cs.CVSep 27, 2026

Printability-Constrained Adversarial Decals for Near-Nadir Aerial Perception: Measured Ink Gamuts, Nested Realism Constraints, and a Physical-World Bound

Authors: Sandesh Shrestha, K. T. Yasas Mahima, Asanka G. Perera

Organizations: Industrial Systems Engineering (ISE), Asian Institute of Technology (AIT), Pathum Thani 12120, Thailand

Abstract

Adversarial patches for aerial perception are typically evaluated as digital composites, with printing left as an implementation detail. This study imposes three physical constraints during optimization rather than after it: the color range a particular printer can reproduce, the size of the flat panel a vehicle offers, and the loss of fine detail incurred when the patch is imaged from altitude. The principal comparison isolates the ink set. Two patches share all seventeen recorded optimization settings and differ only in the colors available to them. One is constrained to a uniform color cube; the other to a gamut measured by printing and scanning a 216-patch chart. Each was optimized at three seeds and evaluated against thirteen victim conditions, with every rate reported against a size-matched optimized control. The effect of the measured gamut is victim-dependent rather than uniform. Net attack success rises on three of six closed-set segmentation victims, and for these the seed ranges of the two ink sets are disjoint: +0.120+0.120 on DeepLabv3-R101 and +0.041+0.041 on SegFormer-B0. The color-cube patch is consistently stronger on the open-vocabulary segmenter and on two of four detectors, though no detector exceeds a net of +0.026+0.026 under either ink set. The natural explanation is that a printable palette is simply less chromatic and lower in frequency than a digital one. Eleven further patches test this account and it does not hold. Once cardinality is matched, a palette as chromatic as the cube attacks equally well. Cardinality itself shows no trend from three inks to thirty-two. Palettes matched on cardinality, lightness and chroma, and differing only in hue placement, span 0.0350.035 to 0.1360.136. A physical evaluation with printed decals did not detect transfer; it bounds the transferred rate at 0.1330.133, which does not exclude the simulated value of 0.1210.121.

Figures & tables

Explore similar work

May 29, 2026cs.CV

Digital-to-Physical Transfer of Adversarial Patches for Aerial Vehicle Detection

Deep neural network (DNN)-based object detectors are widely used for analyzing aerial and satellite imagery in applications such as environmental monitoring and urban analytics. Despite their strong performance, these models are known to be vulnerable to adversarial examples, and physical adversarial attacks using printable patterns pose realistic security threats. In this paper, we evaluate physical adversarial patch attacks against an aerial vehicle detector by bridging digital optimization and real-world deployment. Adversarial patches are optimized in the digital domain using a loss function that minimizes the maximum objectness score while incorporating non-printability score (NPS) and total variation (TV) constraints to ensure both printability and spatial smoothness. The optimized patches are printed and deployed in three configurations: ON, OFF, and OFF-Side. Experiments using a YOLOv3 detector show that while the OFF patch achieves the highest effectiveness in the digital domain (85.51% Average Objectness Reduction Rate (AORR)), the ON patch demonstrates superior robustness in physical environments (0.197-0.343 Objectness Score Ratio (OSR)) due to its consistent visibility. Furthermore, our results indicate that weather-based augmentation does not necessarily improve patch optimization in this domain. These findings provide critical insights into the practical vulnerabilities of aerial object detection systems.
Jun 16, 2026cs.CV

Structured Adversarial Camouflage via Voronoi Diagrams

Pixel-wise adversarial patches are computationally heavy and often visually detectable, limiting utility in security-critical systems. We present adversarial Voronoi camouflage that optimizes only seed-point locations under fixed, printable palettes using a soft assignment, producing structured, splinter camouflage-like patterns without additional regularization. Evaluated on person detection with COCO-style AP@[.5:.95], naive placement (Inria -> COCO) performs comparably bad, while garment-level application via segmentation mask (3DPeople) results in a significant AP drop. The attack transfers to out-of-domain backgrounds and across detector families (YOLOv9/10/11/12), indicating robustness in black-box settings. Repainting with different palettes largely nullifies the effect, and single-color tweaks show limited tolerance (<=0.17), highlighting a structure-palette coupling. The parameter-efficient, palette-constrained design improves visual plausibility while degrading real-time detector performance. Physical validation and color calibration are left for future work. Code: https://github.com/JensBayer/Voronoi This paper was originally presented at the International Conference on Military Communication and Information Systems (ICMCIS), organized by the Information Systems Technology (IST) Scientific and Technical Committee, IST-224-RSY - the ICMCIS, held in Bath, United Kingdom, 12-13 May 2026.
Aug 5, 2026cs.CV

ColorFD: A Finite-Difference Guided Black-Box Physical Adversarial Attack for Remote Sensing Object Detection

Although deep neural network-based remote sensing object detectors have achieved strong performance, they remain vulnerable to adversarial perturbations. Existing studies mainly focus on digital or white-box settings, whereas black-box physical attacks remain underexplored. These attacks are often constrained by limited physical feasibility and inefficient optimization in high-dimensional search spaces. To address these challenges, this paper proposes ColorFD, a black-box physical attack based on multiple pure-color patches. The patch positions and color parameters are jointly optimized using Differential Evolution (DE). A target-wise fitness and selection mechanism evaluates the attack state of each target and preserves target-specific improvements during evolution. Two guidance strategies further constrain the patch search space. Key-region localization identifies sensitive regions through finite-difference color probing. Common-feature extraction provides category-level spatial priors and avoids repeated localization. Although evaluated on aircraft, the formulation is not inherently restricted to this category. Experiments on YOLOv3u, YOLOv5u, and Faster R-CNN show that ColorFD outperforms the tested black-box patch method across all evaluated detectors and remains competitive with strong white-box baselines. Physical-world experiments further demonstrate that the optimized pure-color patches can be transferred from the digital domain to real imaging conditions.