Pith. sign in

REVIEW 1 cited by

Adversarial camera stickers: A physical camera-based attack on deep learning systems

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1904.00759 v4 pith:6PQ2H2XL submitted 2019-03-21 cs.CV cs.CRcs.LGstat.ML

classification cs.CVcs.CRcs.LGstat.ML
keywords adversarialattackscameradeeplearningobjectphysicalwork
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recent work has documented the susceptibility of deep learning systems to adversarial examples, but most such attacks directly manipulate the digital input to a classifier. Although a smaller line of work considers physical adversarial attacks, in all cases these involve manipulating the object of interest, e.g., putting a physical sticker on an object to misclassify it, or manufacturing an object specifically intended to be misclassified. In this work, we consider an alternative question: is it possible to fool deep classifiers, over all perceived objects of a certain type, by physically manipulating the camera itself? We show that by placing a carefully crafted and mainly-translucent sticker over the lens of a camera, one can create universal perturbations of the observed images that are inconspicuous, yet misclassify target objects as a different (targeted) class. To accomplish this, we propose an iterative procedure for both updating the attack perturbation (to make it adversarial for a given classifier), and the threat model itself (to ensure it is physically realizable). For example, we show that we can achieve physically-realizable attacks that fool ImageNet classifiers in a targeted fashion 49.6% of the time. This presents a new class of physically-realizable threat models to consider in the context of adversarially robust machine learning. Our demo video can be viewed at: https://youtu.be/wUVmL33Fx54

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Siren Song: Manipulating Pose Estimation in XR Headsets Using Acoustic Attacks

    cs.CR 2025-02 conditional novelty 7.0 of 10

    Loud tones near the HoloLens 2 IMU resonant frequency reset its pose estimate to the origin, enabling four proof-of-concept AR attacks: input manipulation, clickjacking, denial of interaction, and zone invasion.

Pith tools