CAPAA: Classifier-Agnostic Projector-Based Adversarial Attack

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Zhan, Zhao, Mingyu, Dong, Xin, Ling, Haibin, Huang, Bingyao
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915333783158784
author Li, Zhan
Zhao, Mingyu
Dong, Xin
Ling, Haibin
Huang, Bingyao
author_facet Li, Zhan
Zhao, Mingyu
Dong, Xin
Ling, Haibin
Huang, Bingyao
contents Projector-based adversarial attack aims to project carefully designed light patterns (i.e., adversarial projections) onto scenes to deceive deep image classifiers. It has potential applications in privacy protection and the development of more robust classifiers. However, existing approaches primarily focus on individual classifiers and fixed camera poses, often neglecting the complexities of multi-classifier systems and scenarios with varying camera poses. This limitation reduces their effectiveness when introducing new classifiers or camera poses. In this paper, we introduce Classifier-Agnostic Projector-Based Adversarial Attack (CAPAA) to address these issues. First, we develop a novel classifier-agnostic adversarial loss and optimization framework that aggregates adversarial and stealthiness loss gradients from multiple classifiers. Then, we propose an attention-based gradient weighting mechanism that concentrates perturbations on regions of high classification activation, thereby improving the robustness of adversarial projections when applied to scenes with varying camera poses. Our extensive experimental evaluations demonstrate that CAPAA achieves both a higher attack success rate and greater stealthiness compared to existing baselines. Codes are available at: https://github.com/ZhanLiQxQ/CAPAA.
format Preprint
id arxiv_https___arxiv_org_abs_2506_00978
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle CAPAA: Classifier-Agnostic Projector-Based Adversarial Attack
Li, Zhan
Zhao, Mingyu
Dong, Xin
Ling, Haibin
Huang, Bingyao
Computer Vision and Pattern Recognition
Cryptography and Security
Projector-based adversarial attack aims to project carefully designed light patterns (i.e., adversarial projections) onto scenes to deceive deep image classifiers. It has potential applications in privacy protection and the development of more robust classifiers. However, existing approaches primarily focus on individual classifiers and fixed camera poses, often neglecting the complexities of multi-classifier systems and scenarios with varying camera poses. This limitation reduces their effectiveness when introducing new classifiers or camera poses. In this paper, we introduce Classifier-Agnostic Projector-Based Adversarial Attack (CAPAA) to address these issues. First, we develop a novel classifier-agnostic adversarial loss and optimization framework that aggregates adversarial and stealthiness loss gradients from multiple classifiers. Then, we propose an attention-based gradient weighting mechanism that concentrates perturbations on regions of high classification activation, thereby improving the robustness of adversarial projections when applied to scenes with varying camera poses. Our extensive experimental evaluations demonstrate that CAPAA achieves both a higher attack success rate and greater stealthiness compared to existing baselines. Codes are available at: https://github.com/ZhanLiQxQ/CAPAA.
title CAPAA: Classifier-Agnostic Projector-Based Adversarial Attack
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2506.00978