Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon

Yiqi ZhongXianming LiuDeming ZhaiJunjun JiangXiangyang Ji

article2022CVPR214 citations

Demonstrates that casting simple, natural shadows onto traffic signs can deceive vision models in physical-world black-box settings with success rates exceeding 90%, exposing a critical real-world vulnerability in autonomous systems.

Listen

Deep neural networks are increasingly deployed in safety-critical visual applications such as autonomous driving. However, these systems remain vulnerable to adversarial physical modifications, such as stickers or artificial light beams, which alter model outputs without human detection. Existing physical attacks often require direct physical tampering or rely on conspicuous artificial projections that are easily noticed by people. The article demonstrates a novel, non-invasive physical attack that uses ordinary natural shadows to stealthily fool vision systems under realistic black-box conditions, where the attacker has no knowledge of internal model parameters.

To implement the attack, the authors model shadows digitally as simple triangular geometric shapes that selectively reduce image lightness. They search for optimal shadow placements using a population-based search algorithm called particle swarm optimization, avoiding the need for model gradients. To ensure the physical viability of these digital patterns across changing viewing angles, distances, and lighting conditions, the framework incorporates transformation modeling and prediction stabilization techniques. The authors evaluate the approach digitally across standard benchmark traffic sign datasets (LISA and GTSRB) and physically using real cardboards outdoors in natural sunlight and flashlights indoors.

The findings show that natural shadows pose an acute and practical security risk. In digital benchmarks, the attack achieves misclassification rates of 98.23% on LISA and 90.47% on GTSRB under typical shadow intensities, requiring only tens to hundreds of model queries. In physical outdoor experiments with a moving camera, the shadow perturbation caused continuous misclassification across 100% of recorded frames, stabilizing on a single incorrect class (misclassifying a speed limit 25 sign as a speed limit 35 sign) over 95% of the time. Furthermore, the article demonstrates simulated scheduled attacks, where natural solar movement triggers deception only during specific times of day, such as peak morning traffic hours, lasting from tens of seconds to several minutes.

These results demonstrate that machine vision models can be severely compromised by subtle, everyday phenomena without arousing human suspicion. Because the shadow continuously induces a specific erroneous class rather than random misclassifications, common defensive voting filters fail. To counter this vulnerability, the authors evaluate an adversarial defense mechanism that adds randomized shadow simulations to training data. This defense increases model robustness against shadow attacks up to 40.93% and dramatically elevates attack difficulty with only a minor decrease in standard classification accuracy.

The attack relies on a single dominant light source and struggles in low-contrast diffuse lighting or multi-source environments, and it currently cannot enforce arbitrary target classes directly. System designers for autonomous vehicles and security-critical computer vision should integrate shadow-augmented training into their machine learning pipelines and maintain caution regarding single-sensor reliability in uncontrolled outdoor environments.

arXiv: 2203.03818
  • Paper: Synthesizing Robust Adversarial Examples, Anish Athalye et al. (2017). Its expectation-over-transformation framework establishes how adversarial patterns can remain effective across changing viewpoints and lighting, a key premise of the source’s physically viable shadow attacks.
  • Paper: Adversarial examples in the physical world, Alexey Kurakin et al. (2016). It first demonstrates that adversarial examples can survive printing and camera capture, grounding the source’s move from digital shadow patterns to real-world attacks.
  • Paper: Adversarial Patch, Tom B. Brown et al. (2017). Its printable, scene-robust physical attack provides an early model for understanding how localized visual changes can fool classifiers outside the lab.
  • Paper: Black-box Adversarial Attacks with Limited Queries and Information, Andrew Ilyas et al. (2018). Its treatment of query-limited, gradient-free attacks prepares readers for the source’s black-box search for effective shadow placements.
  • Paper: Intriguing properties of neural networks, Christian Szegedy et al. (2014). Its foundational demonstration that tiny input changes can flip neural-network predictions establishes the adversarial vulnerability that the source exploits with natural shadows.

No sufficiently relevant recommendations were found.

