Fetching the paper…
Reading the bibliography…
Object detectors, which are widely deployed in security-critical systems such as autonomous vehicles, have been found vulnerable to patch hiding attacks.
M. Ester, H. Kriegel, J. Sander, and X. Xu, “A density-based algorithm for discovering clusters in large spatial databases with noise,” in KDD , 1996
1996
Earlier work this paper cites.
M. Everingham, L. V. Gool, C. K. I. Williams, J. M. Winn, and A. Zisserman, “The pascal visual object classes (VOC) challenge,” International Journal of Computer Vision , 2010
2010
Earlier work this paper cites.
M. Barreno, B. Nelson, A. D. Joseph, and J. D. Tygar, “The security of machine learning,” Machine Learning , 2010
2010
Earlier work this paper cites.
A. Geiger, P. Lenz, C. Stiller, and R. Urtasun, “Vision meets robotics: The kitti dataset,” The International Journal of Robotics Research , 2013
2013
Earlier work this paper cites.
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli, “Evasion attacks against machine learning at test time,” in ECML PKDD , 2013
2013
Earlier work this paper cites.
T. Lin, M. Maire, S. J. Belongie, J. Hays, P. Perona, D. Ramanan, P. Dollár, and C. L. Zitnick, “Microsoft COCO: common objects in context,” in ECCV , 2014
2014
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in ICLR , 2014
2014
Earlier work this paper cites.
S. Ren, K. He, R. Girshick, and J. Sun, “Faster r-cnn: Towards real-time object detection with region proposal networks,” in NeurIPS , 2015
2015
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in ICLR , 2015
2015
Earlier work this paper cites.
J. Redmon, S. Divvala, R. Girshick, and A. Farhadi, “You only look once: Unified, real-time object detection,” in IEEE CVPR , 2016
2016
Earlier work this paper cites.
W. Liu, D. Anguelov, D. Erhan, C. Szegedy, S. E. Reed, C. Fu, and A. C. Berg, “SSD: single shot multibox detector,” in ECCV , 2016
2016
Earlier work this paper cites.
N. Papernot, P. D. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in EuroS&P , 2016
2016
Earlier work this paper cites.
N. Papernot, P. D. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in IEEE S&P , 2016
2016
Earlier work this paper cites.
T. B. Brown, D. Mané, A. Roy, M. Abadi, and J. Gilmer, “Adversarial patch,” in NeurIPS Workshop , 2017
2017
Earlier work this paper cites.
K. He, G. Gkioxari, P. Dollár, and R. B. Girshick, “Mask R-CNN,” in ICCV , 2017
2017
Earlier work this paper cites.
J. Redmon and A. Farhadi, “Yolo9000: better, faster, stronger,” in CVPR , 2017
2017
Earlier work this paper cites.
T. Lin, P. Goyal, R. B. Girshick, K. He, and P. Dollár, “Focal loss for dense object detection,” in ICCV . IEEE Computer Society, 2017
2017
Earlier work this paper cites.
J. Lu, H. Sibai, and E. Fabry, “Adversarial examples that fool detectors,” arXiv:1712.02494 , 2017
2017
Earlier work this paper cites.
D. Meng and H. Chen, “Magnet: A two-pronged defense against adversarial examples,” in CCS , 2017
2017
Earlier work this paper cites.
N. Carlini and D. A. Wagner, “Towards evaluating the robustness of neural networks,” in IEEE S&P , 2017
2017
Earlier work this paper cites.
——, “Yolov3: An incremental improvement,” arXiv:1804.02767 , 2018
2018
Earlier work this paper cites.
D. Karmon, D. Zoran, and Y. Goldberg, “LaVAN: Localized and visible adversarial noise,” in ICML , 2018
2018
Earlier work this paper cites.
S.-T. Chen, C. Cornelius, J. Martin, and D. H. P. Chau, “Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector,” in Joint European Conference on Machine Learning and Knowledge Discovery in Databases . Springer, 2018
2018
Earlier work this paper cites.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, F. Tramer, A. Prakash, T. Kohno, and D. Song, “Physical adversarial examples for object detectors,” in USENIX WOOT Workshop , 2018
2018
Earlier work this paper cites.
J. Hayes, “On visible adversarial perturbations & digital watermarking,” in CVPR Workshop , 2018
2018
Cited alongside, same era.
W. Xu, D. Evans, and Y. Qi, “Feature squeezing: Detecting adversarial examples in deep neural networks,” in NDSS , 2018
2018
Cited alongside, same era.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in ICLR , 2018
2018
Cited alongside, same era.
A. Raghunathan, J. Steinhardt, and P. Liang, “Certified defenses against adversarial examples,” in ICLR , 2018
2018
Cited alongside, same era.
E. Wong and J. Z. Kolter, “Provable defenses against adversarial examples via the convex outer adversarial polytope,” in ICML , 2018
2018
Cited alongside, same era.
A. Liu, J. Wang, X. Liu, B. Cao, C. Zhang, and H. Yu, “Bias-based universal adversarial patch attack for automatic check-out,” in ECCV , 2020
2020
Later among the works it cites.
