Adversarial patches threaten visual AI models in the real world. The number of patches in a patch attack is variable and determines the attack's potency in a specific environment. Most existing defenses assume a single patch in the scene, and the multiple patch scenarios are shown to overcome them. This paper presents a model-agnostic defense against patch attacks based on total variation for image resurfacing (TVR). The TVR is an image-cleansing method that processes images to remove probable adversarial regions. TVR can be utilized solely or augmented with a defended model, providing multi-level security for robust prediction. TVR nullifies the influence of patches in a single image scan with no prior assumption on the number of patches in the scene. We validate TVR on the ImageNet-Patch benchmark dataset and with real-world physical objects, demonstrating its ability to mitigate patch attack.
翻译:对抗性补丁威胁着现实世界中的视觉AI模型。补丁攻击中补丁的数量是可变的,并在特定环境中决定了攻击的效力。现有大多数防御方法假设场景中仅存在单个补丁,而多补丁场景已被证明能够突破这些防御。本文提出一种基于总变分图像表面重建(TVR)的模型无关对抗补丁防御方法。TVR是一种图像净化技术,通过处理图像以移除潜在对抗区域。该技术既可单独使用,也可与防御模型协同增强,为鲁棒预测提供多层次安全保障。TVR无需预先假设场景中补丁数量,即可在单次图像扫描中消除补丁的影响。我们在ImageNet-Patch基准数据集及真实物理物体上验证了TVR的有效性,证明其能够有效缓解补丁攻击。