Cover for Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon

Abstract

Estimating the risk level of adversarial examples is essential for safely deploying machine learning models in the real world. One popular approach for physical-world attacks is to adopt the “sticker-pasting” strategy, which however suffers from some limitations, including difficulties in access to the target or printing by valid colors. A new type of non-invasive attacks emerged recently, which attempt to cast perturbation onto the target by optics based tools, such as laser beam and projector. However, the added optical patterns are artificial but not natural. Thus, they are still conspicuous and attention-grabbed, and can be easily noticed by humans. In this paper, we study a new type of optical adversarial examples, in which the perturbations are generated by a very common natural phenomenon, shadow, to achieve naturalistic and stealthy physical-world adversarial attack under the black-box setting. We extensively evaluate the effectiveness of this new attack on both simulated and real-world environments. Experimental results on traffic sign recognition demonstrate that our algorithm can generate adversarial examples effectively, reaching 98.23% and 90.47% success rates on LISA and GTSRB test sets respectively, while continuously misleading a moving camera over 95% of the time in real-world scenarios. We also offer discussions about the limitations and the defense mechanism of this attack1.

Table of Contents

  • 1. Introduction
  • 2. Related Work
  • 2.1. Adversarial Examples
  • 2.2. Adversarial Examples in Digital Domain
  • 2.3. Adversarial Examples in Real Physical World
  • 3. Approach
  • 3.1. Problem Formulation
  • 3.2. Shadow Perturbation Modeling
  • 3.3. Shadow Attack in Digital Domain
  • 3.4. Shadow Attack in Real Physical-World
  • 4. Experiments
  • 4.1. Datasets and Models
  • 4.2. Evaluation in Digital Domain
  • 4.3. Evaluation in Physical Domain
  • 4.4. Scheduled Attack
  • 4.5. Ablation study
  • 4.6. How to Defend against the Shadow Attack?
  • 5. Limitation
  • 6. Conclusion
  • 7. Acknowledgement
  • References

Knowls

  1. Knowl 1 — Shadow Perturbation Modeling in LAB Color Space

    model/method

    Natural shadows primarily affect lightness rather than chromaticity. Empirical statistical analysis of 400 images from the SBU Shadow dataset confirms that the mean ratio of shadow pixel values to non-shadow pixel values is 0.430.43 for the lightness channel LL, 0.990.99 for channel AA, and 0.900.90 for channel BB, with standard deviations for AA and BB of 0.050.05 and 0.070.07, respectively.

    To simulate shadow perturbations in digital images, an input RGB image xx is first converted to the LAB color space LAB(x)=[Lx,Ax,Bx]\text{LAB}(x) = [L_x, A_x, B_x]. A shadow area on the target object is parameterized by a polygon PVP_V with vertices V={(m1,n1),(m2,n2),…,(ms,ns)}V = \{(m_1, n_1), (m_2, n_2), \dots, (m_s, n_s)\} and a binary target mask MM. The shadow perturbation operation S(x,PV,M,k)S(x, P_V, M, k) modifies the LAB pixel values at coordinates (i,j)(i, j) according to:

    LABij(xadv)={LABij(x)⋅[k,1,1]Tif (i,j)∈PV∩MLABij(x)⋅[1,1,1]Tif (i,j)∉PV∩M\text{LAB}_{ij}(x_{\text{adv}}) = \begin{cases} \text{LAB}_{ij}(x) \cdot [k, 1, 1]^T & \text{if } (i, j) \in P_V \cap M \\ \text{LAB}_{ij}(x) \cdot [1, 1, 1]^T & \text{if } (i, j) \notin P_V \cap M \end{cases}

    where k∈(0,1)k \in (0, 1) is the shadow lightness attenuation coefficient. The perturbed image xadvx_{\text{adv}} is subsequently converted back to RGB color space. For stealthiness and physical feasibility, PVP_V is parameterized as a triangle (s=3s = 3 with vertices V={(m1,n1),(m2,n2),(m3,n3)}V = \{(m_1, n_1), (m_2, n_2), (m_3, n_3)\}).

  2. Knowl 2 — Black-Box Shadow Attack via Particle Swarm Optimization

    algorithm

    In a score-based black-box setting, an attacker optimizes the triangle vertex coordinates V={(m1,n1),(m2,n2),(m3,n3)}V = \{(m_1, n_1), (m_2, n_2), (m_3, n_3)\} to minimize the classifier's predicted confidence on the true class ytruey_{\text{true}}:

    arg⁡min⁡Vftrue(S(x,PV,M,k))s.t.y~adv≠ytrue\arg \min_V f_{\text{true}}(S(x, P_V, M, k)) \quad \text{s.t.} \quad \tilde{y}_{\text{adv}} \neq y_{\text{true}}

    where fi(⋅)f_i(\cdot) is the model's confidence for class ii, y~adv=arg⁡max⁡ifi(xadv)\tilde{y}_{\text{adv}} = \arg\max_i f_i(x_{\text{adv}}), and S(x,PV,M,k)S(x, P_V, M, k) generates a shadow-perturbed image.

    Zeroth-Order Optimization (ZOO) exhibits gradient explosion and vanishing because vertex coordinates are discrete and the shadow mask membership function (i,j)∈PV∩M(i, j) \in P_V \cap M is a non-differentiable step indicator. Particle Swarm Optimization (PSO) circumvents gradient estimation by maintaining a population of particles, each representing a candidate coordinate set VV with a corresponding velocity vector. Particles iteratively update their velocity and position based on their individual historical optimum and the global swarm optimum, using ftrue(⋅)f_{\text{true}}(\cdot) as the cost function. Optimization terminates when y~adv≠ytrue\tilde{y}_{\text{adv}} \neq y_{\text{true}} or the iteration budget is exhausted. An nn-random-restarts scheme (with n=5n = 5) reinitializes and reruns PSO up to n−1n - 1 times if an attack run fails.

  3. Knowl 3 — Physical-World Robustness via EOT and Prediction Stabilization

    model/method

    To transfer digitally generated shadow perturbations to physical environments across varying camera poses, distances, and illumination conditions, two enhancement strategies are employed:

    1. Expectation Over Transformation (EOT): The optimization incorporates a distribution of transformation functions T\mathcal{T} that includes random downsampling, brightness adjustment, perspective transformation, motion blur, and variations in the shadow coefficient kk. The optimization minimizes the expectation of true-class confidence over T\mathcal{T}, approximated empirically using 10 random transformations alongside the original image:

    arg⁡min⁡VEt∼T[ftrue(t(xadv))]s.t.y~adv≠ytrue\arg \min_V \mathbb{E}_{t \sim \mathcal{T}}[f_{\text{true}}(t(x_{\text{adv}}))] \quad \text{s.t.} \quad \tilde{y}_{\text{adv}} \neq y_{\text{true}}

    1. Prediction Stabilization: Because untargeted physical perturbations can oscillate across different incorrect labels as viewing geometry changes (which can be countered by majority voting across video frames), a two-stage optimization stabilizes the misclassification. After first finding an incorrect label y~w\tilde{y}_w via EOT minimization, PSO is rerun to maximize the model's confidence for that specific error class:

    arg⁡max⁡VEt∼T[fw(t(xadv))]s.t.y~adv=y~w\arg \max_V \mathbb{E}_{t \sim \mathcal{T}}[f_w(t(x_{\text{adv}}))] \quad \text{s.t.} \quad \tilde{y}_{\text{adv}} = \tilde{y}_w

  4. Knowl 4 — Scheduled Physical Shadow Attack via Solar Trajectory Modeling

    model/method

    A physical shadow attack can be scheduled to activate exclusively during specific time windows (e.g., peak traffic hours) and remain non-adversarial during other times by exploiting the diurnal movement of the sun.

    A physical occluder (such as a cardboard cutout) is placed at a fixed position relative to the target traffic sign. Given the target geographic location (latitude and longitude), calendar date, scheduled time t0t_0, and occluder distance along the axis perpendicular to the sign, the solar elevation angle and solar azimuth angle are computed. These angles determine the projection of the occluder vertices onto the sign plane.

    By fixing the occluder geometry so that the projected shadow matches the adversarial polygon PVP_V at the scheduled time t0t_0, the shadow creates misclassification during a continuous time window around t0t_0 (ranging from dozens of seconds to several minutes) while leaving the traffic sign cleanly classified prior to and after this period.

  5. Knowl 5 — Digital Attack Success Rates and Query Counts across Shadow Coefficients

    data/table

    The effectiveness of the black-box shadow attack depends on the shadow lightness coefficient kk. Attack success rate (ASR, in %) and average query count at first success were evaluated on the test sets of LISA (top 16 classes) and GTSRB (43 classes) using CNN classifiers after removing images with average traffic sign LL-channel value below 120.

