To Make Yourself Invisible with Adversarial Semantic Contours

Published in Computer Vision and Image Understanding (CVIU), Volume 230, 2023

[pdf] [code]

This paper proposes to take use of object semantic contours to enhance the sparse attack, i.e., $\ell_0$-constrained attack, on modern object detectors. We design a prior over the object contour for pixel selection and defines Adversarial Semantic Contours (ASC) as a Maximum A Posteriori (MAP) estimate under a Bayesian formulation of $\ell_0$-constrained sparse attack. Comprehensive experiments are conducted to verify the attack performance of ASC with 9 modern detectors in 3 datasets.

zhang2023make.png