Adversarial Attacks in a Multi-view Setting: An Empirical Study of the Adversarial Patches Inter-view Transferability

While machine learning applications are getting mainstream owing to a\ndemonstrated efficiency in solving complex problems, they suffer from inherent\nvulnerability to adversarial attacks. Adversarial attacks consist of additive\nnoise to an input which can fool a detector. Recently, successful real-world\nprintable adversarial patches were proven efficient against state-of-the-art\nneural networks. In the transition from digital noise based attacks to\nreal-world physical attacks, the myriad of factors affecting object detection\nwill also affect adversarial patches. Among these factors, view angle is one of\nthe most influential, yet under-explored. In this paper, we study the effect of\nview angle on the effectiveness of an adversarial patch. To this aim, we\npropose the first approach that considers a multi-view context by combining\nexisting adversarial patches with a perspective geometric transformation in\norder to simulate the effect of view angle changes. Our approach has been\nevaluated on two datasets: the first dataset which contains most real world\nconstraints of a multi-view context, and the second dataset which empirically\nisolates the effect of view angle. The experiments show that view angle\nsignificantly affects the performance of adversarial patches, where in some\ncases the patch loses most of its effectiveness. We believe that these results\nmotivate taking into account the effect of view angles in future adversarial\nattacks, and open up new opportunities for adversarial defenses.\n

Paper

References (15)

Scroll for more · 3 remaining

Similar papers

© 2026 NYSGPT2525 LLC