REVIEW 3 major objections 5 minor 52 references
Physics-Based Adversarial Attack on Near-Infrared Human Detector for Nighttime Surveillance Camera Systems
T0 review · 3 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read Binary patterns of retro-reflective and insulating tape, searched in digital space on 3D human models and pasted onto clothing, hide a person from a YOLOv5 near-infrared human detector in physical tests, with an average attack success…
desk verdict First physical NIR human-detector attack; the core physics is solid, but the headline physical result runs against a generic YOLO, not a NIR-trained detector, so the broad conclusion needs tempering. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is retro-reflective tape: because it reflects light back along the incoming direction, it appears bright in a co-located camera/illuminant geometry no matter how the tape is oriented, letting the wearer write $0$ or $255$ brightness values onto the NIR image. The search machinery is a black-box genetic algorithm over 31 semantic body-part binary patterns, rendered on SMPL-based 3D human models from random viewpoints and composited with real NIR backgrounds, with the detector's average confidence as the fitness function.
What would settle it
Capture the same physical setup with the 850-nm LED moved off-axis from the camera and measure the attack success rate of the unchanged tape pattern; if the detector still fails around 87.93% of frames, the claim that retro-reflective brightening under co-located geometry drives the attack is falsified.
Extended reading notes
Core claim
The central claim is that the design of NIR nighttime surveillance itself creates an attack surface: the camera's color channels respond almost identically at NIR wavelengths, the spectral reflectance of dyed fabric flattens so clothing textures disappear, and the nearly co-located 850-nm LEDs and camera make it easy to change image brightness with retro-reflective material. The authors demonstrate that covering parts of clothing with retro-reflective tape, which returns light toward its source and therefore appears bright regardless of orientation, and black insulating tape, which appears dark, lets an attacker write binary brightness patterns directly onto the NIR image. They search those body-part patterns with a black-box genetic algorithm over 3D human models without needing model weights or gradients, then paste the winning pattern on a person. On a YOLOv5 detector the pattern achieves an average physical attack success rate of 87.93% at 3–5 meters, and the NIR-finetuned detector is attacked even more easily in digital tests, supporting the claim that NIR-based AI image understanding is fragile.
Load-bearing premise
The argument assumes that one detector model and a small near-infrared training set represent what real surveillance systems use; if actual systems are trained on far more varied data, the demonstrated success rate may not transfer.
Editorial extensions
If this is right
- A person wearing the tape pattern can evade a YOLOv5 human detector in physical NIR surveillance footage at 3–5 meters, with an average attack success rate of 87.93%.
- The attack is fully passive and inexpensive, requiring no knowledge of model parameters, no gradient access, and no active light-emitting hardware.
- Because the NIR-finetuned YOLOv5 was easier to attack than the official checkpoint, specialized NIR training does not by itself remove the vulnerability.
- The pattern transfers across camera angles and distances because the search is performed on 3D human models rendered from arbitrary viewpoints.
- Altering the co-located camera/LED geometry is a fundamental defense, since the tape's brightening effect depends on light returning along the viewing axis.
Reading between the lines
- Not settled by the paper: a detector trained on a much larger, more diverse NIR corpus, or a different architecture, might resist the same pattern; the evidence covers one YOLOv5 checkpoint and a 13-identity finetuning set.
- A natural next experiment is to move the 850-nm LED off the lens axis; if the physical attack success rate collapses, the paper's co-location mechanism is confirmed as the operative cause.
- Because retro-reflective tape brightens NIR regardless of its visible color, the same attack could be rendered as normal-looking clothing, a design direction the paper demonstrates qualitatively but does not quantify with a user study.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper argues that near-infrared (NIR) surveillance imagery is inherently vulnerable to physically realizable adversarial attacks because of color and texture loss in the NIR band and because the co-located placement of NIR illuminants and cameras allows simple intensity manipulation via retro-reflective and insulating tapes. The authors design binary clothing patterns using a black-box genetic algorithm over SMPL-based 3D human renderings, combine these patterns with real NIR backgrounds, and evaluate the resulting attack in both digital and physical settings against YOLOv5-based detectors. The paper reports strong digital attack success rates (up to 94.14% ASR on a finetuned NIR detector, Table 1) and a physical attack success rate of 87.93% on average against the official COCO-pretrained YOLOv5 (Table 2). The central claim is that these results reveal significant reliability concerns for nighttime surveillance systems powered by NIR AI algorithms.
