IP Library › Granted Patent US 12,536,838
Granted Patent B2
US 12,536,838 · App. 18/129,417 · Granted Jan 27, 2026

Patch-based adversarial attack detection and mitigation

Inventors: Celia Cintas (Nairobi, KE); Hannah Halin Kim (New York, NY); Girmaw Abebe Tadesse (Nairobi, KE); Skyler Speakman (Nairobi, KE)
Assignee: International Business Machines Corporation
G06V40/40G06V10/774G06V40/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,838
App. No.
18/129,417
Granted
Jan 27, 2026
Kind
B2
Abstract

A present invention embodiment prevents patch-based adversarial attacks. A plurality of time-series images are processed using a machine learning model to identify an anomaly, wherein the anomaly comprises an adversarial patch-based attack, and wherein the anomaly is present in a locality comprising a particular time and space in the plurality of time-series images. A subset of the plurality of time-series images are modified based on the locality of the anomaly to mask the anomaly from detection by a trained image processing model.

Claims (54)

1 . A computer-implemented method of preventing patch-based adversarial attacks comprising:

processing a plurality of time-series images, using a machine learning model having a plurality of layers including latent space, to identify an anomaly, wherein the anomaly comprises an adversarial patch-based attack, wherein the anomaly is present in a locality comprising a particular time and space in the plurality of time-series images, and wherein processing the plurality of time-series images using the machine learning model includes:

detecting the anomaly in the latent space;

computing a gradient of the anomaly for each layer, of the plurality of layers of the machine learning model, with respect to a corresponding preceding layer; and

identifying the locality based on computing the gradient for the anomaly for each layer; and

modifying, in real-time, a subset of the plurality of time-series images based on the locality to mask the anomaly from detection by a trained image processing model.

2 . The computer-implemented method of claim 1 ,

wherein the trained image processing model is a motion detection model and wherein masking the anomaly from detection prevents the motion detection model from indicating that the anomaly indicates an incorrect motion.

3 . The computer-implemented method of claim 1 ,

wherein the machine learning model comprises a non-parametric machine learning model.

4 . The computer-implemented method of claim 1 ,

wherein the machine learning model is trained using unsupervised learning, and wherein the machine learning model is trained with a training corpus of examples of training time-series images, including a subset of training time-series images that include one or more examples of adversarial patch-based attacks.

5 . The computer-implemented method of claim 1 ,

wherein the machine learning model detects the anomaly in an output layer and identifies the locality in an input layer by propagating back through one or more layers, of the plurality of layers of the machine learning model, to identify the particular time and space of the locality in the plurality of time-series images.

6 . The computer-implemented method of claim 5 ,

wherein the machine learning model applies spatial constraints when propagating back to exclude latent space features from consideration when propagating back when the latent space features are beyond a threshold distance from a latent space feature corresponding to the anomaly.

7 . The computer-implemented method of claim 1 ,

wherein the plurality of time-series images, including the modified subset of the plurality of time-series images, is processed by the trained image processing model to perform an autonomous vehicular navigation task.

8 . A computer system for preventing patch-based adversarial attacks comprising:

one or more memories; and

at least one processor coupled to the one or more memories, wherein the at least one processor is configured to:

process a plurality of time-series images, using a machine learning model having a plurality of layers including latent space, to identify an anomaly, wherein the anomaly comprises an adversarial patch-based attack, wherein the anomaly is present in a locality comprising a particular time and space in the plurality of time-series images, and wherein processing the plurality of time-series images using the machine learning model includes:

detecting the anomaly in the latent space;

computing a gradient of the anomaly for each layer, of the plurality of layers of the machine learning model, with respect to a corresponding preceding layer; and

identifying the locality based on computing the gradient for the anomaly for each layer; and

modify, in real-time, a subset of the plurality of time-series images based on the locality of the anomaly to mask the anomaly from detection by a trained image processing model.

9 . The computer system of claim 8 ,

wherein the trained image processing model is a motion detection model and wherein masking the anomaly from detection prevents the motion detection model from indicating that the anomaly indicates an incorrect motion.

10 . The computer system of claim 8 ,

wherein the machine learning model comprises a non-parametric machine learning model.

11 . The computer system of claim 8 ,

wherein the machine learning model is trained using unsupervised learning, and wherein the machine learning model is trained with a training corpus of examples of training time-series images, including a subset of training time-series images that include one or more examples of adversarial patch-based attacks.

12 . The computer system of claim 8 ,

wherein the machine learning model detects the anomaly in an output layer and identifies the locality in an input layer by propagating back through one or more layers, of the plurality of layers of the machine learning model, to identify the particular time and space of the locality in the plurality of time-series images.

13 . The computer system of claim 12 ,

wherein the machine learning model applies spatial constraints when propagating back to exclude latent space features from consideration when propagating back when the latent space features are beyond a threshold distance from a latent space feature corresponding to the anomaly.

14 . The computer system of claim 8 ,

wherein the plurality of time-series images, including the modified subset of the plurality of time-series images, is processed by the trained image processing model to perform an autonomous vehicular navigation task.

