TY - JOUR
T1 - The Vanishing-Truth Patch
T2 - A Scale-Adaptive Vanishing Attack for Anchor-Based YOLO Detectors
AU - Li, Yang
AU - Zhang, Xiaoning
AU - Wang, Zhengjie
AU - Wei, Haoming
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Deep learning-based object detection is essential for aerial surveillance systems, yet it remains critically vulnerable to adversarial attacks. While adversarial patches can conceal objects, current attack methods often lack consistent effectiveness across varying object scales, which poses a fundamental limitation for their robustness in practical aerial scenarios. To address this challenge, we propose the Vanishing-Truth Attack, a novel adversarial patch framework that specifically optimizes a single patch to remain effective across continuous scale changes. Our approach integrates a geometry-aware adaptive scaling (GAAS) mechanism with a tailored objective function, enabling robust dynamic adaptation without requiring multiple patch instances. We evaluate our method on three anchor-based YOLO detectors: YOLOv3, YOLOv5s, and YOLOv5l. Experiments on the challenging multiscale MAR20 dataset demonstrate that our attack achieves a high success rate in concealing objects across all three models, outperforming the compared baseline methods. This work highlights a critical vulnerability in AI perception and provides foundational insights for developing more robust and certifiably secure AI systems.
AB - Deep learning-based object detection is essential for aerial surveillance systems, yet it remains critically vulnerable to adversarial attacks. While adversarial patches can conceal objects, current attack methods often lack consistent effectiveness across varying object scales, which poses a fundamental limitation for their robustness in practical aerial scenarios. To address this challenge, we propose the Vanishing-Truth Attack, a novel adversarial patch framework that specifically optimizes a single patch to remain effective across continuous scale changes. Our approach integrates a geometry-aware adaptive scaling (GAAS) mechanism with a tailored objective function, enabling robust dynamic adaptation without requiring multiple patch instances. We evaluate our method on three anchor-based YOLO detectors: YOLOv3, YOLOv5s, and YOLOv5l. Experiments on the challenging multiscale MAR20 dataset demonstrate that our attack achieves a high success rate in concealing objects across all three models, outperforming the compared baseline methods. This work highlights a critical vulnerability in AI perception and provides foundational insights for developing more robust and certifiably secure AI systems.
KW - Adversarial attack
KW - adversarial patch
KW - deep learning
KW - object detection
UR - https://www.scopus.com/pages/publications/105042735968
U2 - 10.1109/LGRS.2026.3704366
DO - 10.1109/LGRS.2026.3704366
M3 - Article
AN - SCOPUS:105042735968
SN - 1545-598X
VL - 23
JO - IEEE Geoscience and Remote Sensing Letters
JF - IEEE Geoscience and Remote Sensing Letters
M1 - 6013305
ER -