Pith. sign in

REVIEW 2 cited by

Adversarial Color Film: Effective Physical-World Attack to DNNs

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2209.02430 v2 pith:CGZXLAM5 submitted 2022-09-02 cs.CV

classification cs.CV
keywords physicaladvcfadversarialattackattackscamera-basedcolorfilm
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

It is well known that the performance of deep neural networks (DNNs) is susceptible to subtle interference. So far, camera-based physical adversarial attacks haven't gotten much attention, but it is the vacancy of physical attack. In this paper, we propose a simple and efficient camera-based physical attack called Adversarial Color Film (AdvCF), which manipulates the physical parameters of color film to perform attacks. Carefully designed experiments show the effectiveness of the proposed method in both digital and physical environments. In addition, experimental results show that the adversarial samples generated by AdvCF have excellent performance in attack transferability, which enables AdvCF effective black-box attacks. At the same time, we give the guidance of defense against AdvCF by means of adversarial training. Finally, we look into AdvCF's threat to future vision-based systems and propose some promising mentality for camera-based physical attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Physics-Based Adversarial Attack on Near-Infrared Human Detector for Nighttime Surveillance Camera Systems

    cs.CV 2024-12 conditional novelty 6.0 of 10

    Binary tape patterns designed with a black-box genetic search and rendered on 3D human models can hide people from a NIR-based YOLOv5 detector, with 87.9% average physical attack success at 3-5 m.

  2. Revisiting Adversarial Perception Attacks and Defense Methods on Autonomous Driving Systems

    cs.RO 2025-05 conditional novelty 4.0 of 10

    Adversarial attacks shift OpenPilot distance estimates by tens of meters and cut YOLOv8 stop sign recall sharply, while tested defenses trade off gains against new failure modes.

Pith tools