IP Library › Granted Patent US 12,536,300
Granted Patent B2
US 12,536,300 · App. 18/399,939 · Granted Jan 27, 2026

System and method for query efficient blackbox physically realizable attack with bayesian optimization

Inventors: Jianghong Shi (Pittsburgh, PA); Devin T. Willmott (Pittsburgh, PA); Wan-Yi Lin (Wexford, PA); Filipe J. Cabrita Condessa (Pittsburgh, PA); Bingqing Chen (Pittsburgh, PA); João D. Semedo (Pittsburgh, PA)
Assignee: Robert Bosch GmbH
G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,300
App. No.
18/399,939
Granted
Jan 27, 2026
Kind
B2
Abstract

A system includes a machine learning network input interface configured to receive input data from a sensor, one or more processors collectively programmed to receive an input data from the sensor, wherein the input data is indicative of image of a scene that includes a perturbation from a black-box attack with a physical perturbation at the scene, display an adversarial pattern at the scene, determine an objective function utilizing at least the adversarial pattern and a target classification of the machine-learning network, randomly select a plurality of data points associated with the adversarial pattern and the objective function, wherein the data points are associated with a number of queries of the objective function, obtain a machine-learning model output utilizing the data points displayed in the scene, and in response to meeting a criteria associated with the adversarial pattern and model output, identify a successful attack pattern.

Claims (46)

1 . A computer-implemented method for attacking a machine-learning model, comprising:

determine an objective function utilizing at least an adversarial pattern displayed at a scene, and either (1) output of the machine-learning network, or (2) a target output of the machine-learning network;

determining a maximum number of queries to the machine learning model, which includes a number of initial queries,

randomly selecting a plurality of data points within the adversarial pattern's space and the objective function, wherein the plurality of data points are associated with a number of initial queries;

displaying the plurality of data points in the scene to generate a rendered scene utilizing a system, wherein the rendered scene is received as input for the machine-learning model;

obtaining a machine-learning model output utilizing the randomly selected plurality of data points displayed at the rendered scene;

in response to the corresponding objective values given the previous plurality of data points and the machine-learning output, creating the next adversarial pattern at the system,

displaying the next adversarial pattern and querying the machine learning model; and

generating, via the system, additional adversarial patterns until identifying a successful attack pattern meeting a success criteria associated with the adversarial pattern and the machine-learning model output, or the maximum number of queries has reached.

2 . The computer-implemented method of claim 1 , wherein the dimensional input is 5×5.

3 . The computer-implemented method of claim 1 , wherein the adversarial pattern is an RGB image.

4 . The computer-implemented method of claim 1 , update the adversarial pattern with Bayesian optimization utilizing the objective function.

5 . The computer-implemented method of claim 1 , wherein no training data is utilized to identify the successful pattern.

6 . The computer-implemented method of claim 1 , wherein the adversarial pattern is located on a display or monitor in a scene within sensor range.

7 . The computer-implemented method of claim 1 , wherein the method includes initializing and updating the adversarial pattern with Bayesian optimization utilizing the objective function.

8 . The computer-implemented method of claim 1 , wherein the input data includes video information obtained from the camera.

9 . A system including an attack for a machine-learning network, comprising:

a machine learning network input interface configured to receive input data from a sensor, wherein the sensor includes a camera;

one or more processors in communication with the input interface, wherein the one or more processors are collectively programmed to:

receive an input data from the sensor, wherein the input data is indicative of image of a scene that includes a perturbation from a black-box attack with a physical perturbation at the scene;

display an adversarial pattern at the scene;

determine an objective function utilizing at least the adversarial pattern and a target classification of the machine-learning network; and

randomly select a plurality of data points associated with the adversarial pattern and the objective function, wherein the plurality of data points are associated with a number of queries of the objective function;

obtain a machine-learning model output utilizing the randomly selected plurality of data points displayed in the scene; and

in response to meeting a success criteria associated with the adversarial pattern and the machine-learning model output, identify a successful attack pattern associated with the adversarial pattern.

10 . The system of claim 9 , wherein the processor is programmed to randomly convert the adversarial pattern utilizing a monitor display function.

11 . The system of claim 9 , wherein the dimensional input is 5×5 dimensions or less.

12 . The system of claim 9 , wherein the one or more processors is a single processor.

13 . The system of claim 9 , wherein the one or more processors are collectively programmed to initialize and update the adversarial pattern with Bayesian optimization utilizing the objective function.

14 . The system of 9 , wherein the input data includes radar, sonar, or sound information.

