Transferable Physical-World Adversarial Patches Against Object Detection in Autonomous Driving

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhu, Zihui, Zhou, Ziqi, Wang, Yichen, Xue, Lulu, Li, Minghui, Hu, Shengshan
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917436435988480
author Zhu, Zihui
Zhou, Ziqi
Wang, Yichen
Xue, Lulu
Li, Minghui
Hu, Shengshan
author_facet Zhu, Zihui
Zhou, Ziqi
Wang, Yichen
Xue, Lulu
Li, Minghui
Hu, Shengshan
contents Deep learning drives major advances in autonomous driving (AD), where object detectors are central to perception. However, adversarial attacks pose significant threats to the reliability and safety of these systems, with physical adversarial patches representing a particularly potent form of attack. Physical adversarial patch attacks pose severe risks but are usually crafted for a single model, yielding poor transferability to unseen detectors. We propose AdvAD, a transfer-based physical attack against object detection in autonomous driving. Instead of targeting a specific detector, AdvAD optimizes adversarial patches over multiple detection models in a unified framework, encouraging the learned perturbations to capture shared vulnerabilities across architectures. The optimization process adaptively balances model contributions and enforces robustness to physical variations. It further employs data augmentation and geometric transformations to maintain patch effectiveness under diverse physical conditions. Experiments in both digital and real-world settings show that AdvAD consistently outperforms state-of-the-art (SOTA) attacks in performance and transferability.
format Preprint
id arxiv_https___arxiv_org_abs_2604_23105
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Transferable Physical-World Adversarial Patches Against Object Detection in Autonomous Driving
Zhu, Zihui
Zhou, Ziqi
Wang, Yichen
Xue, Lulu
Li, Minghui
Hu, Shengshan
Computer Vision and Pattern Recognition
Deep learning drives major advances in autonomous driving (AD), where object detectors are central to perception. However, adversarial attacks pose significant threats to the reliability and safety of these systems, with physical adversarial patches representing a particularly potent form of attack. Physical adversarial patch attacks pose severe risks but are usually crafted for a single model, yielding poor transferability to unseen detectors. We propose AdvAD, a transfer-based physical attack against object detection in autonomous driving. Instead of targeting a specific detector, AdvAD optimizes adversarial patches over multiple detection models in a unified framework, encouraging the learned perturbations to capture shared vulnerabilities across architectures. The optimization process adaptively balances model contributions and enforces robustness to physical variations. It further employs data augmentation and geometric transformations to maintain patch effectiveness under diverse physical conditions. Experiments in both digital and real-world settings show that AdvAD consistently outperforms state-of-the-art (SOTA) attacks in performance and transferability.
title Transferable Physical-World Adversarial Patches Against Object Detection in Autonomous Driving
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2604.23105