TL;DR该论文提出了一种以非刚性变形为特点的新型物理对抗样本,名为 “对抗 T 恤”,用于欺骗人物探测器,并展示了这种方法在数字和物理世界中的攻击成功率。
Abstract
It is known that deep neural networks (DNNs) are vulnerable to adversarial
attacks. The so-called physical adversarial examples deceive DNN-based
decisionmakers by attaching adversarial patches to real objects. H