Detection of Uncertainty in Exceedance of Threshold (DUET): An Adversarial Patch Localizer

03/18/2023
by   Terence Jie Chua, et al.
0

Development of defenses against physical world attacks such as adversarial patches is gaining traction within the research community. We contribute to the field of adversarial patch detection by introducing an uncertainty-based adversarial patch localizer which localizes adversarial patch on an image, permitting post-processing patch-avoidance or patch-reconstruction. We quantify our prediction uncertainties with the development of Detection of Uncertainties in the Exceedance of Threshold (DUET) algorithm. This algorithm provides a framework to ascertain confidence in the adversarial patch localization, which is essential for safety-sensitive applications such as self-driving cars and medical imaging. We conducted experiments on localizing adversarial patches and found our proposed DUET model outperforms baseline models. We then conduct further analyses on our choice of model priors and the adoption of Bayesian Neural Networks in different layers within our model architecture. We found that isometric gaussian priors in Bayesian Neural Networks are suitable for patch localization tasks and the presence of Bayesian layers in the earlier neural network blocks facilitates top-end localization performance, while Bayesian layers added in the later neural network blocks contribute to better model generalization. We then propose two different well-performing models to tackle different use cases.

READ FULL TEXT

page 1

page 2

page 4

page 7

page 8

research
04/20/2023

Jedi: Entropy-based Localization and Removal of Adversarial Patches

Real-world adversarial physical patches were shown to be successful in c...
research
12/08/2021

Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch Detection

Object detection plays a key role in many security-critical systems. Adv...
research
06/25/2022

Empirical Evaluation of Physical Adversarial Patch Attacks Against Overhead Object Detection Models

Adversarial patches are images designed to fool otherwise well-performin...
research
07/26/2023

Defending Adversarial Patches via Joint Region Localizing and Inpainting

Deep neural networks are successfully used in various applications, but ...
research
06/16/2022

Adversarial Patch Attacks and Defences in Vision-Based Tasks: A Survey

Adversarial attacks in deep learning models, especially for safety-criti...
research
02/08/2021

Efficient Certified Defenses Against Patch Attacks on Image Classifiers

Adversarial patches pose a realistic threat model for physical world att...
research
03/03/2023

AdvART: Adversarial Art for Camouflaged Object Detection Attacks

A majority of existing physical attacks in the real world result in cons...

Please sign up or login with your details

Forgot password? Click here to reset