arXiv:2608.20748v1 Announce Type: new
Abstract: The Visual Geometry Grounded Transformer (VGGT) enables unified feed-forward 3D reconstruction from multi-view images. However, deploying such a high-p...
By Qi Song, Ziyuan Luo, Haoliang Han, Renjie Wan
The paper presents 3DGAA, a fabrication-first framework that generates view-consistent, geometry-preserving adversarial wraps for vehicles using 3D Gaussian splatting optimization. It ensures consistency across viewpoints, illumination, and occlusion while limiting changes to vehicle geometry, producing realistic print-only textures that significantly reduce detection confidence and average precision in simulations and physical tests. Ablation and efficiency studies analyze the impact of physical filtering, augmentation, and shape-consistency regularization, and the method demonstrates robustness against common preprocessing defenses and cross-detector transferability.
By Yixun Zhang, Lizhi Wang, Junjun Zhao, Wending Zhao, Feng Zhou, Yonghao Dang, Jianqin Yin
arXiv:2608.29510v1 Announce Type: cross
Abstract: Aerial object detection is increasingly deployed in real-world applications, but models remain vulnerable to physical, universal adversarial patches...
By Haoran Wang, Matthew Lau, Alec Helbling, Matthew Hull, ShengYun Peng, Mansi Phute, Martin Andreoni, Willian T. Lunardi, Duen Horng Chau, Wenke Lee
arXiv:2602. 07104v2 Announce Type: replace-cross Abstract: Multimodal large language models (MLLMs) have advanced the capabilities to interpret and act on visual input in 3D environments, empowering diverse applications such as robotics and situated conversational agents.
By Zhuoheng Li, Ying Chen
arXiv:2607. 17077v1 Announce Type: cross Abstract: Adversarial attacks against vision models like object detectors are often evaluated under limited conditions, leaving their performance under-characterized.
By Mansi Phute, Alexander Greenhalgh, Matthew Hull, Haoran Wang, Alec Helbling, ShengYun Peng, Elliott Faa, Willian Lunardi, Martin Andreoni, Wenke Lee, Duen Horng Chau
arXiv:2510. 16923v3 Announce Type: replace-cross Abstract: Deep learning models deployed in safety critical applications like autonomous driving use simulations to test their robustness against adversarial attacks in realistic conditions.
By Mansi Phute, Matthew Hull, Haoran Wang, Alec Helbling, ShengYun Peng, Willian Lunardi, Martin Andreoni, Wenke Lee, Duen Horng Chau
arXiv:2609.18133v1 Announce Type: new
Abstract: Visible-infrared object detectors are used for robust perception under challenging illumination and weather conditions. Current physical attacks apply...
By Yueqi Zhu, Qi Ming, Guo Cheng, Yongkang Zhang, Feiran Liu, Juan Fang, Jiahuan Zhou, Jiangmeng Li, Yuhan Zhang
arXiv:2606. 30024v1 Announce Type: cross Abstract: Recent advances in deep learning have notably improved steganographic message hiding.
By Fanye Kong, Hongyu Xia, Yu Zheng, Boyang Gong, Jie Zhou, Jiwen Lu
arXiv:2608.23984v1 Announce Type: new
Abstract: Recent advances in single-image 3D Gaussian head reconstruction have enabled highly realistic and freely renderable digital heads from a single portrai...
By Yujie Gao, Zijian Yu, Yan Hong, Jun Lan, Jianfu Zhang
arXiv:2606. 17711v1 Announce Type: cross Abstract: Pixel-wise adversarial patches are computationally heavy and often visually detectable, limiting utility in security-critical systems.
By Jens Bayer, Stefan Becker, David M\"unch, Michael Arens, J\"urgen Beyerer
arXiv:2607. 00174v1 Announce Type: cross Abstract: We present a black-box model-stealing attack that recovers private vision-tokenizer configurations of deployed vision-language models (VLMs), including the visual patch size and input preprocessing pipeline.
By Kai Hu, Akash Bharadwaj, Weichen Yu, Matt Fredrikson
The paper introduces TempJail, a temporal jailbreak framework targeting image‑to‑video generation models. It exploits a newly identified vulnerability where unsafe semantics arise from the composition of frames over time, rather than from single‑frame violations. By decomposing malicious captions into visual conditions and temporal instructions, and by employing controlled latent perturbations and template rewriting, TempJail achieves a 23.3 % higher attack success rate than prior methods on several commercial models.
By Qi Lu, Zehui Guo, David Yuanda Gan, Zijing Li, Hengda Zhang, Weijun Xu, Qiankun Zhang