AbstractThe physical attack has been regarded as a kind of threat against real-world computer vision systems. Still, many existing defense methods are only useful for small perturbations attacks and can't detect
physical attacks effectively. In this paper, we propose a
→