Distillation-Enhanced Physical Adversarial Attacks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Liu, Wei, Wu, Yonglin, Li, Chaoqun, Liu, Zhuodong, Yan, Huanqian
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915090533449728
author Liu, Wei
Wu, Yonglin
Li, Chaoqun
Liu, Zhuodong
Yan, Huanqian
author_facet Liu, Wei
Wu, Yonglin
Li, Chaoqun
Liu, Zhuodong
Yan, Huanqian
contents The study of physical adversarial patches is crucial for identifying vulnerabilities in AI-based recognition systems and developing more robust deep learning models. While recent research has focused on improving patch stealthiness for greater practical applicability, achieving an effective balance between stealth and attack performance remains a significant challenge. To address this issue, we propose a novel physical adversarial attack method that leverages knowledge distillation. Specifically, we first define a stealthy color space tailored to the target environment to ensure smooth blending. Then, we optimize an adversarial patch in an unconstrained color space, which serves as the 'teacher' patch. Finally, we use an adversarial knowledge distillation module to transfer the teacher patch's knowledge to the 'student' patch, guiding the optimization of the stealthy patch. Experimental results show that our approach improves attack performance by 20%, while maintaining stealth, highlighting its practical value.
format Preprint
id arxiv_https___arxiv_org_abs_2501_02232
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Distillation-Enhanced Physical Adversarial Attacks
Liu, Wei
Wu, Yonglin
Li, Chaoqun
Liu, Zhuodong
Yan, Huanqian
Computer Vision and Pattern Recognition
The study of physical adversarial patches is crucial for identifying vulnerabilities in AI-based recognition systems and developing more robust deep learning models. While recent research has focused on improving patch stealthiness for greater practical applicability, achieving an effective balance between stealth and attack performance remains a significant challenge. To address this issue, we propose a novel physical adversarial attack method that leverages knowledge distillation. Specifically, we first define a stealthy color space tailored to the target environment to ensure smooth blending. Then, we optimize an adversarial patch in an unconstrained color space, which serves as the 'teacher' patch. Finally, we use an adversarial knowledge distillation module to transfer the teacher patch's knowledge to the 'student' patch, guiding the optimization of the stealthy patch. Experimental results show that our approach improves attack performance by 20%, while maintaining stealth, highlighting its practical value.
title Distillation-Enhanced Physical Adversarial Attacks
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2501.02232