An information-theoretic perspective of physical adversarial patches

Published: 01 Jan 2024, Last Modified: 25 Jan 2025Neural Networks 2024EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: Highlights•An adversarial patch defense (Jedi) that uses entropy to locate and remove adversarial patches.•Jedi’s precise patch localization leads to state-of-the-art performance.•Jedi is robust against adaptive entropy aware attacks as well as stealthy naturalistic patches.•A qualitative study of Jedi’s failure cases suggests that a high entropy plays an important role in adversarial patches.•A new Adaptive Jedi approach to mitigate the limits.
Loading