Benchmarking Adversarial Patch Selection and Location

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kimhi, Shai, Mendlson, Avi, Kimhi, Moshe
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916878191951872
author Kimhi, Shai
Mendlson, Avi
Kimhi, Moshe
author_facet Kimhi, Shai
Mendlson, Avi
Kimhi, Moshe
contents Adversarial patch attacks threaten the reliability of modern vision models. We present PatchMap, the first spatially exhaustive benchmark of patch placement, built by evaluating over 1.5e8 forward passes on ImageNet validation images. PatchMap reveals systematic hot-spots where small patches (as little as 2% of the image) induce confident misclassifications and large drops in model confidence. To demonstrate its utility, we propose a simple segmentation guided placement heuristic that leverages off the shelf masks to identify vulnerable regions without any gradient queries. Across five architectures-including adversarially trained ResNet50, our method boosts attack success rates by 8 to 13 percentage points compared to random or fixed placements. We publicly release PatchMap and the code implementation. The full PatchMap bench (6.5B predictions, multiple backbones) will be released soon to further accelerate research on location-aware defenses and adaptive attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2508_01676
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Benchmarking Adversarial Patch Selection and Location
Kimhi, Shai
Mendlson, Avi
Kimhi, Moshe
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
Adversarial patch attacks threaten the reliability of modern vision models. We present PatchMap, the first spatially exhaustive benchmark of patch placement, built by evaluating over 1.5e8 forward passes on ImageNet validation images. PatchMap reveals systematic hot-spots where small patches (as little as 2% of the image) induce confident misclassifications and large drops in model confidence. To demonstrate its utility, we propose a simple segmentation guided placement heuristic that leverages off the shelf masks to identify vulnerable regions without any gradient queries. Across five architectures-including adversarially trained ResNet50, our method boosts attack success rates by 8 to 13 percentage points compared to random or fixed placements. We publicly release PatchMap and the code implementation. The full PatchMap bench (6.5B predictions, multiple backbones) will be released soon to further accelerate research on location-aware defenses and adaptive attacks.
title Benchmarking Adversarial Patch Selection and Location
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2508.01676