Research & Papers

Budget-aware adversarial patches fool YOLOv5, Faster R-CNN, and YOLOS

New attack grows patch only when progress stalls, achieving strong suppression with compact designs.

Deep Dive

A team of researchers (Pedram MohajerAnsari et al.) has developed a budget-aware adaptive adversarial patch attack for black-box object detectors, accepted at ICIP 2026. Traditional adversarial patches often require many queries or large visual footprints. This work addresses three gaps: joint optimization of patch location, texture, and size under tight query budgets; linking success to visual footprint; and separating robustness evaluations from plain-view suppression. The method combines a lightweight Contextual Thompson-Sampling placer with NES-style pixel updates, growing the patch only when progress stalls. A strict plain-image suppression test anchors reporting, while EOT is audited separately. Optional appearance and printability weights expose strength-visibility trade-offs.

Across YOLOv5 (CNN), Faster R-CNN (CNN), and YOLOS (transformer), the attack achieves strong suppression on CNN detectors and substantial suppression on the transformer-based detector, using compact patches. Query-footprint trade-offs are clearly shown compared to fixed-size and heuristic baselines. A print-capture pilot further demonstrates transfer across unseen physical objects and viewpoints, proving practical relevance. The work highlights a growing arms race between adversarial patches and real-world object detection systems, with implications for security in autonomous driving, surveillance, and any vision-based AI.

Key Points
  • Jointly optimizes patch location, texture, and size using Contextual Thompson-Sampling and NES-style pixel updates.
  • Achieves strong suppression on YOLOv5 and Faster R-CNN with compact patches, substantial suppression on YOLOS.
  • Includes a print-capture pilot showing physical-world transfer across unseen objects and viewpoints.

Why It Matters

Demonstrates a practical, query-efficient adversarial attack that threatens real-world object detectors in security-critical applications.

📬 Get the top 10 AI stories daily