Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
97 tokens/sec
GPT-4o
53 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
5 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

PatchZero: Defending against Adversarial Patch Attacks by Detecting and Zeroing the Patch (2207.01795v3)

Published 5 Jul 2022 in cs.CV, cs.CR, and cs.LG

Abstract: Adversarial patch attacks mislead neural networks by injecting adversarial pixels within a local region. Patch attacks can be highly effective in a variety of tasks and physically realizable via attachment (e.g. a sticker) to the real-world objects. Despite the diversity in attack patterns, adversarial patches tend to be highly textured and different in appearance from natural images. We exploit this property and present PatchZero, a general defense pipeline against white-box adversarial patches without retraining the downstream classifier or detector. Specifically, our defense detects adversaries at the pixel-level and "zeros out" the patch region by repainting with mean pixel values. We further design a two-stage adversarial training scheme to defend against the stronger adaptive attacks. PatchZero achieves SOTA defense performance on the image classification (ImageNet, RESISC45), object detection (PASCAL VOC), and video classification (UCF101) tasks with little degradation in benign performance. In addition, PatchZero transfers to different patch shapes and attack types.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (5)
  1. Ke Xu (309 papers)
  2. Yao Xiao (77 papers)
  3. Zhaoheng Zheng (12 papers)
  4. Kaijie Cai (1 paper)
  5. Ram Nevatia (54 papers)
Citations (21)

Summary

We haven't generated a summary for this paper yet.