_the_Physical_World_CVPR_2022_paper.pdf), physicals
  • [2022 IJCAI] Learning Coated Adversarial Camouflages for Object Detectors, PDF, physicals
  • [2022 AAAI] FCA: Learning a 3D Full-coverage Vehicle Camouflage for Multi-view Physical Adversarial Attack, PDF, physicals
  • [2021 CVPR] Dual Attention Suppression Attack: Generate adversarial camouflage in physical world, PDF, Source code, physicals
  • [2020 arxiv] Physical Adversarial Attack on Vehicle Detector in the Carla Simulator, PDF, digital
  • [2020 CVPR] Universal Physical Camouflage Attack on Object Detectors, PDF, physicals
  • [2019 CVPR] MeshAdv Adversarial Meshes for Visual Recognition, PDF, physical
  • [2019 CVPR] Adversarial Attacks Beyond the Image Space, PDF, digital

Attack against Aerial Object detectors

  • [2022 IEEE transactions on geoscience and remote sensing] Benchmarking Adversarial Patch Against Aerial Detection, PDF, aerial imagery, physical

  • [2020 ATVA] Adversarial Patch Camouflage against Aerial Detection, PDF, digital

  • [remote sensing, 2022] Adversarial Patch Attack on Multi-Scale Object Detection for UAV Remote Sensing Images, PDF, UAV related attacks, physical

  • [WACV 2022] [hysical Adversarial Attacks on an Aerial Imagery Object Detector, homepage, PDF, demo

  • [remote sensing] Scale-Adaptive adversarial patch attack for remote sensing image aircraft detection,PDF, digital

  • [preprint] Adversarial Attacks against a Satellite-borne Multispectral Cloud Detector, PDF, digital

Blackbox Attack

3D Attack

Defense of Attacks on Object Detectors

  • [2021 ICLR Workshop on Security and Safety in Machine Learning Systems (Travel Award)], PDF, [GitHub] [Slides] [Poster], digital

  • [2021 ACM CCS], DetectorGuard: Provably Securing Object Detectors against Localized Patch Hiding Attacks, PDF [GitHub] [ACM DL] [Video] [Slides], digital

  • [2021 USENIX Security], PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and Masking, PDF, [GitHub] [arXiv Technical Report] [Video] [Slides], digital

  • [arXiv 2108],PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image Classifier, PDF, GitHub], digital

  • [2021 arxiv] adversarial YOLO defense human detection patch attacks via detecting adversarial patches, PDF, physical

  • [2021 arxiv], We Can Always Catch You: Detecting Adversarial Patched Objects WITH or WITHOUT Signature, PDF, physical

  • [ICCV 2019] Towards Adversarially Robust Object Detection, PDF, digital

  • [ICML 2021]Knowledge Enhanced Machine Learning Pipeline against Diverse Adversarial Attacks, PDF, digital

Useful Object Detection Dataset

  1. MS COCO
  1. Inria
  1. DOTA
  1. Open Images(QID)
  1. Remote sensing/UAV aerial dataset
  1. Cars Overhead With Context (COWC)
  1. visdrone
  1. NWPU VHR-10
  1. RSOD