    Model / Metric Shadow Coefficient kk
    0.20 0.25 0.30 0.35 0.40 0.43 0.45 0.50 0.55 0.60 0.65 0.70
    LISA-CNN ASR (%) 100.00 100.00 99.73 99.18 99.05 98.23 97.95 96.04 93.18 88.81 83.08 72.71
    LISA-CNN Queries 26.6 27.7 38.4 71.8 83.4 91.2 100.6 137.0 169.2 195.9 306.7 293.4
    GTSRB-CNN ASR (%) 97.37 96.35 95.14 93.45 91.36 90.47 88.97 87.15 84.25 80.36 73.76 66.73
    GTSRB-CNN Queries 98.3 93.7 112.8 129.0 128.4 126.8 136.9 155.9 188.3 232.0 294.2 343.4

    At the empirical dataset mean k=0.43k = 0.43, the attack achieves 98.23%98.23\% success on LISA with 91.291.2 queries and 90.47%90.47\% on GTSRB with 126.8126.8 queries. When k>0.70k > 0.70, the shadow is faint, causing attack success rates to decline and required query counts to increase.

  6. Knowl 6 — Physical-World Experimental Results for Outdoor and Indoor Shadow Attacks

    empirical result

    Physical validation on traffic sign recognition demonstrates high attack success and temporal stability under dynamic video capture:

    • Outdoor Daylight Scenario: A cardboard cutout was used to cast an adversarial shadow onto a US Speed Limit 25 sign under natural sunlight. A video of 220 frames captured an approaching camera moving from far to near. The classifier achieved a 100.00%100.00\% frame-level misclassification rate, with 95.91%95.91\% of all frames consistently misclassified as Speed Limit 35.

    • Indoor / Night Scenario: In a dark stairwell illuminated by a single flashlight, shadow attacks were evaluated across 100-frame approaching videos for four US speed limit signs from the LISA dataset:

      • Speed limit 25 sign: 100%100\% error rate, 88%88\% predicted as Speed limit 35.
      • Speed limit 30 sign: 100%100\% error rate, 93%93\% predicted as Speed limit 35.
      • Speed limit 35 sign: 95%95\% error rate, 71%71\% predicted as Speed limit 30.
      • Speed limit 45 sign: 100%100\% error rate, 76%76\% predicted as Signal Ahead.
  7. Knowl 7 — Defense via Fast Random-Shadow Adversarial Training

    data/table

    Standard adversarial training using full PSO black-box optimization per sample per epoch is computationally intractable. A fast adversarial training alternative incorporates a random triangular shadow (random vertex coordinates VV and random coefficient kk) into each training image during every epoch.

    Evaluating retrained models (denoted with subscript rob) against the black-box shadow attack (k=0.43k = 0.43) yields the following clean accuracy, robustness (defined as 1−attack success rate1 - \text{attack success rate} in %), and average queries needed for successful attack:

    Model Clean Accuracy (%) Robustness (%) Queries
    LISA-CNN 99.63 1.73 91.24
    GTSRB-CNN 99.00 9.53 126.75
    LISA-CNNrob_{\text{rob}} 99.56 40.93 849.51
    GTSRB-CNNrob_{\text{rob}} 98.91 25.57 464.52

    Random-shadow adversarial training substantially increases the model robustness and query budget required to find an adversarial shadow, while incurring less than a 0.1%0.1\% drop in clean accuracy.

  8. Knowl 8 — Ablation on Polygon Edge Count and PSO Random Restarts

    data/table

    The influence of the number of polygon edges in PVP_V and the number of PSO random restarts nn on attack success rate (ASR, in %) was evaluated in the digital domain:

    Model Number of Polygon Edges
    3 5 7 9
    LISA-CNN 97.95 98.91 99.45 99.59
    GTSRB-CNN 90.80 93.72 96.83 97.59
    Model Number of Restarts nn
    1 5 10 50 100
    LISA-CNN 95.91 98.36 98.50 99.05 99.18
    GTSRB-CNN 87.76 90.74 91.76 92.81 93.22

    Triangular shadows (33 edges) provide a practical trade-off, obtaining over 90%90\% ASR while preserving natural appearance and physical realizability compared to complex polygons. For restarts, n=5n = 5 achieves most of the performance gain over single-run PSO (n=1n = 1) with minimal additional computation.

  9. Knowl 9 — Physical Limitations of Shadow Adversarial Attacks

    limitation

    The physical shadow attack is subject to two main constraints:

    1. Lighting Environment Dependency: The attack requires a dominant single light source (such as direct sunlight or a focused flashlight). In environments with poor lighting, the shadow factor kk is large, leaving the perturbed image indistinguishable from the clean image and reducing attack success. In environments with multiple ambient or diffuse light sources, distinct sharp shadow boundaries cannot be formed.

    2. Lack of Direct Targeted Optimization: Due to the single-directional nature of shadow perturbations (which only darken the LL channel within a local area), the attack cannot directly enforce arbitrary target class misclassifications during initial search, requiring a post-hoc stabilization phase to freeze whatever incorrect class is found.

Coverage note — None was omitted; all contributed models, equations, physical/digital algorithms, empirical evaluations, ablations, defense analyses, and limitations are fully represented.

References

  1. 1.Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. Synthesizing robust adversarial examples. In International conference on machine learning, pages 284–293. PMLR, 2018.
  2. 2.Wieland Brendel, Jonas Rauber, and Matthias Bethge. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv preprint arXiv:1712.04248, 2017.
  3. 3.Nicholas Carlini and David Wagner. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp), pages 39–57. IEEE, 2017.
  4. 4.Jianbo Chen, Michael I Jordan, and Martin J Wainwright. Hopskipjumpattack: A query-efficient decision-based attack. In 2020 ieee symposium on security and privacy (sp), pages 1277–1294. IEEE, 2020.
  5. 5.Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM workshop on artificial intelligence and security, pages 15–26, 2017.
  6. 6.Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li. Boosting adversarial attacks with momentum. In Proceedings of the IEEE conference on computer vision and pattern recognition, pages 9185–9193, 2018.
  7. 7.Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu. Evading defenses to transferable adversarial examples by translation-invariant attacks. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 4312–4321, 2019.
  8. 8.Ranjie Duan, Xingjun Ma, Yisen Wang, James Bailey, A Kai Qin, and Yun Yang. Adversarial camouflage: Hiding physical-world attacks with natural styles. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, pages 1000–1008, 2020.
  9. 9.Ranjie Duan, Xiaofeng Mao, A. K. Qin, Yuefeng Chen, Shaokai Ye, Yuan He, and Yun Yang. Adversarial laser beam: Effective physical-world attack to dnns in a blink. In 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 16057–16066, 2021.
  10. 10.Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song. Robust physical-world attacks on deep learning visual classification. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), June 2018.
  11. 11.G.D. Finlayson, S.D. Hordley, Cheng Lu, and M.S. Drew. On the removal of shadows from images. IEEE Transactions on Pattern Analysis and Machine Intelligence, 28(1):59–68, 2006.
  12. 12.Abhiram Gnanasambandam, Alex M. Sherman, and Stanley H. Chan. Optical adversarial attack. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV) Workshops, pages 92–101, October 2021.
  13. 13.Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572, 2014.
  14. 14.Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. Black-box adversarial attacks with limited queries and information. In International Conference on Machine Learning, pages 2137–2146. PMLR, 2018.
  15. 15.James Kennedy and Russell Eberhart. Particle swarm optimization. In Proceedings of ICNN'95-international conference on neural networks, volume 4, pages 1942–1948. IEEE, 1995.
  16. 16.Alexey Kurakin, Ian Goodfellow, Samy Bengio, et al. Adversarial examples in the physical world, 2016.
  17. 17.Hieu Le and Dimitris Samaras. Physics-based shadow image decomposition for shadow removal. IEEE Transactions on Pattern Analysis and Machine Intelligence, pages 1–1, 2021.
  18. 18.Peiliang Li, Xiaozhi Chen, and Shaojie Shen. Stereo r-cnn based 3d object detection for autonomous driving. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), June 2019.
  19. 19.Geert Litjens, Thijs Kooi, Babak Ehteshami Bejnordi, Arnaud Arindra Adiyoso Setio, Francesco Ciompi, Mohsen Ghafoorian, Jeroen Awm Van Der Laak, Bram Van Ginneken, and Clara I Sánchez. A survey on deep learning in medical image analysis. Medical image analysis, 42:60–88, 2017.
  20. 20.Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083, 2017.
  21. 21.Andreas Mogelmose, Mohan Manubhai Trivedi, and Thomas B Moeslund. Vision-based traffic sign detection and analysis for intelligent driver assistance systems: Perspectives and survey. IEEE Transactions on Intelligent Transportation Systems, 13(4):1484–1497, 2012.
  22. 22.Dinh-Luan Nguyen, Sunpreet S. Arora, Yuhang Wu, and Hao Yang. Adversarial light projection attacks on face recognition systems: A feasibility study. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) Workshops, June 2020.
  23. 23.Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. The limitations of deep learning in adversarial settings. In 2016 IEEE European symposium on security and privacy (EuroS&P), pages 372–387. IEEE, 2016.
  24. 24.Athena Sayles, Ashish Hooda, Mohit Gupta, Rahul Chatterjee, and Earlence Fernandes. Invisible perturbations: Physical adversarial examples exploiting the rolling shutter effect. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 14666–14675, 2021.
  25. 25.Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter. Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 acm sigsac conference on computer and communications security, pages 1528–1540, 2016.
  26. 26.Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel. Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural networks, 32:323–332, 2012.
  27. 27.Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199, 2013.
  28. 28.James Tu, Mengye Ren, Sivabalan Manivasagam, Ming Liang, Bin Yang, Richard Du, Frank Cheng, and Raquel Urtasun. Physically realizable adversarial examples for lidar object detection. In 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 13713–13722, 2020.
  29. 29.Tomás F Yago Vicente, Le Hou, Chen-Ping Yu, Minh Hoai, and Dimitris Samaras. Large-scale training of shadow detectors with noisily-annotated shadow examples. In European Conference on Computer Vision, pages 816–832. Springer, 2016.
  30. 30.Weibin Wu, Yuxin Su, Xixian Chen, Shenglin Zhao, Irwin King, Michael R Lyu, and Yu-Wing Tai. Boosting the transferability of adversarial samples via attention. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 1161–1170, 2020.
  31. 31.Cihang Xie, Zhishuai Zhang, Yuyin Zhou, Song Bai, Jianyu Wang, Zhou Ren, and Alan L Yuille. Improving transferability of adversarial examples with input diversity. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 2730–2739, 2019.
  32. 32.Jiancheng Yang, Yangzhou Jiang, Xiaoyang Huang, Bingbing Ni, and Chenglong Zhao. Learning black-box attackers with transferable priors and query feedback. Advances in Neural Information Processing Systems, 33, 2020.
  33. 33.Ling Zhang, Qing Zhang, and Chunxia Xiao. Shadow remover: Image shadow removal based on illumination recovering optimization. IEEE Transactions on Image Processing, 24(11):4623–4636, 2015.
  34. 34.Wuming Zhang, Xi Zhao, Jean-Marie Morvan, and Liming Chen. Improving shadow suppression for illumination robust face recognition. IEEE Transactions on Pattern Analysis and Machine Intelligence, 41(3):611–624, 2019.

Citation

MLA
Zhong, Y., et al. “Shadows Can Be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon”. arXiv, 2022, http://arxiv.org/abs/2203.03818v3.
APA
Zhong, Y., Liu, X., Zhai, D., Jiang, J., & Ji, X. (2022). Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon. arXiv. http://arxiv.org/abs/2203.03818v3
Chicago
Zhong, Y., X. Liu, D. Zhai, J. Jiang, and X. Ji. 2022. “Shadows Can Be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon”. arXiv. http://arxiv.org/abs/2203.03818v3.
Harvard
Zhong, Y. et al. (2022) “Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon”, arXiv [Preprint]. Available at: http://arxiv.org/abs/2203.03818v3.
Vancouver
1. Zhong Y, Liu X, Zhai D, Jiang J, Ji X (2022) Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon. arXiv

BibTeX

@article{zhong2022shadows,
  title = {Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon},
  author = {Zhong, Yiqi and Liu, Xianming and Zhai, Deming and Jiang, Junjun and Ji, Xiangyang},
  year = {2022},
  journal = {arXiv},
  url = {http://arxiv.org/abs/2203.03818v3},
  eprint = {2203.03818}
}
Metadata:arXiv

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: IEEE