Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New Insights

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zheng, Junhao, Sun, Jiahao, Lin, Chenhao, Zhao, Zhengyu, Ma, Chen, Zhang, Chong, Wang, Cong, Wang, Qian, Shen, Chao
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911095694819328
author Zheng, Junhao
Sun, Jiahao
Lin, Chenhao
Zhao, Zhengyu
Ma, Chen
Zhang, Chong
Wang, Cong
Wang, Qian
Shen, Chao
author_facet Zheng, Junhao
Sun, Jiahao
Lin, Chenhao
Zhao, Zhengyu
Ma, Chen
Zhang, Chong
Wang, Cong
Wang, Qian
Shen, Chao
contents Developing reliable defenses against patch attacks on object detectors has attracted increasing interest. However, we identify that existing defense evaluations lack a unified and comprehensive framework, resulting in inconsistent and incomplete assessments of current methods. To address this issue, we revisit 11 representative defenses and present the first patch defense benchmark, involving 2 attack goals, 13 patch attacks, 11 object detectors, and 4 diverse metrics. This leads to the large-scale adversarial patch dataset with 94 types of patches and 94,000 images. Our comprehensive analyses reveal new insights: (1) The difficulty in defending against naturalistic patches lies in the data distribution, rather than the commonly believed high frequencies. Our new dataset with diverse patch distributions can be used to improve existing defenses by 15.09% AP@0.5. (2) The average precision of the attacked object, rather than the commonly pursued patch detection accuracy, shows high consistency with defense performance. (3) Adaptive attacks can substantially bypass existing defenses, and defenses with complex/stochastic models or universal patch properties are relatively robust. We hope that our analyses will serve as guidance on properly evaluating patch attacks/defenses and advancing their design. Code and dataset are available at https://github.com/Gandolfczjh/APDE, where we will keep integrating new attacks/defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2508_00649
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New Insights
Zheng, Junhao
Sun, Jiahao
Lin, Chenhao
Zhao, Zhengyu
Ma, Chen
Zhang, Chong
Wang, Cong
Wang, Qian
Shen, Chao
Computer Vision and Pattern Recognition
Cryptography and Security
Developing reliable defenses against patch attacks on object detectors has attracted increasing interest. However, we identify that existing defense evaluations lack a unified and comprehensive framework, resulting in inconsistent and incomplete assessments of current methods. To address this issue, we revisit 11 representative defenses and present the first patch defense benchmark, involving 2 attack goals, 13 patch attacks, 11 object detectors, and 4 diverse metrics. This leads to the large-scale adversarial patch dataset with 94 types of patches and 94,000 images. Our comprehensive analyses reveal new insights: (1) The difficulty in defending against naturalistic patches lies in the data distribution, rather than the commonly believed high frequencies. Our new dataset with diverse patch distributions can be used to improve existing defenses by 15.09% AP@0.5. (2) The average precision of the attacked object, rather than the commonly pursued patch detection accuracy, shows high consistency with defense performance. (3) Adaptive attacks can substantially bypass existing defenses, and defenses with complex/stochastic models or universal patch properties are relatively robust. We hope that our analyses will serve as guidance on properly evaluating patch attacks/defenses and advancing their design. Code and dataset are available at https://github.com/Gandolfczjh/APDE, where we will keep integrating new attacks/defenses.
title Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New Insights
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2508.00649