Significance. If the results hold, the paper would be one of the first to demonstrate a fully passive, low-cost physical attack specifically targeting NIR-based human detection, an important and underexplored security domain. The work has several concrete strengths: it identifies a physical mechanism (co-located illumination plus retro-reflective materials) that is well grounded in imaging optics; it uses a black-box, 3D-aware search that avoids gradient access; it includes physical validation with qualitative RGB/NIR stealthiness results; and it releases code. The digital evaluation includes error bars and compares against reasonable baselines (all black, all white, random). However, the physical evaluation is limited in scope and, as detailed in the major comments, the experimental bridge between the physical demonstration and the paper's broad conclusion about NIR-based surveillance AI is incomplete.
major comments (3)
- [Sec. 5.2.2, Table 2] The physical attack experiments are conducted only against the official COCO-pretrained YOLOv5, not against the NIR-finetuned detector described in Sec. 5.1. The 87.93% average ASR in Table 2 therefore demonstrates an attack on an RGB-trained model, not on the NIR-based surveillance models that the Sec. 7 conclusion warns about. The digital results on the finetuned NIR model (94.14% ASR, Table 1) are suggestive, but no physical evaluation is reported on that model. To support the central claim, the authors should either run physical attacks against the NIR-finetuned detector (or a larger NIR-trained detector) or provide a concrete argument and supporting evidence for why the physical attack transfers from the official YOLO to NIR-trained detectors.
- [Table 2, Sec. 5.2.2] Table 2 reports no error bars, no number of subjects, no number of frames, and no per-subject breakdown for the physical experiments. The aggregate 87.93% ASR could be dominated by a single subject or by many correlated frames from one pose sequence. The paper should report per-subject and per-frame statistics, confidence intervals, and a description of the capture protocol (number of subjects, actions, angles, distances) so that the physical result is properly interpretable.
- [Sec. 5.1] The NIR-finetuned detector is trained on only 13 identities and 13,000 video frames. This is a very small training set, and the digital ASR of 94.14% on this model may partly reflect the model's low capacity and limited variation rather than a fundamental vulnerability of NIR-based AI in general. The conclusion in Sec. 7 extrapolates from this single small model to 'NIR-based AI' at large. The authors should temper the claim or support it with experiments on a larger, more diverse NIR training set or on additional architectures.
minor comments (5)
- [Sec. 4.3.1] There is a typo: 'disussed' should be 'discussed'.
- [Sec. 4.3.1, Fig. 8] The term 'homeomorphism' is used loosely; consider 'shared topology' or 'consistent mesh topology' for clarity.
- [Sec. 5.1, Table 1] The notation 'Ours (5black)' and 'Ours (1black)' is not defined in the main text; please explain that these refer to whether the head/hands/feet parts (5 parts) or only the head (1 part) are fixed to black.
- [Eq. (7)] The ASR definition could be clarified for the case where the detector produces no true-positive labels in the no-attack condition; currently N_0 might be zero for some inputs.
- [Sec. 5.2.2] The sentence 'we can see that both AC and ASR become worse as the distance of the person becomes closer to the camera' appears to be an error: the numbers in Table 2 improve (AC decreases and ASR increases) at shorter distances, except for the 3m row where ASR is lower. Please rephrase to describe the actual trend (degradation at very close range due to visible head/hands/feet and non-black insulating tape).
