[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123748-en":3,"doc-seo-123748-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123748,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","ImageNet-Patch - A dataset for benchmarking machine learning robustness against adversarial patches","Adversarial patches are contiguous pixel blocks that drive machine-learning models to misclassify input images, but optimizing them is computationally expensive and depends on careful hyperparameter tuning, which can weaken robustness evaluations. ImageNet-Patch provides a benchmark dataset of pre-optimized patches created using a transferable, state-of-the-art attack, then randomly rotated and translated before being applied to ImageNet data. The benchmark evaluates 127 models and further validates patch effectiveness in physical settings by printing and deploying them on real objects.","Pattern Recognition 134 (2023) 109064  \nContents lists available at ScienceDirect  \nPattern Recognition  \njournal [homepage: www.elsevier.com/locate/patcog](homepage: www.elsevier.com/locate/patcog)  \n| ImageNet-Patch: A dataset for benchmarking machine learning robustness against adversarial patches |  |  |  |\n| --- | --- | --- | --- |\n| Maura Pintora,c, Daniele Angionia, Angelo Sotgiua,c, Luca Demetrio b,c, Ambra Demontisa,∗, Battista Biggioa,c, Fabio Rolib,c\u003Cbr>a University of Cagliari, Italy b University of Genova, Italy c Pluribus One, Italy |  |  |  |\n| a r t i c l e i n f o |  | a b s t r a c t |  |\n| Article history:\u003Cbr>Received 1 March 2022\u003Cbr>Revised 7 July 2022\u003Cbr>Accepted 20 September 2022\u003Cbr>Available online 23 September 2022 |  | Adversarial patches are optimized contiguous pixel blocks in an input image that cause a machinelearning model to misclassify it. However, their optimization is computationally demanding, and requires careful hyperparameter tuning, potentially leading to suboptimal robustness evaluations. To overcome these issues, we propose ImageNet-Patch, a dataset to benchmark machine-learning models against adversarial patches. The dataset is built by ﬁrst optimizing a set of adversarial patches against an ensemble of models, using a state-of-the-art attack that creates transferable patches. The corresponding patches are then randomly rotated and translated, and ﬁnally applied to the ImageNet data. We use ImageNet-Patch to benchmark the robustness of 127 models against patch attacks, and also validate the effectiveness of the given patches in the physical domain (i.e., by printing and applying them to real-world objects). We conclude by discussing how our dataset could be used as a benchmark for robustness, and how our methodology can be generalized to other domains. We open source our dataset and evaluation code at [https://github.com/pralab/ImageNet-Patch](https://github.com/pralab/ImageNet-Patch).\u003Cbr>© 2022 Elsevier Ltd. All rights reserved. |  |\n| Keywords:\u003Cbr>Adversarial machine learning\u003Cbr>Adversarial patches\u003Cbr>Neural networks\u003Cbr>Defense\u003Cbr>Detection |  |  |  |\n\n1. Introduction  \nUnderstanding the security of machine-learning models is of paramount importance nowadays, as these algorithms are used ina large variety of settings, including security-related and missioncritical applications, to extract actionable knowledge from vast amounts of data. Nevertheless, such data-driven algorithms are not robust against adversarial perturbations of the input data [1– 4] In particular, attackers can hinder the performance of classiﬁcation algorithms by means of adversarial patches [5], i.e., contiguous chunks of pixels which can be applied to any input image to cause the target model to output an attacker-chosen class. When embedded into input images, adversarial patches produce out-ofdistribution samples. The reason is that the injected patch inducesa spurious correlation with the target label, which is likely to shift the input sample off the manifold of natural images. Adversarial patches can be printed as stickers and physically placed on real objects, like stop signs that are then recognized as speed limits [6], and accessories that camouﬂage the identity of a person, hiding  \n∗ Corresponding author.  \nE-mail address: [ambra.demontis@unica.it](ambra.demontis@unica.it) (A. Demontis).  \ntheir real identity [7,8]. Therefore, the evaluation of the robustness against these attacks is of the uttermost importance, as they can critically impact real-world applications with physical consequences.  \nThe only way to assess the robustness of a machine-learning system against adversarial patches is to generate and test them against the target model of choice. Adversarial patches are created by solving an optimization problem via gradient descent. However, this process is costly as it requires both querying the target model many times and computing the back-propagation algorithm until convergence is reached. Hence","cbCaihXjT72fYIPy","https://ap.wps.com/l/cbCaihXjT72fYIPy","pdf",3677379,1,11,"English","en",105,"# Introduction\n## Problem: adversarial patches and robustness evaluation\n## Proposed solution: ImageNet-Patch dataset\n## Benchmark construction and physical-domain validation","[{\"question\":\"What problem does ImageNet-Patch address in robustness evaluation?\",\"answer\":\"It addresses the high computational cost and hyperparameter sensitivity of optimizing adversarial patches, which makes robustness evaluation slow and potentially suboptimal. The dataset replaces costly per-evaluation optimization with pre-optimized patches.\"},{\"question\":\"How are the ImageNet-Patch adversarial patches constructed?\",\"answer\":\"The patches are optimized against an ensemble of models using a transferable adversarial patch attack, so they work across different model architectures. Each patch is then randomly rotated and translated before being applied to ImageNet images.\"},{\"question\":\"How is the benchmark validated beyond digital image testing?\",\"answer\":\"The method validates effectiveness in the physical domain by printing the patches and applying them to real-world objects. This checks whether the intended misclassification behavior survives uncontrolled acquisition and environmental conditions.\"}]","ImageNet-Patch - A dataset for benchmarking machine learning robustness against adversarial patches | PDF",1785818321,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"imagenet-patch-a-dataset-for-benchmarking-machine-learning-robustness-against-adversarial-patches-123748","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/imagenet-patch-a-dataset-for-benchmarking-machine-learning-robustness-against-adversarial-patches-123748/123748/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does ImageNet-Patch address in robustness evaluation?","Question",{"text":75,"@type":76},"It addresses the high computational cost and hyperparameter sensitivity of optimizing adversarial patches, which makes robustness evaluation slow and potentially suboptimal. The dataset replaces costly per-evaluation optimization with pre-optimized patches.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How are the ImageNet-Patch adversarial patches constructed?",{"text":80,"@type":76},"The patches are optimized against an ensemble of models using a transferable adversarial patch attack, so they work across different model architectures. Each patch is then randomly rotated and translated before being applied to ImageNet images.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the benchmark validated beyond digital image testing?",{"text":84,"@type":76},"The method validates effectiveness in the physical domain by printing the patches and applying them to real-world objects. This checks whether the intended misclassification behavior survives uncontrolled acquisition and environmental conditions.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]