Adversarial Robustness in Perception Models
Hardening perception systems against real-world attacks.
Techniques and evaluations for improving robustness of perception models under physical and digital adversarial conditions. Joint work informing AI Security technology and defence deployments.
Threat Models
Physical, digital, and supply-chain vectors.
Defences
Adversarial training and certified methods.
Evaluation
Realistic red-team benchmarks.
Deployment
Robust perception in the field.
Threat landscape
We catalog sticker attacks, lighting spoofs, digital perturbations, and poisoned fine-tuning sets. Each threat is paired with detection and training-time mitigations suitable for industrial and defence contexts.
Methods
Adversarial training, randomized smoothing, and input-space detectors are compared under compute constraints typical of edge devices. We emphasize defences that degrade gracefully rather than fail silently.
Field transfer
Lab robustness does not always transfer outdoors. We report outdoor red-team results and monitoring signals that catch novel attacks after deployment.
Discuss this work with our labs.