15 . A computer program product for preventing patch-based adversarial attacks, the computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable by at least one processor to cause the at least one processor to:

process a plurality of time-series images, using a machine learning model having a plurality of layers including latent space, to identify an anomaly, wherein the anomaly comprises an adversarial patch-based attack, wherein the anomaly is present in a locality comprising a particular time and space in the plurality of time-series images, and wherein processing the plurality of time-series images using the machine learning model includes:

detecting the anomaly in the latent space;

computing a gradient of the anomaly for each layer, of the plurality of layers of the machine learning model, with respect to a corresponding preceding layer; and

identifying the locality based on computing the gradient for the anomaly for each layer; and

modify, in real-time, a subset of the plurality of time-series images based on the locality to mask the anomaly from detection by a trained image processing model.

16 . The computer program product of claim 15 ,

wherein the trained image processing model is a motion detection model and wherein masking the anomaly from detection prevents the motion detection model from indicating that the anomaly indicates an incorrect motion.

17 . The computer program product of claim 15 ,

wherein the machine learning model comprises a non-parametric machine learning model.

18 . The computer program product of claim 15 ,

wherein the machine learning model is trained using unsupervised learning, and wherein the machine learning model is trained with a training corpus of examples of training time-series images, including a subset of training time-series images that include one or more examples of adversarial patch-based attacks.

19 . The computer program product of claim 15 ,

wherein the machine learning model detects the anomaly in an output layer and identifies the locality in an input layer by propagating back through one or more layers, of the plurality of layers of the machine learning model, to identify the particular time and space of the locality in the plurality of time-series images.

20 . The computer program product of claim 19 ,

wherein the machine learning model applies spatial constraints when propagating back to exclude latent space features from consideration when propagating back when the latent space features are beyond a threshold distance from a latent space feature corresponding to the anomaly.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2023
From: CINTAS, CELIA; KIM, HANNAH HALIN; TADESSE, GIRMAW ABEBE; SPEAKMAN, SKYLAR
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 063191/0782 →
Continuity (1)
Related Publication 20240331449A1 · Oct 3, 2024
References Cited (30)
US 8495429B2 · Fu et al. · 2013 [cited by applicant]
US 9361463B2 · Ferragut et al. · 2016 [cited by applicant]
US 10783401B1 · Jiang et al. · 2020 [cited by applicant]
US 10805316B2 · Aditham et al. · 2020 [cited by applicant]
US 20120041575A1 · Maeda et al. · 2012 [cited by applicant]
US 20210097176A1 · Mathews · 2021 [cited by examiner]
US 20210125005A1 · Kuta et al. · 2021 [cited by applicant]
US 20210157912A1 · Kruthiveti Subrahmanyeswara Sai · 2021 [cited by examiner]
US 20220277173A1 · He · 2022 [cited by examiner]
US 20220277187A1 · Wang · 2022 [cited by examiner]
US 20220405648A1 · Lin · 2022 [cited by examiner]
US 20230061517A1 · Yang · 2023 [cited by examiner]
US 20230325678A1 · Fradkin · 2023 [cited by examiner]
US 20230410469A1 · Muehlenstaedt · 2023 [cited by examiner]
US 20240182071A1 · Jafari Tafti · 2024 [cited by examiner]
US 20240296225A1 · Afrasiabi · 2024 [cited by examiner]
US 20250068960A1 · Yu · 2025 [cited by examiner]
CN 109951500B · 2019 [cited by applicant]
CN 110691100B · 2020 [cited by applicant]
CN 112738015A · 2021 [cited by applicant]
IN 104506482B · 2015 [cited by applicant]
WO 2017087591A1 · 2017 [cited by applicant]
Xu et al. , PatchZero: Defending against Adversarial Patch Attacks by Detecting and Zeroing the Patch p. 1-10, Sep. 5, 2022 (Year: 2022). [cited by examiner]
W. R. Almeida, et al., “Detecting face presentation attacks in mobile devices with a patch-based CNN and a sensoraware loss function”, Research Article, PLoS ONE 15(9): e0238058, https://doi.org/10.1371/journal.pone.023… [cited by applicant]
S. Schrodi, et al., “What Causes Optical Flow Networks to be Vulnerable to Physical Adversarial Attacks”, https://www.researchgate.net/publication/350512124_What_Causes_Optical_Flow_Networks_to_be_Vulnerable_to_Physical… [cited by applicant]
A. Ranjan, et al., “Attacking Optical Flow”, https://arxiv.org/abs/1910.10053, Oct. 22, 2019, 21 pages. [cited by applicant]
B. Vinzamuri, et al., “An End-to-End Context Aware Anomaly Detection System”, 2020 IEEE International Conference on Big Data (Big Data), Dec. 2020, 10 pages. [cited by applicant]
S. Maleki, et al., “Unsupervised anomaly detection with LSTM autoencoders using statistical data-filtering”, https://www.sciencedirect.com/science/article/abs/pii/S1568494621003665, Applied Soft Computing 108 (2021): 10… [cited by applicant]
M. Du, et al., “DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep Learning”, https://dl.acm.org/, In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security (pp. 1285-1… [cited by applicant]
S. Schrodi, et al., “Towards Understanding Adversarial Robustness of Optical Flow Networks”, https://www.semanticscholar.org/paper/Towards-Understanding-Adversarial-Robustness-of-Schrodi-Saikia/423a32ae52806af0a4c730e34… [cited by applicant]