Circularity Check
No circular derivation: the attack is obtained by optimizing detector confidence and evaluated on held-out digital and physical data; self-citations are background, not load-bearing.
full rationale
I found no circularity in the paper's derivation chain. The adversarial pattern is produced by a black-box genetic search whose fitness is the target detector's average confidence (Eq. 2-6, Sec. 4.3.4-4.3.5), and the reported success is measured on held-out rendered images (Tab. 1) and on physical captures against a real YOLOv5 detector (Tab. 2). This is standard attack construction followed by independent evaluation, not a prediction forced by construction. The Sec. 3 analysis of NIR color/texture loss is supported by the paper's own spectral measurements and camera-sensitivity figures (Figs. 1, 3, 4), not by the paper's conclusion. Self-citations by the authors (e.g., refs. [18, 36] for dyed-fabric reflectance, [22, 23] for low-light enhancement, [32] for thermal attacks) are used as contextual background and are not the evidence establishing the attack's effectiveness. The main weakness—physical experiments attack the official COCO-pretrained YOLOv5 rather than the NIR-finetuned model, so the physical ASR does not by itself prove the Sec. 7 generalization to NIR-trained surveillance AI—is a validity/generalization concern, not a circularity concern. Accordingly the circularity score is low.
Assumptions & free parameters
free parameters (3)
- Number of body segments K =
31
- Genetic algorithm hyperparameters (N=1000, B=300, P_cross=0.5, P_mut=0.01) =
as stated
- Fixed black parts for head/hands/feet (5black or 1black) =
5 or 1
assumptions (5)
- domain assumption R/G/B channel spectral sensitivities coincide in the NIR range for the trichromatic sensors used in dual-mode surveillance cameras.
- domain assumption Spectral reflectance of dyed fabrics tends to converge around 850 nm, causing texture loss.
- domain assumption Retro-reflective tape returns NIR light to the co-located camera with high efficiency regardless of tape orientation and visible color.
- ad hoc to paper Flat binary segmentation maps rendered over real NIR backgrounds are a sufficient digital approximation of the physical taped-clothing appearance at 850 nm.
- domain assumption YOLOv5, either the official COCO checkpoint or a version finetuned on the authors' 13-identity dataset, is representative of NIR human detectors deployed in surveillance.
Cite this review
Pith. "Pith review of Physics-Based Adversarial Attack on Near-Infrared Human Detector for Nighttime Surveillance Camera Systems." pith.science (2026). https://pith.science/paper/AL55OPZ2
@misc{pith2026241213709,
author = {Pith},
title = {Pith review of: Physics-Based Adversarial Attack on Near-Infrared Human Detector for Nighttime Surveillance Camera Systems},
year = {2026},
howpublished = {\url{https://pith.science/paper/AL55OPZ2}},
note = {Machine review of arXiv:2412.13709}
}
read the original abstract
Many surveillance cameras switch between daytime and nighttime modes based on illuminance levels. During the day, the camera records ordinary RGB images through an enabled IR-cut filter. At night, the filter is disabled to capture near-infrared (NIR) light emitted from NIR LEDs typically mounted around the lens. While RGB-based AI algorithm vulnerabilities have been widely reported, the vulnerabilities of NIR-based AI have rarely been investigated. In this paper, we identify fundamental vulnerabilities in NIR-based image understanding caused by color and texture loss due to the intrinsic characteristics of clothes' reflectance and cameras' spectral sensitivity in the NIR range. We further show that the nearly co-located configuration of illuminants and cameras in existing surveillance systems facilitates concealing and fully passive attacks in the physical world. Specifically, we demonstrate how retro-reflective and insulation plastic tapes can manipulate the intensity distribution of NIR images. We showcase an attack on the YOLO-based human detector using binary patterns designed in the digital space (via black-box query and searching) and then physically realized using tapes pasted onto clothes. Our attack highlights significant reliability concerns for nighttime surveillance systems, which are intended to enhance security. Codes Available: https://github.com/MyNiuuu/AdvNIR
Figures
Figures from the paper (9 more)
Reference graph
Works this paper leans on
-
[1]
Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018. Synthesiz- ing robust adversarial examples. In International conference on machine learning . PMLR, 284–293
work page 2018
-
[2]
Nicolas Carion, Francisco Massa, Gabriel Synnaeve, Nicolas Usunier, Alexander Kirillov, and Sergey Zagoruyko. 2020. End-to-end object detection with trans- formers. In Computer Vision–ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part I 16 . Springer, 213–229
2020
-
[3]
Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp) . Ieee, 39–57
2017
-
[4]
Yunfeng Diao, Tianjia Shao, Yong-Liang Yang, Kun Zhou, and He Wang. 2021. BASAR: black-box attack on skeletal action recognition. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 7597–7607
work page 2021
-
[5]
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li. 2018. Boosting adversarial attacks with momentum. In Proceedings of the IEEE conference on computer vision and pattern recognition . 9185–9193
work page 2018
-
[6]
Ranjie Duan, Xingjun Ma, Yisen Wang, James Bailey, A Kai Qin, and Yun Yang
-
[7]
Ranjie Duan, Xiaofeng Mao, A Kai Qin, Yuefeng Chen, Shaokai Ye, Yuan He, and Yun Yang. 2021. Adversarial laser beam: Effective physical-world attack to dnns in a blink. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 16062–16071
work page 2021
-
[8]
Yexin Duan, Jialin Chen, Xingyu Zhou, Junhua Zou, Zhengyun He, Jin Zhang, Wu Zhang, and Zhisong Pan. 2021. Learning coated adversarial camouflages for object detectors. arXiv preprint arXiv:2109.00124 (2021)
arXiv 2021
Show all 52 references
-
[9]
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song. 2018. Robust physical- world attacks on deep learning visual classification. In Proceedings of the IEEE conference on computer vision and pattern r...
2018
-
[10]
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)
2014 arXiv
-
[11]
Chengyin Hu and Weiwen Shi. 2022. Adversarial Color Film: Effective Physical- World Attack to DNNs. arXiv:2209.02430 [cs.CV]
2022 arXiv
-
[12]
Yu-Chih-Tuan Hu, Bo-Han Kung, Daniel Stanley Tan, Jun-Cheng Chen, Kai- Lung Hua, and Wen-Huang Cheng. 2021. Naturalistic physical adversarial patch for object detectors. In Proceedings of the IEEE/CVF International Conference on Computer Vision. 7848–7857
2021
-
[13]
Zhanhao Hu, Siyuan Huang, Xiaopei Zhu, Fuchun Sun, Bo Zhang, and Xiaolin Hu
-
[14]
Steve TK Jan, Joseph Messou, Yen-Chen Lin, Jia-Bin Huang, and Gang Wang
-
[15]
Shasha Li, Abhishek Aich, Shitong Zhu, Salman Asif, Chengyu Song, Amit Roy- Chowdhury, and Srikanth Krishnamurthy. 2021. Adversarial attacks on black box video classifiers: Leveraging the power of geometric transformations. Advances in Neural Information Processing Systems 34 ...
2021
-
[16]
Aishan Liu, Xianglong Liu, Jiaxin Fan, Yuqing Ma, Anlan Zhang, Huiyuan Xie, and Dacheng Tao. 2019. Perceptual-sensitive gan for generating adversarial patches. In Proceedings of the AAAI conference on artificial intelligence , Vol. 33. 1028–1035
2019
-
[17]
Aishan Liu, Jiakai Wang, Xianglong Liu, Bowen Cao, Chongzhi Zhang, and Hang Yu. 2020. Bias-based universal adversarial patch attack for automatic check-out. In European conference on computer vision . Springer, 395–410
2020
-
[18]
Lei Liu, Yuze Chen, Junchi Yan, and Yinqiang Zheng. 2022. Optimal LED Spectral Multiplexing for NIR2RGB Translation. InProceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 12652–12660
2022
-
[19]
Matthew Loper, Naureen Mahmood, Javier Romero, Gerard Pons-Moll, and Michael J. Black. 2015. SMPL: A Skinned Multi-Person Linear Model. ACM Trans. Graphics (Proc. SIGGRAPH Asia) 34, 6 (Oct. 2015), 248:1–248:16
2015
-
[20]
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)
2017 arXiv
-
[21]
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal adversarial perturbations. In Proceedings of the IEEE conference on computer vision and pattern recognition . 1765–1773
2017
-
[22]
Muyao Niu, Zhuoxiao Li, Zhihang Zhong, and Yinqiang Zheng. 2023. Visibility Constrained Wide-band Illumination Spectrum Design for Seeing-in-the-Dark. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 13976–13985
2023
-
[23]
Muyao Niu, Zhihang Zhong, and Yinqiang Zheng. 2023. NIR-assisted Video Enhancement via Unpaired 24-hour Data. In Proceedings of the IEEE/CVF Interna- tional Conference on Computer Vision . 10778–10788
2023
-
[24]
Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et al. 2019. Pytorch: An imperative style, high-performance deep learning library. Advances in neural information processing system...
