Abstract
Achieving physical-world attacks on object detectors often relies on adversarial camouflage, which applies textures to target surfaces. However, existing methods typically simulate environmental variations through post-rendering image transformations, which do not fully account for the 3D object’s geometry and its interaction with lighting. To address this, we propose the Flexible Physical-camouflage Attack (FPA), a framework that integrates a differentiable 3D renderer with comprehensive, multi-parameter environmental randomization such as lighting, material, and viewpoint directly into the optimization loop. This ensures that the generated textures are robust to real-world variations. For texture generation, FPA leverages a denoising diffusion probabilistic model whose generative prior helps produce structurally coherent and visually realistic patterns. These are jointly optimized with a set of task-oriented loss functions including adversarial, smoothness, non-printability, and concealment constraints within the unified framework. Through systematic ablation and extensive physical experiments on a 1:24 scale model, we demonstrate that FPA achieves a high attack success rate (ASR) and strong transferability to black-box detectors. Crucially, our analysis reveals a controllable trade-off between adversarial effectiveness and visual stealth, validated by perceptual metrics and human evaluation. Our findings highlight the importance of integrated physical modeling and systematic evaluation for advancing physically realizable adversarial camouflage.
| Original language | English |
|---|---|
| Journal | IEEE Internet of Things Journal |
| DOIs | |
| State | Accepted/In press - 2026 |
Keywords
- adversarial camouflage
- physical adversarial attacks
- security of neural network
Fingerprint
Dive into the research topics of 'Flexible Physical Camouflage Generation Based on a Differential Approach'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver