Transferable Physical-World Adversarial Patches Against Pedestrian Detection Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yan, Shihui, Zhou, Ziqi, Song, Yufei, Hu, Yifan, Li, Minghui, Hu, Shengshan
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914504784216064
author Yan, Shihui
Zhou, Ziqi
Song, Yufei
Hu, Yifan
Li, Minghui
Hu, Shengshan
author_facet Yan, Shihui
Zhou, Ziqi
Song, Yufei
Hu, Yifan
Li, Minghui
Hu, Shengshan
contents Physical adversarial patch attacks critically threaten pedestrian detection, causing surveillance and autonomous driving systems to miss pedestrians and creating severe safety risks. Despite their effectiveness in controlled settings, existing physical attacks face two major limitations in practice: they lack systematic disruption of the multi-stage decision pipeline, enabling residual modules to offset perturbations, and they fail to model complex physical variations, leading to poor robustness. To overcome these limitations, we propose a novel pedestrian adversarial patch generation method that combines multi-stage collaborative attacks with robustness enhancement under physical diversity, called TriPatch. Specifically, we design a triplet loss consisting of detection confidence suppression, bounding-box offset amplification, and non-maximum suppression (NMS) disruption, which jointly act across different stages of the detection pipeline. In addition, we introduce an appearance consistency loss to constrain the color distribution of the patch, thereby improving its adaptability under diverse imaging conditions, and incorporate data augmentation to further enhance robustness against complex physical perturbations. Extensive experiments demonstrate that TriPatch achieves a higher attack success rate across multiple detector models compared to existing approaches.
format Preprint
id arxiv_https___arxiv_org_abs_2604_22552
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Transferable Physical-World Adversarial Patches Against Pedestrian Detection Models
Yan, Shihui
Zhou, Ziqi
Song, Yufei
Hu, Yifan
Li, Minghui
Hu, Shengshan
Computer Vision and Pattern Recognition
Physical adversarial patch attacks critically threaten pedestrian detection, causing surveillance and autonomous driving systems to miss pedestrians and creating severe safety risks. Despite their effectiveness in controlled settings, existing physical attacks face two major limitations in practice: they lack systematic disruption of the multi-stage decision pipeline, enabling residual modules to offset perturbations, and they fail to model complex physical variations, leading to poor robustness. To overcome these limitations, we propose a novel pedestrian adversarial patch generation method that combines multi-stage collaborative attacks with robustness enhancement under physical diversity, called TriPatch. Specifically, we design a triplet loss consisting of detection confidence suppression, bounding-box offset amplification, and non-maximum suppression (NMS) disruption, which jointly act across different stages of the detection pipeline. In addition, we introduce an appearance consistency loss to constrain the color distribution of the patch, thereby improving its adaptability under diverse imaging conditions, and incorporate data augmentation to further enhance robustness against complex physical perturbations. Extensive experiments demonstrate that TriPatch achieves a higher attack success rate across multiple detector models compared to existing approaches.
title Transferable Physical-World Adversarial Patches Against Pedestrian Detection Models
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2604.22552