InfoResearchPreprint
Can Attack Difficulty Be Characterized Before Optimization? A Study of Pre-optimization Difficulty in Person-Vanishing Attacks
- Published
- Record updated
Summary
This research paper asks whether the difficulty of person-vanishing attacks on object detectors can be estimated before adversarial optimization runs. The authors introduce Quad-CLEVER, a geometry-based estimator built from a quadratic approximation of the local person-vanishing margin, and report that it correlates with observed optimization cost across several attack algorithms. A difficulty-aware framework that allocates optimization budgets using these estimates raises image-level attack success by up to 5.78% on BDD100K and saves up to 11.42 iterations, while saving 2.25 iterations on EventPed.
Related items
- InfoDoes Target Alignment Mean Target Recovery? An Evidence-Ladder Study of Adversarial Claims on Contrastive EncodersSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoBRANCH: Bypassing Multi-Scanner AI GuardrailsSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)
- InfoDetecting Adversarial Images through Response Profiles of Vision-Language ModelsSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoGraphRectify: Graph-Based Transfer of Adversarial Example Detectors Across Neural NetworksSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoVCR-Bench: A Modular Open-Source Benchmark for Video Classification RobustnessSimilar attack · Arxiv (cs.RO + cs.CV security)