kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Saliuitl: Ensemble Salience Guided Recovery of Adversarial Patches against CNNs
KTH, School of Electrical Engineering and Computer Science (EECS), Network and Systems Engineering.ORCID iD: 0009-0009-8875-8329
KTH, School of Electrical Engineering and Computer Science (EECS), Network and Systems Engineering.ORCID iD: 0000-0002-4876-0223
KTH, School of Electrical Engineering and Computer Science (EECS), Network and Systems Engineering.ORCID iD: 0000-0003-1835-2963
2025 (English)In: Proceedings IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2025, Institute of Electrical and Electronics Engineers (IEEE) , 2025, p. 20360-20369Conference paper, Published paper (Refereed)
Abstract [en]

Adversarial patches are capable of misleading computer vision systems based on convolutional neural networks. Existing recovery methods suffer of at least one of three fundamental shortcomings: no information about the presence of patches in the scene, inability to efficiently handle noncontiguous patch attacks, and a strong reliance on fixed saliency thresholds. We propose Saliuitl, a recovery method independent of the number of patches and their shape, which unlike prior works, explicitly detects patch attacks before attempting recovery. In our approach, detection is based on the attributes of a binarized feature map ensemble, which is generated by using an ensemble of saliency thresholds. If an attack is detected, Saliuitl recovers clean predictions locating patches guided by an ensemble of binarized feature maps and inpainting them. We evaluate Saliuitl on widely used object detection and image classification benchmarks from the adversarial patch literature, and our results show that compared to recent state-of-the-art defenses, Saliuitl achieves a recovery rate up to 97.81 and 42.63 percentage points higher at the same rate of lost predictions for image classification and object detection, respectively. By design, Saliuitl has low computational complexity and is robust to adaptive white-box attacks. Our code is available at https://github.com/ Saliuitl/Saliuitl/tree/main.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE) , 2025. p. 20360-20369
Series
IEEE Conference on Computer Vision and Pattern Recognition, ISSN 1063-6919
National Category
Computer graphics and computer vision
Identifiers
URN: urn:nbn:se:kth:diva-377408DOI: 10.1109/CVPR52734.2025.01896ISI: 001601158200218OAI: oai:DiVA.org:kth-377408DiVA, id: diva2:2042114
Conference
IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2025, Nashville, TN, USA, June 11-15, 2025
Note

Part of ISBN 979-8-3315-4365-5; 979-8-3315-4364-8

QC 20260226

Available from: 2026-02-26 Created: 2026-02-26 Last updated: 2026-02-26Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Byrd Victorica, MauricioDán, GyörgySandberg, Henrik

Search in DiVA

By author/editor
Byrd Victorica, MauricioDán, GyörgySandberg, Henrik
By organisation
Network and Systems Engineering
Computer graphics and computer vision

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 33 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf