Pith. sign in

REVIEW 5 cited by

Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2201.08970 v1 pith:4IAX4I57 submitted 2022-01-22 cs.CV

classification cs.CV
keywords attackattackedblack-boxdetectionadversarialattacksbounding-boxobject
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Object detection has been widely used in many safety-critical tasks, such as autonomous driving. However, its vulnerability to adversarial examples has not been sufficiently studied, especially under the practical scenario of black-box attacks, where the attacker can only access the query feedback of predicted bounding-boxes and top-1 scores returned by the attacked model. Compared with black-box attack to image classification, there are two main challenges in black-box attack to detection. Firstly, even if one bounding-box is successfully attacked, another sub-optimal bounding-box may be detected near the attacked bounding-box. Secondly, there are multiple bounding-boxes, leading to very high attack cost. To address these challenges, we propose a Parallel Rectangle Flip Attack (PRFA) via random search. We explain the difference between our method with other attacks in Fig.~\ref{fig1}. Specifically, we generate perturbations in each rectangle patch to avoid sub-optimal detection near the attacked region. Besides, utilizing the observation that adversarial perturbations mainly locate around objects' contours and critical points under white-box attacks, the search space of attacked rectangles is reduced to improve the attack efficiency. Moreover, we develop a parallel mechanism of attacking multiple rectangles simultaneously to further accelerate the attack process. Extensive experiments demonstrate that our method can effectively and efficiently attack various popular object detectors, including anchor-based and anchor-free, and generate transferable adversarial examples.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. 3D Gaussian Splatting Driven Multi-View Robust Physical Adversarial Camouflage Generation

    cs.CV 2025-07 conditional novelty 7.0 of 10

    PGA uses 3D Gaussian Splatting to generate physical adversarial camouflage from a few images, improving multi-view attack robustness on vehicle detectors.

  2. Adversarial Generation and Collaborative Evolution of Safety-Critical Scenarios for Autonomous Vehicles

    cs.CV 2025-08 conditional novelty 6.0 of 10

    ScenGE generates more collision-prone autonomous driving test scenarios by combining LLM-suggested adversarial events with optimized background traffic, beating prior generators on CARLA benchmarks.

  3. Benchmarking the Robustness of Autonomous Driving to Environmental Illusions: A Lane Perception Perspective

    cs.CV 2026-07 conditional novelty 5.0 of 10

    Environmental illusions cause 5-7% accuracy drops in lane detection models and can trigger collisions in closed-loop simulation, with a proposed defense (MIDA) recovering ~4% robustness.

  4. Physical Adversarial Camouflage through Gradient Calibration and Regularization

    cs.CV 2025-08 conditional novelty 5.0 of 10

    Nearest Gradient Calibration and Loss-Prioritized Gradient Decorrelation reduce the AP@0.5 of a camouflaged vehicle detector from 13.19% to 2.16% with YOLOv3, and improve transfer to other detectors.

  5. Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025

    cs.CR 2025-06 conditional novelty 3.0 of 10

    The ATLAS 2025 competition demonstrates that vision-language models remain highly vulnerable to flowchart-based and cross-modal jailbreak attacks, with top scores exceeding 93%.

Pith tools