- By:
- Singhvi, Vivaan ; Hutchins, Jack R; Sadovnik, Amir ; Brogan, Joel R; Bolme, David S; Young, Steven R
- Page Number:
- 1404604
- Volume:
- 14046
- Book Title:
- Proceedings of SPIE Defense + Security 2026
- Publication Date:
- July 2, 2026
- Conference Name:
- SPIE Defense + Security 2026
- Conference Location:
- National Harbor, Maryland, United States of America
- Conference Sponsor:
- SPIE
- View DOI Listing:
- https://doi.org/10.1117/12.3094751
Abstract
While evasion attacks on computer vision systems have been widely studied, creating attacks that remain effective under significant changes in viewpoint continues to be challenging. Traditional approaches often rely on affine transformations of images, but these approaches degrade at larger perspective shifts and often produce unrealistic or ineffective perturbations. Recent methods use differentiable renderers to improve viewpoint robustness, but they typically depend on manually constructed 3D models. We introduce a semi-automated pipeline that generates physically printable and perspective-invariant adversarial patches using only a small set of 2D images. Our method integrates 3D reconstruction, neural rendering, adversarial patch optimization, and an object detection victim model into a unified workflow. We use 2D Gaussian Splatting for high fidelity mesh reconstruction and FlexPara for surface parameterization that produces texture maps suitable for patch editing. Together, these components form a fully differentiable pipeline in PyTorch3D that links texture modification to model outputs, enabling efficient optimization of patches that remain effective across many viewpoints. The complete process, from image capture to patch printing and physical evaluation, can be completed within a few hours. We demonstrate the effectiveness of the resulting patches through attacks on the YOLOv8 object detection model and discuss remaining challenges and opportunities for improving robustness and scalability.