Fooling automated surveillance cameras: adversarial patches to attack person detection

Simen Thys, Wiebe Van Ranst, Toon Goedemé from KU Leuven/Belgium researched adver­sar­i­al patch­es for mov­ing images and came up with sev­er­al pat­terns that dis­turb detec­tion.

Their attack is direct­ed against a specifc library for mov­ing image recog­ni­tion, called YOLOv2, https://pjreddie.com/darknet/yolov2/

The per­son left gets detect­ed as “per­son”, the per­son right with an adver­sar­i­al patch in front of his stom­age is not rec­og­nized auto­mat­i­cal­ly. Simen Thys/Ranst/Goedeme 2019

Full paper at: https://arxiv.org/pdf/1904.08653.pdf