From Pixels to Reality: Physical-Digital Patch Attacks on Real-World Camera

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Leonenkova, Victoria, Shumitskaya, Ekaterina, Vatolin, Dmitriy, Antsiferova, Anastasia
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917369308250112
author Leonenkova, Victoria
Shumitskaya, Ekaterina
Vatolin, Dmitriy
Antsiferova, Anastasia
author_facet Leonenkova, Victoria
Shumitskaya, Ekaterina
Vatolin, Dmitriy
Antsiferova, Anastasia
contents This demonstration presents Digital-Physical Adversarial Attacks (DiPA), a new class of practical adversarial attacks against pervasive camera-based authentication systems, where an attacker displays an adversarial patch directly on a smartphone screen instead of relying on printed artifacts. This digital-only physical presentation enables rapid deployment, removes the need for total-variation regularization, and improves patch transferability in black-box conditions. DiPA leverages an ensemble of state-of-the-art face-recognition models (ArcFace, MagFace, CosFace) to enhance transfer across unseen commercial systems. Our interactive demo shows a real-time dodging attack against a deployed face-recognition camera, preventing authorized users from being recognized while participants dynamically adjust patch patterns and observe immediate effects on the sensing pipeline. We further demonstrate DiPA's superiority over existing physical attacks in terms of success rate, feature-space distortion, and reductions in detection confidence, highlighting critical vulnerabilities at the intersection of mobile devices, pervasive vision, and sensor-driven authentication infrastructures.
format Preprint
id arxiv_https___arxiv_org_abs_2603_28425
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle From Pixels to Reality: Physical-Digital Patch Attacks on Real-World Camera
Leonenkova, Victoria
Shumitskaya, Ekaterina
Vatolin, Dmitriy
Antsiferova, Anastasia
Computer Vision and Pattern Recognition
This demonstration presents Digital-Physical Adversarial Attacks (DiPA), a new class of practical adversarial attacks against pervasive camera-based authentication systems, where an attacker displays an adversarial patch directly on a smartphone screen instead of relying on printed artifacts. This digital-only physical presentation enables rapid deployment, removes the need for total-variation regularization, and improves patch transferability in black-box conditions. DiPA leverages an ensemble of state-of-the-art face-recognition models (ArcFace, MagFace, CosFace) to enhance transfer across unseen commercial systems. Our interactive demo shows a real-time dodging attack against a deployed face-recognition camera, preventing authorized users from being recognized while participants dynamically adjust patch patterns and observe immediate effects on the sensing pipeline. We further demonstrate DiPA's superiority over existing physical attacks in terms of success rate, feature-space distortion, and reductions in detection confidence, highlighting critical vulnerabilities at the intersection of mobile devices, pervasive vision, and sensor-driven authentication infrastructures.
title From Pixels to Reality: Physical-Digital Patch Attacks on Real-World Camera
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2603.28425