Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection
Qiucheng Yu, Tao Ni, Yihe Zhou, Jiayimei Wang, Qingchuan Zhao
cs.CR, cs.CV
Submitted: 2026-07-25
Code: https://github.com/derronqi/yolov8-face
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
The gist: Deep learning-based visual-infrared fused face detection models are increasingly deployed across a wide range of applications, yet they remain susceptible to adversarial patch attacks.
Terminology
Abstract
Deep learning-based visual-infrared fused face detection models are increasingly deployed across a wide range of applications, yet they remain susceptible to adversarial patch attacks. Most prior attacks target either the visual or the infrared image alone in the digital domain, which renders them ineffective against fused models in the physical world. Moreover, many of these methods are readily noticeable, as their patch patterns deviate substantially from those seen in the real world. In this paper, we introduce VIPatch (Visual-Infrared Patch), a novel physical adversarial patch attack that produces inconspicuous, realistic, and natural-looking patches for facial images. Specifically, VIPatch crafts a gradient-color mask together with a band-aid sticker across both the visual and infrared images, and jointly optimizes these two elements; the resulting digital patches further guide the fabrication of their physical counterparts. Experimental results show that VIPatch achieves competitive attack success rates (over 90%) in both the digital and physical domains, while keeping the patches unobtrusive to human observers.
Sources
- RetinaFace: Single-stage Dense Face Localisation in the Wild
- Sample and Computation Redistribution for Efficient Face Detection
- PuriDefense: Randomized Local Implicit Adversarial Purification for Defending Black-box Query-based Attacks
- Non-intrusive and Unconstrained Keystroke Inference in VR Platforms via Infrared Side Channel
- Visually Imperceptible Adversarial Patch Attacks on Digital Images
- A Contemporary Survey of Large Language Model Assisted Program Analysis
- Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition
- The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
- FIGhost: Fluorescent Ink-based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition
- Hidden Tail: Adversarial Image Causing Stealthy Resource Consumption in Vision-Language Models
- A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs