1
Return

CaDe: Adaptive Sparse Causal Decoupling for Adversarially Robust Object Detection via Hierarchical Stability Constraints

delete2026-07-20
delete0
PRE
AI
W
Wenlong Zheng
Y
Yuhao Zhang
H
Heng Zhang
P
Peng Li
H
He Xu
DOI:10.1109/tifs.2026.3715119delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Object detectors are widely deployed in safety-critical systems, but their robustness is significantly threatened by physical adversarial patch (AP) attacks. While various defense mechanisms have been proposed in recent years to mitigate such attacks, existing methods primarily focus on suppressing perturbation-induced degradation in the feature space, without systematically analyzing how these perturbations propagate across the hierarchical structure of deep neural networks (DNNs) and disrupt the decision-making process. This paper examines the primary destructive mechanism of APs, which largely involves the disruption of operational causal consistency within the model rather than directly corrupting feature values. Specifically, perturbations disrupt the operational causal consistency of features through layer-wise propagation, disrupting the model’s decision pipeline and inducing cross-layer coupling interference, ultimately leading to reduced robustness. To target this mechanism, we propose a defense method for robust object detection called CaDe. CaDe mitigates the hierarchical propagation of residual perturbations through hierarchical stability constraints and adaptive sparse causal decoupling strategies, fundamentally enhancing the model’s robustness. Theoretical analysis demonstrates that CaDe possesses global exponential stability, preserving task-relevant semantic representations while sparsely separating adversarial components. Experimental results show that CaDe can effectively defend against Hiding Attack (HA) and Appearing Attack (AA), achieving improvements of 6.19% and 5.53% in mean Average Precision (mAP) compared with the best baseline method, respectively. Additionally, the mAP on benign samples only decreases by 0.14% compared with the baseline. Furthermore, CaDe incurs minimal additional computational overhead, enabling significant improvements in robustness while maintaining real-time performance.
Keywords:
Object detection
adversarial patch defense
operational causal decoupling
hierarchical prediction

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

N
nanjing university of posts and telecommunications
Scholars:
3.1K
Papers: 1.4K
Citations: 0
Cited Papers

Cited Papers

Citing Papers

Citing Papers