Skip to content
InfoResearchPreprint

Can Attack Difficulty Be Characterized Before Optimization? A Study of Pre-optimization Difficulty in Person-Vanishing Attacks

Published
Record updated
View JSON

Summary

This research paper asks whether the difficulty of person-vanishing attacks on object detectors can be estimated before adversarial optimization runs. The authors introduce Quad-CLEVER, a geometry-based estimator built from a quadratic approximation of the local person-vanishing margin, and report that it correlates with observed optimization cost across several attack algorithms. A difficulty-aware framework that allocates optimization budgets using these estimates raises image-level attack success by up to 5.78% on BDD100K and saves up to 11.42 iterations, while saving 2.25 iterations on EventPed.