APRICOT: A Dataset of Physical Adversarial Attacks on Object Detection

12/17/2019
by   Anneliese Braunegg, et al.
16

Physical adversarial attacks threaten to fool object detection systems, but reproducible research on the real-world effectiveness of physical patches and how to defend against them requires a publicly available benchmark dataset. We present APRICOT, a collection of over 1,000 annotated photographs of printed adversarial patches in public locations. The patches target several object categories for three COCO-trained detection models, and the photos represent natural variation in position, distance, lighting conditions, and viewing angle. Our analysis suggests that maintaining adversarial robustness in uncontrolled settings is highly challenging, but it is still possible to produce targeted detections under white-box and sometimes black-box settings. We establish baselines for defending against adversarial patches through several methods, including a detector supervised with synthetic data and unsupervised methods such as kernel density estimation, Bayesian uncertainty, and reconstruction error. Our results suggest that adversarial patches can be effectively flagged, both in a high-knowledge, attack-specific scenario, and in an unsupervised setting where patches are detected as anomalies in natural images. This dataset and the described experiments provide a benchmark for future research on the effectiveness of and defenses against physical adversarial objects in the wild.

READ FULL TEXT

page 1

page 4

page 11

page 12

page 13

page 14

page 15

research
10/31/2019

Making an Invisibility Cloak: Real World Adversarial Attacks on Object Detectors

We present a systematic study of adversarial attacks on state-of-the-art...
research
10/10/2021

Adversarial Attacks in a Multi-view Setting: An Empirical Study of the Adversarial Patches Inter-view Transferability

While machine learning applications are getting mainstream owing to a de...
research
10/25/2020

Dynamic Adversarial Patch for Evading Object Detection Models

Recent research shows that neural networks models used for computer visi...
research
06/19/2023

Eigenpatches – Adversarial Patches from Principal Components

Adversarial patches are still a simple yet powerful white box attack tha...
research
10/16/2022

Object-Attentional Untargeted Adversarial Attack

Deep neural networks are facing severe threats from adversarial attacks....
research
03/14/2022

Defending From Physically-Realizable Adversarial Attacks Through Internal Over-Activation Analysis

This work presents Z-Mask, a robust and effective strategy to improve th...
research
11/07/2021

Natural Adversarial Objects

Although state-of-the-art object detection methods have shown compelling...

Please sign up or login with your details

Forgot password? Click here to reset