Saved in:
Bibliographic Details
Main Authors: Li, Chaoqun, Yan, Huanqian, Zhou, Lifeng, Chen, Tairan, Liu, Zhuodong, Su, Hang
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2411.10498
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916483237412864
author Li, Chaoqun
Yan, Huanqian
Zhou, Lifeng
Chen, Tairan
Liu, Zhuodong
Su, Hang
author_facet Li, Chaoqun
Yan, Huanqian
Zhou, Lifeng
Chen, Tairan
Liu, Zhuodong
Su, Hang
contents Adversarial attacks in the physical world pose a significant threat to the security of vision-based systems, such as facial recognition and autonomous driving. Existing adversarial patch methods primarily focus on improving attack performance, but they often produce patches that are easily detectable by humans and struggle to achieve environmental consistency, i.e., blending patches into the environment. This paper introduces a novel approach for generating adversarial patches, which addresses both the visual naturalness and environmental consistency of the patches. We propose Prompt-Guided Environmentally Consistent Adversarial Patch (PG-ECAP), a method that aligns the patch with the environment to ensure seamless integration into the environment. The approach leverages diffusion models to generate patches that are both environmental consistency and effective in evading detection. To further enhance the naturalness and consistency, we introduce two alignment losses: Prompt Alignment Loss and Latent Space Alignment Loss, ensuring that the generated patch maintains its adversarial properties while fitting naturally within its environment. Extensive experiments in both digital and physical domains demonstrate that PG-ECAP outperforms existing methods in attack success rate and environmental consistency.
format Preprint
id arxiv_https___arxiv_org_abs_2411_10498
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Prompt-Guided Environmentally Consistent Adversarial Patch
Li, Chaoqun
Yan, Huanqian
Zhou, Lifeng
Chen, Tairan
Liu, Zhuodong
Su, Hang
Computer Vision and Pattern Recognition
Adversarial attacks in the physical world pose a significant threat to the security of vision-based systems, such as facial recognition and autonomous driving. Existing adversarial patch methods primarily focus on improving attack performance, but they often produce patches that are easily detectable by humans and struggle to achieve environmental consistency, i.e., blending patches into the environment. This paper introduces a novel approach for generating adversarial patches, which addresses both the visual naturalness and environmental consistency of the patches. We propose Prompt-Guided Environmentally Consistent Adversarial Patch (PG-ECAP), a method that aligns the patch with the environment to ensure seamless integration into the environment. The approach leverages diffusion models to generate patches that are both environmental consistency and effective in evading detection. To further enhance the naturalness and consistency, we introduce two alignment losses: Prompt Alignment Loss and Latent Space Alignment Loss, ensuring that the generated patch maintains its adversarial properties while fitting naturally within its environment. Extensive experiments in both digital and physical domains demonstrate that PG-ECAP outperforms existing methods in attack success rate and environmental consistency.
title Prompt-Guided Environmentally Consistent Adversarial Patch
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2411.10498