Skip to content
Open access

Color Adversarial Patch Generation for Physical-Domain Palmprint Recognition Attacks

Aug 2026 · Electronics · 0 citations · 38 references

TL;DR

A Color Adversarial Patch generation algorithm that leverages style transfer principles to produce visually natural color patches while maintaining high attack success rates, demonstrating the feasibility of concealed physical-domain attacks on palmprint recognition systems.

Abstract

Physical-domain adversarial attacks have been extensively studied in face recognition and object detection, yet the field of palmprint recognition remains largely unexplored. Existing methods generate grayscale patches constrained by the single-channel input of most palmprint models. When deployed on skin, these patches contrast sharply with the surrounding tissue and are readily noticeable to human observers, undermining the covertness required in practical attacks. To address this limitation, we propose a Color Adversarial Patch (CAP) generation algorithm that leverages style transfer principles to produce visually natural color patches while maintaining high attack success rates. The method initiates the patch with a style prior using a pre-trained Contrastive Arbitrary Style Transfer (CAST) model and jointly optimizes adversarial loss, style loss, and smoothness loss within a unified framework. A three-channel averaging strategy is adopted to ensure compatibility with single-channel recognition models during gradient backpropagation. Experiments on the Tongji palmprint dataset show that the generated color patches achieve average cosine similarity values above the decision threshold in physical-domain tests, with peak signal-to-noise ratio (PSNR) and structural similarity index (SSIM) values significantly higher than those for their grayscale counterparts. Ablation studies validate the indispensable role of each loss component. CAP offers a practical balance between attack effectiveness and visual camouflage, demonstrating the feasibility of concealed physical-domain attacks on palmprint recognition systems.

Read PDF

Similar papers

Preprint Aug 2026

AdvTiles: Physical Adversarial Camouflage Clothing against Person Detectors via Learnable Tiles

Physical adversarial attacks against person detectors have evolved from localized patches to full-body textures. However, achieving both visual naturalness and strong attack effectiveness remains challenging. Existing natural-looking methods typically optimize camouflage textures as a whole, limiting the flexibility to refine local adversarial patterns and their spatial arrangement. To address this issue, we propose AdvTiles, a physical adversarial camouflage framework built from learnable tiles, enabling strong attack performance while preserving a natural camouflage appearance. Specifically, we use a Straight-through (ST) Gumbel-Softmax estimator for differentiable tile selection, enabling joint optimization of tile patterns and spatial layouts. This design provides fine-grained control over adversarial texture generation. To improve robustness in diverse physical conditions, we further optimize the camouflage through differentiable 3D Gaussian Splatting rendering with variations in viewpoints, scales, illuminations and backgrounds. Extensive experiments across multiple detectors demonstrate that AdvTiles achieves an average ASR of 86.2%, outperforming existing state-of-the-art attack methods. We further fabricate the optimized camouflage into wearable adversarial clothing, validating its effectiveness in real-world scenarios across diverse distances, angles and backgrounds.

Jinlei Wang, Jiahuan Long, Mingkai Sun et al. · 0 citations
Open access Jul 2026

DPSF: A Dynamic Patch Shape Selection Framework for Cross-Model Transferable Adversarial Attacks

Adversarial patch attacks are core tools to evaluate adversarial robustness in remote sensing image classification, yet existing methods with fixed patch shapes and single-model optimization yield poor cross-architecture black-box transferability. This paper proposes the Dynamic Patch Shape Selection Framework (DPSF), which integrates a 12-shape patch library, adaptive category matching and multi-model joint optimization with dynamic weight adjustment under a strict 2% patch area constraint. We test DPSF on the UC Merced dataset over eight random split seeds, taking ResNet101, DenseNet161 and VGG19 as held-out black-box models. Under the five-source protocol, DPSF-full achieves mean accuracy drop (ACCD) of 0.380 ± 0.034, adversarial accuracy (Adv Acc) 0.593 ± 0.039, attack success rate (ASR) 0.393 ± 0.037 (on clean-correct test samples, averaged over held-out evaluators), union success rate (USR) 0.581  ±  0.046, and intersection success rate (ISR) 0.188  ±  0.023. With the ResNet50 single-source setting, DPSF-single obtains mean ACCD = 0.275  ±  0.109, surpassing Sparse-RS (0.033  ±  0.012) and Cross-shaped adversarial patch attack (CSPA) (0.232 ± 0.029). Supplementary results on CIFAR-10, Tiny-ImageNet and Mini-ImageNet illustrate cross-scale transfer trends. This work builds a reproducible digital-domain robustness benchmark for aerial land-use scene classification.

Han Zhang, Bo Huang, Bingshu Wang et al. · 0 citations
Open access 2026

Mitigating Adversarial Vulnerabilities in Deep Learning-Based Face Recognition Using Stacked Attention Residual GAN and Fire Hawk Optimization

Optimize Deep Learning–based Adversarial Defense Mechanism (ODL-ADM) is proposed in this work, which projects adversarial samples into an immune feature space that is both discriminative and resistant to perturbations.

Sheilla Ann Bangoy Pacheco, Mahesh Goyani, Jayzel P. Bangoy et al. · 0 citations
Aug 2026

Adversarial face camouflage based on multi-parameter enhancement.

This approach improves transferability by combining different parameter initializations to generate a diversified set of surrogate models and integrates an adversarial makeup technique that generates adversarial disguises from reference images, thereby further boosting the attack's effectiveness.

DaPeng Men, Jingyu Wang, Xiaolin Zhang et al. · 0 citations
2026

RFA-Tex: Range-Flexible Adaptive Physical Adversarial Texture Against Real-World Person Detectors

Adversarial attacks have attracted growing research interest as they transition from the digital domain to the real world. Among these, adversarial textures that conceal the human body from various person detectors have drawn significant research attention. Yet existing methods can only launch attacks at close range (within 5 m); once the distance increases to common imaging and surveillance distances (over 15 m), these methods become ineffective. We identify that this limitation stems from the numerous fragile fine-grained structures in the textures, which are prone to deterioration during long-range imaging, leading to the loss of adversarial effectiveness. Modifying these fragile structures requires fine-grained adjustments to the textures, but the existing texture generation frameworks fail to support such adjustments. To address this issue, we propose a Range-Flexible Adaptive Physical Adversarial Texture, named RFA-Tex. We first design a detail-preserving texture generation framework that decouples the environmental adaptability from the adversarial effectiveness and optimizes them separately. We further develop a novel deterioration function to suppress the fragile structures in textures, which significantly improves their adaptability to long-range imaging. Moreover, we conduct a theoretical analysis to illustrate that RFA-Tex better supports fine-grained texture adjustments than prior works. Experimental results in digital and physical domains demonstrate that RFA-Tex significantly extends the adversarial attack range to 25–45 m in various real-world scenarios, while exhibiting strong generalization and robustness.

Mengyao Zhu, Xinghua Li, Decheng Liu et al. · 1 citation
Open access Jul 2026

Wrapper-Based Adversarial Input Screening for Deep Image Classifiers Using Feature Squeezing and Logit-Space Inconsistency

A wrapper-based adversarial input screening approach that compares a classifier’s output on an original image with its output after benign feature-squeezing transformations is evaluated, supporting the use of median filtering with logit-space ℓ2 inconsistency as a tool for screening adversarial inputs to image classifiers, but its effectiveness depends on dataset complexity, classifier behaviour, and attack adaptivity.

Alketa Hyso, Dezdemona Gjylapi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.