arrow
Return

PATCHOUT: Adversarial Patch Detection and Localization using Semantic Consistency

delete2025-06-01
delete0
delete
OA
AI
D
Dominic A. Simon *
S
S. K. Jha
R
Rickard Ewetz
DOI:10.1007/s11063-025-11775-5delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Computer vision systems are actively deployed in safety-critical applications such as autonomous vehicles. Real-world adversarial patches are capable of compromising the artificial intelligence (AI) systems with catastrophic outcomes. Existing defenses against patch attacks are based on identifying neurons, features, or gradients of high intensity. However, these defenses are vulnerable to weaker attacks that have less obvious attack signatures. In this paper, we propose the PATCHOUT framework that detects and locates adversarial patches using semantic consistency. Within patch detection, the key insight is that the top class predictions for an entity are semantically consistent for benign images, whereas they are inconsistent for attacked images. Within patch localization, it is observed that patches are semantically consistent with a coarse grained segmentation of the image. This allows the PATCHOUT framework to detect and remove adversarial patches using a class consistency checker as well as image segmentation, attribution analysis, and image restoration techniques. The experimental evaluation demonstrates that PATCHOUT can detect a broad range of adversarial patches with over 90% accuracy. The framework achieves 20% higher accuracy than other defenses. The framework is also evaluated against unseen attacks and adaptive attacks, reducing the success rate of adaptive attacks from 56% to 24%.
Keywords:
Adversarial Machine Learning
Adversarial Patch
Computer Vision
Artificial Intelligence

Journal

Neural Processing Letters cover
Neural Processing Letters
IF:
2.8
Papers:
174
Citations:
5.5K

Organization

U
University of Florida
Scholars:
4.0W
Papers: 3.1W
Citations: 6.6W
Cited Papers

Cited Papers

DeepGIN: Deep Generative Inpainting Network for Extreme Image Inpainting
err2021-01-03
err0
PREAI
errChu-Tak Li; Wan-Chi Siu; Zhi-Song Liu; Li-Wen Wang; Daniel Pak-Kong Lun
errShare
errSave
err
IF0
err
err0
errOAAI
err
errShare
errSave
Naturalistic Physical Adversarial Patch for Object Detectors
err2021-10-01
err0
PREAI
errYu-Chih-Tuan Hu; Jun-Cheng Chen; Bo-Han Kung; Kai-Lung Hua; Daniel Stanley Tan
errShare
errSave
ImageNet Large Scale Visual Recognition Challenge
err2015-04-11
err2.7W
PREAI
errRussakovsky, Olga; Deng, Jia; Su, Hao; Krause, Jonathan; Satheesh, Sanjeev; Ma, Sean; Huang, Zhiheng; Karpathy, Andrej; Khosla, Aditya; Bernstein, Michael; Berg, Alexander C.; Fei-Fei, Li
errShare
errSave
Defending against Universal Adversarial Patches by Clipping Feature Norms
err2021-10-01
err0
PREAI
errCheng Yu; Jiansheng Chen; Youze Xue; Yuyang Liu; Weitao Wan; Jiayu Bao; Huimin Ma
errShare
errSave
researcher View more