arrow
Return

Benchmarking Adversarial Patch Selection and Location

delete2025-12-27
delete0
PRE
AI
S
Shai Kimhi *
M
Moshe Kimhi
A
Avi Mendelson
DOI:10.3390/math14010103delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Adversarial patch attacks threaten the reliability of modern vision models. We present PatchMap, the first spatially exhaustive benchmark of patch placement, built by evaluating over 1.5x108 forward passes on ImageNet validation images. PatchMap reveals systematic hot-spots where small patches (as little as 2% of the image) induce confident misclassifications and large drops in model confidence. To demonstrate its utility, we propose a simple segmentation-guided placement heuristic that leverages off-the-shelf masks to identify vulnerable regions without any gradient queries. Across five architectures-including adversarially trained ResNet-50-our method boosts attack success rates by 8-13 percentage points compared to random or fixed placements.
Keywords:
adversarial patches
patch placement
spatial vulnerability map
ImageNet
robustness benchmarking
segmentation-guided placement
location-aware attacks
confidence drop

Journal

Mathematics cover
Mathematics
IF:
2.2
Papers:
2.9K
Citations:
3.6W

Organization

T
technion israel institute of technology
Scholars:
1.8K
Papers: 758
Citations: 0