2019
-
[25]
Georgios Pavlakos, Vasileios Choutas, Nima Ghorbani, Timo Bolkart, Ahmed A. A. Osman, Dimitrios Tzionas, and Michael J. Black. 2019. Expressive Body Capture: 3D Hands, Face, and Body from a Single Image. In Proceedings IEEE Conf. on Computer Vision and Pattern Recognition (CVP...
2019
-
[26]
Joseph Redmon, Santosh Divvala, Ross Girshick, and Ali Farhadi. 2016. You only look once: Unified, real-time object detection. In Proceedings of the IEEE conference on computer vision and pattern recognition . 779–788
2016
-
[27]
Javier Romero, Dimitrios Tzionas, and Michael J. Black. 2017. Embodied Hands: Modeling and Capturing Hands and Bodies Together. ACM Transactions on Graphics, (Proc. SIGGRAPH Asia) 36, 6 (Nov. 2017)
2017
-
[28]
Florian Schroff, Dmitry Kalenichenko, and James Philbin. 2015. Facenet: A unified embedding for face recognition and clustering. In Proceedings of the IEEE conference on computer vision and pattern recognition . 815–823
2015
-
[29]
Naufal Suryanto, Yongsu Kim, Hyoeun Kang, Harashta Tatimma Larasati, Youngyeo Yun, Thi-Thu-Huong Le, Hunmin Yang, Se-Yoon Oh, and Howon Kim. 2022. Dta: Physical camouflage attacks using differentiable transforma- tion network. In Proceedings of the IEEE/CVF Conference on Compu...
2022
-
[30]
Jia Tan, Nan Ji, Haidong Xie, and Xueshuang Xiang. 2021. Legitimate Adversarial Patches: Evading Human Eyes and Detection Models in the Physical World. In Proceedings of the 29th ACM International Conference on Multimedia . 5307–5315
2021
-
[31]
Donghua Wang, Tingsong Jiang, Jialiang Sun, Weien Zhou, Zhiqiang Gong, Xi- aoya Zhang, Wen Yao, and Xiaoqian Chen. 2022. Fca: Learning a 3d full-coverage vehicle camouflage for multi-view physical adversarial attack. In Proceedings of the AAAI Conference on Artificial Intellig...
