← Search

Zhi Cheng

2 accepted papers

2024

Full-Distance Evasion of Pedestrian Detectors in the Physical World

NeurIPS 2024poster

Many studies have proposed attack methods to generate adversarial patterns for evading pedestrian detection, alarming the computer vision community about the need for more attention to the robustness of detectors. However, adversarial patterns optimized by these methods commonly have limited perform…

2023

Neural Architecture Search for Wide Spectrum Adversarial Robustness

AAAI 2023technical

One major limitation of CNNs is that they are vulnerable to adversarial attacks. Currently, adversarial robustness in neural networks is commonly optimized with respect to a small pre-selected adversarial noise strength, causing them to have potentially limited performance when under attack by large…