Queen's University Belfast

Centre for Secure Information Technologies (CSIT)


Senior Lecturer (Associate Prof.)

Email: i.alouani@qub.ac.uk


- We establish that adversarial patches have inherently high entropy distribution compared to benign images (including naturalistic patches)

- We leverage this observation to detect, localise and neutralise adversarial patches, recovering initial models performance

- We proposed a new adaptive attack that optimises the patch generation with an entropy budget; The generated patches evade detection BUT are no longer adversarial ... This lose-lose game is in favour of the defender.

A demo is available on Youtube: https://www.youtube.com/watch?v=8B5Mn9t7zc8&t=2s&ab_channel=IhsenAlouani