IP Library › Granted Patent US 12,597,246
Granted Patent B2
US 12,597,246 · App. 18/554,498 · Granted Apr 7, 2026

Method and apparatus for generating adversarial patch

Inventors: Hang Su (Beijing, CN); Yichi Zhang (Beijing, CN); Xinxin Gu (Shanghai, CN); Ze Cheng (Shanghai, CN); Yunjia Wang (Shanghai, CN); Zijian Zhu (Beijing, CN)
Assignees: ROBERT BOSCH GMBH; TSINGHUA UNIVERSITY
G06V10/82G06T11/001G06V10/267G06T2210/12G06V10/776
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,597,246
App. No.
18/554,498
Granted
Apr 7, 2026
Kind
B2
Abstract

A method for generating a set of adversarial patches for an image. The method includes segmenting the image into a plurality of regions; selecting a set of target regions that satisfies an attacking criterion by discretely searching of the plurality of regions; and generating a set of adversarial patches by using the set of target regions.

Claims (37)

1 . A method for generating a set of adversarial patches for an image, comprising the following steps:

segmenting the image into a plurality of regions;

selecting a set of target regions from the plurality of regions that satisfies an attacking criterion by discretely searching of the plurality of regions for regions satisfying the attacking criterion; and

generating a set of adversarial patches for the image by using the set of target regions;

wherein a shape of at least one adversarial patch in the set of adversarial patches is optimized by optimizing the selection of the set of target regions;

wherein at least some of the adversarial patches in the set of adversarial patches have different shapes relative to one another.

2 . The method of claim 1 , wherein the segmenting includes:

segmenting the image into the plurality of regions based on a polygon shape or a predetermined number of regions.

3 . The method of claim 1 , wherein the segmenting includes:

segmenting the image into the plurality of regions based on pixels having values within a threshold range.

4 . The method of claim 3 , wherein the segmenting further includes:

changing the plurality of regions into convex shapes by getting a convex envelope for each of the plurality of regions.

5 . The method of claim 1 , wherein the segmenting is constrained to a foreground object of the image.

6 . The method of claim 1 , wherein the selecting includes:

optimizing a probability distribution of a selection vector of the plurality of regions by calculating a search gradient, the selection vector indicating whether each of the plurality of regions is to be selected into the set of target regions; and

selecting the set of target regions based on a selection vector sampled based on the optimized probability distribution.

7 . The method of claim 1 , wherein the generating of the set of adversarial patches includes:

modifying textures of the set of adversarial patches, wherein the modifying includes: optimizing the textures with iterative gradient ascent, or selecting the textures from a texture dictionary.

8 . The method of claim 1 , wherein the selecting is based on a function of an output from a computer vision neural network for the image applied by the set of adversarial patches, a ground-truth label of the image, and a total area of the set of adversarial patches.

9 . The method of claim 8 , wherein the computer vision neural network is used for object detection, and the function is based on a task of misclassification or position shift or disappearing during the object detection.

10 . The method of claim 1 , wherein the segmenting of the image is based on pixels having values with a threshold range, wherein each of the plurality of regions is a superpixel.

11 . The method of claim 1 , wherein at least some of the adversarial patches are each constituted by several adjacent regions of the set of target regions.

12 . The method of claim 1 , wherein each of the different shapes is non-rectangular.

13 . An apparatus for generating a set of adversarial patches for an image, comprising:

a memory; and

at least one processor coupled to the memory and configured to generating a set of adversarial patches for an image, the at least one processor configured to:

segment the image into a plurality of regions;

select a set of target regions from the plurality of regions that satisfies an attacking criterion by discretely searching of the plurality of regions for regions satisfying the attacking criterion; and

generate a set of adversarial patches for the image by using the set of target regions;

wherein a shape of at least one adversarial patch in the set of adversarial patches is optimized by optimizing the selection of the set of target regions;

wherein at least some of the adversarial patches in the set of adversarial patches have different shapes relative to one another.

14 . A non-transitory computer readable medium on which is stored storing computer code for generating a set of adversarial patches for an image, the computer code when executed by a processor, causing the processor to perform the following steps:

segmenting the image into a plurality of regions;

selecting a set of target regions from the plurality of regions that satisfies an attacking criterion by discretely searching of the plurality of regions for regions satisfying the attacking criterion; and

generating a set of adversarial patches for the image by using the set of target regions;

wherein a shape of at least one adversarial patch in the set of adversarial patches is optimized by optimizing the selection of the set of target regions;

wherein at least some of the adversarial patches in the set of adversarial patches have different shapes relative to one another.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2024
From: SU, HANG; ZHANG, YICHI; GU, XINXIN; CHENG, ZE; WANG, YUNJIA; ZHU, ZIJIAN
To: ROBERT BOSCH GMBH; TSINGHUA UNIVERSITY
Reel/Frame 065994/0185 →
Continuity (1)
Related Publication 20240193931A1 · Jun 13, 2024
References Cited (13)
US 10783401B1 · Jiang · 2020 [cited by examiner]
US 20210064938A1 · Ahuja · 2021 [cited by examiner]
Yang et al. “PatchAttack: A Black-box Texture-based Attack with Reinforcement Learning”, https://arxiv.org/abs/2004.05682v2 (Year: 2020). [cited by examiner]
Thys et al. “Fooling automated surveillance cameras: adversarial patches to attack person detection”, https://arxiv.org/abs/1904.08653v1 (Year: 2019). [cited by examiner]
M. N. Vijayalakshmi and M. Senthilvadivu, “Performance evaluation of object detection techniques for object detection,” 2016 International Conference on Inventive Computation Technologies (ICICT), Coimbatore, India, 201… [cited by examiner]
X. Dong et al., “Robust Superpixel-Guided Attentional Adversarial Attack,” 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Seattle, WA, USA, 2020, pp. 12892-12901, doi: 10.1109/CVPR42600.2020… [cited by examiner]
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, Justin Gilmer, “Adversarial Patch”, https://arxiv.org/abs/1712.09665v2 (Year: 2018). [cited by examiner]
Wang, Yaxiong & Wei, Yunchao & Qian, Xueming & Zhu, Li & Yang, Yi. (2021). AINet: Association Implantation for Superpixel Segmentation. Jan. 26, 2021, arXiv:2101.10696v1 (Year: 2021). [cited by examiner]
International Search Report for PCT/CN2021/088875, Issued Oct. 20, 2021. [cited by applicant]
Zhao et al., “Object Hider: Adversarial Patch Attack Against Object Detectors,” Proceedings of the Cikm Analyticup, 2020, pp. 24-27. <https://ceur-ws.org/Vol-2881/paper7.pdf> Downloaded Oct. 6, 2023. [cited by applicant]
Liu et al., “Perceptual-Sensitive Gan for Generating Adversarial Patches,” The Thirty-Third AAAI Conference On Artificial Intelligence (AAAI-19), vol. 33, 2019, pp. 1028-1035. <https://sci-hub.ru/10.1609/aaai.v33i01.330… [cited by applicant]
Rao et al., “Adversarial Training Against Location-Optimized Adversarial Patches,” Computer Vision—ECCV 2020 Workshops: Glasgow, UK, Proceedings, Part V, 2020, pp. 1-18. <https://www.researchgate.net/publication/3489012… [cited by applicant]
ArXiv:2010.14974v1, Yusheng Zhao, et al.: “Object Hider: Adversarial Patch Attach Against Object Detectors.” Jun. 3-5, 2018, Woodstock, NY, Copyright 2020, Association for Computing Machinery. [cited by applicant]