[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122600-en":3,"doc-seo-122600-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122600,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","ImageNet-Patch - A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches","Adversarial patches are optimized contiguous pixel blocks that drive machine-learning models to misclassify images, but generating them is computationally intensive and requires careful hyperparameter tuning for fair robustness evaluations. ImageNet-Patch provides a ready-to-use set of pre-optimized patches designed to generalize across different models, enabling an approximate yet faster robustness assessment on ImageNet after fine transformations. Experiments evaluate effectiveness against 127 models and release dataset and evaluation code for broader benchmarking and transfer to other domains.","This is the Author’s manuscript version of the following contribution:  \nM. Pintor, D. Angioni, A. Sotgiu, L. Demetrio, A. Demontis, B. Biggio, and  \nF. Roli. Imagenet-patch: A dataset for benchmarking machine learning robustness against adversarial patches. Pattern Recognition, 134, 2023.  \nThe publisher's version is available at:  \n[https://doi.org/10.1016/j.patcog.2022.109064](https://doi.org/10.1016/j.patcog.2022.109064)  \n[When citing](When citing), please refer to the published version.  \nThis full text was downloaded from UNICA IRIS [https://iris.unica.it/](https://iris.unica.it/)  \nImageNet-Patch: A Dataset for Benchmarking Machine Learning Robustness against  \nAdversarial Patches  \nMaura Pintora,c , Daniele Angionia , Angelo Sotgiua,c , Luca Demetrioa,c , Ambra Demontisa,􀀃, Battista Biggioa,c , Fabio Rolib,c  \na University of Cagliari, Italy  \nb University of Genova, Italy  \nc Pluribus One, Italy  \nAbstract  \nAdversarial patches are optimized contiguous pixel blocks in an input image that cause a machine-learning model to misclassify it. However, their optimization is computationally demanding, and requires careful hyperparameter tuning, potentially leading to suboptimal robustness evaluations. To overcome these issues, we propose ImageNet-Patch, a dataset to benchmark machinelearning models against adversarial patches. It consists of a set of patches, optimized to generalize across di􀀋erent models, and readily applicable to ImageNet data after preprocessing them with a􀀎ne transformations. This process enables an approximate yet faster robustness evaluation, leveraging the transferability of adversarial perturbations. We showcase the usefulness of this dataset by testing the e􀀋ectiveness of the computed patches against 127 models. We conclude by discussing how our dataset could be used as a benchmark for robustness, and how our methodology can be generalized to other domains. We open source our dataset and evaluation code at [https://github.com/pralab/ImageNet-Patch](https://github.com/pralab/ImageNet-Patch).  \nKeywords: adversarial machine learning, adversarial patches, neural networks, defense, detection  \n1. Introduction  \nUnderstanding the security of machine-learning models is of paramount importance nowadays, as these algorithms are used in a large variety of settings, including security-related and mission-critical applications, to extract actionable knowledge from vast amounts of data. Nevertheless, such data-driven algorithms are not robust against attacks, as malicious attackers can easily alter the behavior of state-of-the-art models by carefully manipulating their input data [1, 2, 3, 4] . In particular, attackers can hinder the performance of classiﬁcation algorithms by means of adversarial patches [5], i.e., contiguous chunks of pixels which can be applied to any input image to cause the target model to output an attacker-chosen class. When embedded into input images, adversarial patches produce outof-distribution samples. The reason is that the injected patch induces a spurious correlation with the target label, which is likely to shift the input sample o􀀋 the manifold of natural images. Adversarial patches can be printed as stickers and physically placed on real objects, like stop signs that are then recognized as speed limits [6], and accessories that camouﬂage the identity of a person, hiding their real identity [7] . Therefore, the evaluation of the robustness against these attacks is of the uttermost importance, as they can critically impact real-world applications with physical consequences.  \nThe only way to assess the robustness of a machine-learning system against adversarial patches is to generate and test them  \nagainst the target model of choice. Adversarial patches are created by solving an optimization problem via gradient descent. However, this process is costly as it requires both querying the target model many times and computing the back-propagation algorithm until convergence is reach","cbCaivBxIWOVCgr7","https://ap.wps.com/l/cbCaivBxIWOVCgr7","pdf",3261329,1,12,"English","en",105,"# Introduction\n## Adversarial patches and robustness challenges\n## Dataset motivation and proposed approach\n# Dataset construction and optimization setup\n# Benchmarking evaluation and results\n# Discussion and generalization\n# Open-source release","[{\"question\":\"What are adversarial patches in this work?\",\"answer\":\"Adversarial patches are contiguous pixel blocks applied to an input image so the model outputs an attacker-chosen class.\"},{\"question\":\"Why is evaluating robustness against adversarial patches computationally demanding?\",\"answer\":\"Creating effective patches requires solving an optimization via gradient descent with many model queries and backpropagation steps until convergence.\"},{\"question\":\"How does ImageNet-Patch speed up robustness evaluation?\",\"answer\":\"It uses a small set of pre-optimized patches targeting specific classes, applied to ImageNet samples after fine transformations, leveraging transferability to reduce computational overhead.\"}]","ImageNet-Patch - A Dataset for Benchmarking Machine Learning Robustness against Adversarial Patches | PDF",1785811665,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"imagenet-patch-a-dataset-for-benchmarking-machine-learning-robustness-against-adversarial-patches","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/imagenet-patch-a-dataset-for-benchmarking-machine-learning-robustness-against-adversarial-patches/122600/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What are adversarial patches in this work?","Question",{"text":75,"@type":76},"Adversarial patches are contiguous pixel blocks applied to an input image so the model outputs an attacker-chosen class.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why is evaluating robustness against adversarial patches computationally demanding?",{"text":80,"@type":76},"Creating effective patches requires solving an optimization via gradient descent with many model queries and backpropagation steps until convergence.",{"name":82,"@type":73,"acceptedAnswer":83},"How does ImageNet-Patch speed up robustness evaluation?",{"text":84,"@type":76},"It uses a small set of pre-optimized patches targeting specific classes, applied to ImageNet samples after fine transformations, leveraging transferability to reduce computational overhead.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]