T. Wu, L. Tong, and Y. Vorobeychik, “Defending against physically realizable attacks on image classification,” in ICLR , 2020
2020
Later among the works it cites.
S. Rao, D. Stutz, and B. Schiele, “Adversarial training against location-optimized adversarial patches,” in ECCV Workshop , 2020
2020
Later among the works it cites.
P.-Y. Chiang, R. Ni, A. Abdelkader, C. Zhu, C. Studor, and T. Goldstein, “Certified defenses for adversarial patches,” in ICLR , 2020
2020
Later among the works it cites.
Z. Zhang, B. Yuan, M. McCoyd, and D. Wagner, “Clipped bagnet: Defending against sticker attacks with clipped bag-of-features,” in Deep Learning and Security Workshop (DLS) , 2020
2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
M. Mirman, T. Gehr, and M. T. Vechev, “Differentiable abstract interpretation for provably robust neural networks,” in ICML , 2018
2018
Cited alongside, same era.
Y. Zhao, H. Zhu, R. Liang, Q. Shen, S. Zhang, and K. Chen, “Seeing isn’t believing: Towards more robust adversarial attack against real world object detectors,” in CCS , 2019
2019
Cited alongside, same era.
S. Thys, W. Van Ranst, and T. Goedemé, “Fooling automated surveillance cameras: adversarial patches to attack person detection,” in CVPR Workshop , 2019
2019
Cited alongside, same era.
H. Zhang and J. Wang, “Towards adversarially robust object detection,” in ICCV . IEEE, 2019
2019
Cited alongside, same era.
A. Liu, X. Liu, J. Fan, Y. Ma, A. Zhang, H. Xie, and D. Tao, “Perceptual-sensitive GAN for generating adversarial patches,” in AAAI , 2019
2019
Cited alongside, same era.
X. Liu, H. Yang, Z. Liu, L. Song, Y. Chen, and H. Li, “DPATCH: an adversarial patch attack on object detectors,” in AAAI Workshop , 2019
2019
Cited alongside, same era.
M. Naseer, S. Khan, and F. Porikli, “Local gradients smoothing: Defense against localized adversarial attacks,” in WACV , 2019
2019
Cited alongside, same era.
Later among the works it cites.
A. Levine and S. Feizi, “(De)randomized smoothing for certifiable defense against patch attacks,” in NeurIPS , 2020
2020
Later among the works it cites.
Y.-C.-T. Hu, B.-H. Kung, D. S. Tan, J.-C. Chen, K.-L. Hua, and W.-H. Cheng, “Naturalistic physical adversarial patch for object detectors,” in ICCV , 2021
2021
Later among the works it cites.
J. Tan, N. Ji, H. Xie, and X. Xiang, “Legitimate adversarial patches: Evading human eyes and detection models in the physical world,” in ACM International Conference on Multimedia , 2021
2021
Later among the works it cites.
J. H. Metzen, N. Finnie, and R. Hutmacher, “Meta adversarial training against universal patches,” in ICML Workshop , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
P.-H. Chiang, C.-S. Chan, and S.-H. Wu, “Adversarial pixel masking: A defense against physical attacks for pre-trained object detectors,” in International Conference on Multimedia , 2021
2021
Later among the works it cites.
C. Xiang and P. Mittal, “Detectorguard: Provably securing object detectors against localized patch hiding attacks,” in ACM CCS , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
Z. Liu, Y. Lin, Y. Cao, H. Hu, Y. Wei, Z. Zhang, S. Lin, and B. Guo, “Swin transformer: Hierarchical vision transformer using shifted windows,” in ICCV , 2021
2021
Later among the works it cites.
C. Xiang, A. N. Bhagoji, V. Sehwag, and P. Mittal, “Patchguard: A provably robust defense against adversarial patches via small receptive fields and masking,” in USENIX Security , 2021
2021
Later among the works it cites.
C. Xiang and P. Mittal, “Patchguard++: Efficient provable attack detection against adversarial patches,” in ICLR Workshop , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
N. Mu and D. Wagner, “Defending against adversarial patches with robust self-attention,” in ICML Workshop , 2021
2021
Later among the works it cites.
J. H. Metzen and M. Yatsura, “Efficient certified defenses against patch attacks on image classifiers,” in ICLR , 2021
2021
Later among the works it cites.
H. Han, K. Xu, X. Hu, X. Chen, L. Liang, Z. Du, Q. Guo, Y. Wang, and Y. Chen, “Scalecert: Scalable certified defense against adversarial patches with sparse superficial layers,” in NeurIPS , 2021
2021
Later among the works it cites.
C. Xiang, S. Mahloujifar, and P. Mittal, “Patchcleanser: Certifiably robust defense against adversarial patches for any image classifier,” in USENIX Security , 2022
2022
Closest in time.
H. Salman, S. Jain, E. Wong, and A. Madry, “Certified patch robustness via smoothed vision transformers,” in CVPR , 2022
2022
Closest in time.