Generating adversarial patches against YOLOv2

Supplementary material of our paper to be presented on the CVPR Workshop: CVCOPS (

Simen Thys, Wiebe Van Ranst, and Toon Goedemé. "Fooling automated surveillance cameras: adversarial patches to attack person detection."


Atalay Deveci says:

For military use, it's more convenient to use thermal, depth or infrared dataset to train the detector. I guess they will be harder to fool. says:

Rodrigo Benenson says:

I would suggest a second version of this video where person 2 holds a random poster (e.g. favourite CD album cover) of same size as the adversarial patch; to show that it is not the "hips occlusion by colourful square" that is not throwing out the detector (but instead, the crafted adversarial attack).

Nationsorg Asscociation says:

beanNronin says:

I'm curious to see the patch moved horizontally and vertically within the (potential) human frame, not just held in the middle.

Maxime Tournadre says:

Amazing, the paper was great too

the paper:

Денис Рыбальченко says:

It works only for YOLO detector. I try SSD detector, it founds all persons.

This is important because if such object detection system is used in autonomous military systems, then the enemies can easily fool them with such techniques.

