Assessing the Transferability of Adversarial Patches in Real-World Systems: Implications for Adversarial Testing of Image Recognition Security
At a glance
- الاستشهادات
- 0
- المراجع
- 19
- Comments
- 0
Abstract
This paper investigates the transferability of adversarial patches for attacking real-world image recognition systems used within cyber-physical systems (CPS). Adversarial Patch (AP) attacks pose a significant threat to the safety and reliability of such CPS due to their low-effort implementation and ability to bypass many traditional defenses. While previous research has explored AP attack mechanisms, this work focuses on evaluating their transferability in real-world scenarios. To this end, we enhance an existing framework for adversarial attack evaluation extending it in terms of both patch generation and novel application aspects of the attack.In our evaluation, we systematically investigate the influence of various hyperparameters on AP generation and the effectiveness of different target motif labels on different surrogate models. We analyze the success rate of AP attacks in different attack scenarios through extensive experimentation with multiple model architectures (VGG, ResNet, MobileNet) and diverse patch positions and sizes. The results reveal significant potential of transferability of AP attacks between models, which underlines the importance of robust defense mechanisms against such attacks in real-world CPS. By extending the evaluation framework, we also contribute to adversarial testing capabilities for analyzing the safety and reliability of models against APs.
Publication details
- DOI
- 10.1109/dsn-s65789.2025.00040
- OpenAlex
- W4412130384
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.