2022
-
[32]
Hui Wei, Zhixiang Wang, Xuemei Jia, Yinqiang Zheng, Hao Tang, Shin’ichi Satoh, and Zheng Wang. 2022. HOTCOLD Block: Fooling Thermal Infrared Detectors with a Novel Wearable Design. arXiv preprint arXiv:2212.05709 (2022)
2022 arXiv
-
[33]
Zhipeng Wei, Jingjing Chen, Xingxing Wei, Linxi Jiang, Tat-Seng Chua, Fengfeng Zhou, and Yu-Gang Jiang. 2020. Heuristic black-box adversarial attacks on video recognition models. InProceedings of the AAAI Conference on Artificial Intelligence, Vol. 34. 12338–12345
2020
-
[34]
Yandong Wen, Kaipeng Zhang, Zhifeng Li, and Yu Qiao. 2016. A discriminative feature learning approach for deep face recognition. In Computer Vision–ECCV 2016: 14th European Conference, Amsterdam, The Netherlands, October 11–14, 2016, Proceedings, Part VII 14 . Springer, 499–515
2016
-
[35]
Ancong Wu, Wei-Shi Zheng, Hong-Xing Yu, Shaogang Gong, and Jianhuang Lai
-
[36]
Guangming Wu, Yinqiang Zheng, Zhiling Guo, Zekun Cai, Xiaodan Shi, Xin Ding, Yifei Huang, Yimin Guo, and Ryosuke Shibasaki. 2020. Learn to recover visible color for video surveillance in a day. In European Conference on Computer Vision. Springer, 495–511
2020
-
[37]
Zuxuan Wu, Ser-Nam Lim, Larry S Davis, and Tom Goldstein. 2020. Making an invisibility cloak: Real world adversarial attacks on object detectors. In European Conference on Computer Vision . Springer, 1–17
2020
-
[38]
Wei Xingxing, Yu Jie, and Huang Yao. 2023. Physically Adversarial Infrared Patches with Learnable Shapes and Locations. arXiv:2303.13868 (2023)
2023 arXiv
-
[39]
Kaidi Xu, Gaoyuan Zhang, Sijia Liu, Quanfu Fan, Mengshu Sun, Hongge Chen, Pin-Yu Chen, Yanzhi Wang, and Xue Lin. 2020. Adversarial t-shirt! evading person detectors in a physical world. In European conference on computer vision . Springer, 665–681
2020
-
[40]
Takayuki Yamada, Seiichi Gohshi, and Isao Echizen. 2012. Use of invisible noise signals to prevent privacy invasion through face recognition from camera images. In Proceedings of the 20th ACM international conference on Multimedia. 1315–1316
2012
-
[41]
Takayuki Yamada, Seiichi Gohshi, and Isao Echizen. 2013. Privacy visor: Method for preventing face image detection by using differences in human and device sensitivity. In Communications and Multimedia Security: 14th IFIP TC 6/TC 11 International Conference, CMS 2013, Magdebur...
2013
-
[42]
Qiang Zhang, Changzhou Lai, Jianan Liu, Nianchang Huang, and Jungong Han
-
[43]
Yiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang, and Xiangyang Ji. 2022. Shadows can be dangerous: Stealthy and effective physical-world adversarial attack by natural phenomenon. In Proceedings of the IEEE/CVF Conference on ACM MM’23, Oct.29–Nov.3, 2023, Ottawa, Canada Muy...
2022
-
[44]
Xiaopei Zhu, Zhanhao Hu, Siyuan Huang, Jianmin Li, and Xiaolin Hu. 2022. Infrared Invisible Clothing: Hiding From Infrared Detectors at Multiple Angles in Real World. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 13317–13326
2022
-
[45]
Xiaopei Zhu, Xiao Li, Jianmin Li, Zheyao Wang, and Xiaolin Hu. 2021. Fool- ing thermal infrared pedestrian detectors in real world using small bulbs. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 35. 3616–3624
2021
-
[46]
Alon Zolfi, Moshe Kravchik, Yuval Elovici, and Asaf Shabtai. 2021. The translucent patch: A physical and universal attack on object detectors. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 15232–15241
2021
-
[47]
In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition
Fmcnet: Feature-level modality compensation for visible-infrared person re-identification. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 7349–7358
-
[52]
Alon Zolfi, Moshe Kravchik, Yuval Elovici, and Asaf Shabtai. 2021. The Translu- cent Patch: A Physical and Universal Attack on Object Detectors. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition . 15232–15241
2021
-
[2017]
In Proceedings of the IEEE international conference on computer vision
RGB-infrared cross-modality person re-identification. In Proceedings of the IEEE international conference on computer vision . 5380–5389
-
[2019]
In Proceedings of the AAAI Conference on Artificial Intelligence, Vol
Connecting the digital and physical world: Improving the robustness of adversarial attacks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 33. 962–969
-
[2020]
In Proceedings of the IEEE/CVF conference on computer vision and pattern recogni- tion
Adversarial camouflage: Hiding physical-world attacks with natural styles. In Proceedings of the IEEE/CVF conference on computer vision and pattern recogni- tion. 1000–1008
-
[2022]
In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition
Adversarial texture for fooling person detectors in the physical world. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 13307–13316
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.