15 . A computer-implemented method for attacking a machine-learning model, comprising:

receiving input data from one or more sensors and a display in proximity to the sensors,

determining an objective function utilizing at least the adversarial pattern, and the classification of the machine-learning network, or a target classification of the machine-learning network;

determining a maximum number of queries to the machine learning model, which includes a number of initial queries,

randomly selecting a plurality of data points within the adversarial pattern's space and the objective function, wherein the plurality of data points are associated with a number of initial queries;

obtaining a machine-learning model output utilizing the randomly selected plurality of data points converted; and

displaying a plurality of randomly selected data points in a scene, wherein a a rendered scene is received as input for the machine-learning model;

obtaining a machine-learning model output utilizing the randomly selected plurality of data points displayed;

in response to the corresponding objective values given previous plurality of data points and the machine-learning output, creating a next adversarial pattern;

displaying the next adversarial pattern and query the machine-learning model;

creating new adversarial patterns until either (1) identifying a successful attack pattern meeting a criteria associated with the adversarial pattern and the machine-learning model output, or (2) the maximum number of queries has reached.

16 . The computer implemented method of claim 15 , wherein the instructions include selecting the plurality of data points is conducted randomly.

17 . The computer implemented method of claim 15 , wherein the objective function includes a loss between output associated with a target classification and a benign scene.

18 . The computer implemented method of claim 15 , wherein the instructions include initializing and updating the adversarial pattern with Bayesian optimization utilizing the objective function.

19 . The computer implemented method of claim 18 , wherein the Bayesian optimization utilizes a Gaussian process to approximate a joint distribution of samples associated with the adversarial pattern.

20 . The computer implemented method of claim 18 , wherein the success criteria includes a threshold associated with the adversarial pattern.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: SHI, JIANGHONG; WILLMOTT, DEVIN T.; LIN, WAN-YI; CABRITA CONDESSA, FILIPE J.; CHEN, BINGQING; SEMEDO, JOÃO D.
To: ROBERT BOSCH GMBH
Reel/Frame 066934/0697 →
Continuity (1)
Related Publication 20250217493A1 · Jul 3, 2025
References Cited (26)
US 9996902B2 · Milanfar et al. · 2018 [cited by applicant]
US 11941823B2 · Xu · 2024 [cited by examiner]
US 12002055B1 · Miller · 2024 [cited by examiner]
US 12019740B2 · Trost · 2024 [cited by examiner]
US 20080168561A1 · Durie · 2008 [cited by examiner]
US 20180350085A1 · Lu et al. · 2018 [cited by applicant]
US 20200057965A1 · Howard · 2020 [cited by applicant]
US 20210025679A1 · Hoch · 2021 [cited by examiner]
US 20210064938A1 · Ahuja et al. · 2021 [cited by applicant]
US 20230004754A1 · Fan et al. · 2023 [cited by applicant]
US 20230259658A1 · Munoz Delgado et al. · 2023 [cited by applicant]
US 20240064157A1 · Koseki · 2024 [cited by applicant]
US 20240095891A1 · Saha et al. · 2024 [cited by applicant]
US 20240098118A1 · Kaznocha · 2024 [cited by examiner]
US 20240193931A1 · Su et al. · 2024 [cited by applicant]
US 20240249116A1 · Xu et al. · 2024 [cited by applicant]
US 20240311578A1 · Laudij · 2024 [cited by examiner]
US 20240414184A1 · Barai · 2024 [cited by examiner]
US 20250095373A1 · Monteuuis et al. · 2025 [cited by applicant]
US 20250217493A1 · Shi · 2025 [cited by examiner]
US 20250220042A1 · Shi · 2025 [cited by examiner]
Satya Narayan Shukla et al., “Black-box Adversarial Attacks with Bayesian Optimization.” arXiv:1909.13857v1 [cs.LG] Sep. 30, 2019, 12 Pages. [cited by applicant]
Francesco Croce et al., “Sparse-RS: a Versatile Framework for Query-Efficient Sparse Black-Box Adversarial Attacks.” arXiv:2006.12834v3 [cs.LG] Feb. 8, 2022, 22 Pages. [cited by applicant]
Bobak Shahriari et al., “Taking the Human Out of the Loop: A Review of Bayesian Optimization.” Proceedings of the IEEE | vol. 104, No. 1, Jan. 2016, pp. 148-175. [cited by applicant]
James Tu et al., “Physically Realizable Adversarial Examples for LiDAR Object Detection.” CVPR 2020, pp. 113716-13725. [cited by applicant]
Andrew Ilyas et al., “Black-box Adversarial Attacks with Limited Queries and Information.” Proceedings of the 35 th International Conference on Machine Learning, Stockholm, Sweden, PMLR 80, 2018, 10 Pages. [cited by applicant]