about
Making an Invisibility Cloak: Real World Adversarial Attacks on Object Detectors (arxiv.org)
2 points by jonbaer on Nov 16, 2019 | hide | past | pdf | discuss on HN

In plain words: They trained printed patterns that make object detectors stop flagging an object, then tested them as posters and clothing in real life. The patterns hid objects from several detectors, even ones they weren't trained against, and across different object types and datasets.

Abstract

We present a systematic study of adversarial attacks on state-of-the-art object detection frameworks. Using standard detection datasets, we train patterns that suppress the objectness scores produced by a range of commonly used detectors, and ensembles of detectors. Through extensive experiments, we benchmark the effectiveness of adversarially trained patches under both white-box and black-box settings, and quantify transferability of attacks between datasets, object classes, and detector models. Finally, we present a detailed study of physical world attacks using printed posters and wearable clothes, and rigorously quantify the performance of such attacks with different metrics.

Zuxuan Wu, Ser-Nam Lim, Larry Davis, Tom Goldstein
arXiv:1910.14667 · cs.CV, cs.CR, cs.LG, math.OC · submitted Oct 31, 2019 · updated Jul 22, 2020
abstract · pdf · html · ECCV 2020

add comment on HN
Also discussed: Oct 2022 (38 points, 9 comments)