{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-examples-for-semantic","title":"Adversarial Examples for Semantic Segmentation and Object Detection","arxiv_id":"1703.08603","date":"2017-03-24","proceeding":"ICCV 2017 10","authors":["Cihang Xie","Jian-Yu Wang","Zhishuai Zhang","Yuyin Zhou","Lingxi Xie","Alan Yuille"],"abstract":"It has been well demonstrated that adversarial examples, i.e., natural images\nwith visually imperceptible perturbations added, generally exist for deep\nnetworks to fail on image classification. In this paper, we extend adversarial\nexamples to semantic segmentation and object detection which are much more\ndifficult. Our observation is that both segmentation and detection are based on\nclassifying multiple targets on an image (e.g., the basic target is a pixel or\na receptive field in segmentation, and an object proposal in detection), which\ninspires us to optimize a loss function over a set of pixels/proposals for\ngenerating adversarial perturbations. Based on this idea, we propose a novel\nalgorithm named Dense Adversary Generation (DAG), which generates a large\nfamily of adversarial examples, and applies to a wide range of state-of-the-art\ndeep networks for segmentation and detection. We also find that the adversarial\nperturbations can be transferred across networks with different training data,\nbased on different architectures, and even for different recognition tasks. In\nparticular, the transferability across networks with the same architecture is\nmore significant than in other cases. Besides, summing up heterogeneous\nperturbations often leads to better transfer performance, which provides an\neffective method of black-box adversarial attack.","url_abs":"http://arxiv.org/abs/1703.08603v3","url_pdf":"http://arxiv.org/pdf/1703.08603v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-examples-for-semantic","repo_url":"https://github.com/cihangxie/DAG","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok","spdx":"MIT"}},{"paper_slug":"adversarial-examples-for-semantic","repo_url":"https://github.com/yizhe-ang/detectron2-1","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"object","task_name":"Object"},{"task_slug":"object-detection","task_name":"Object Detection"},{"task_slug":"segmentation","task_name":"Segmentation"},{"task_slug":"semantic-segmentation","task_name":"Semantic Segmentation"},{"task_slug":"image-classification","task_name":"image-classification"},{"task_slug":"object-detection-1","task_name":"object-detection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1703.08603","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1703.08603"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/yizhe-ang/detectron2-1","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/cihangxie/DAG","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"ran_draft_wrong":1},"by_repo_kind":{"listed":{"samples":1,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"7ac7d78c168ae77b","entry":"load_yaml","repo":"yizhe-ang/detectron2-1","repo_kind":"listed","path":"train_net.py","file_url":"https://github.com/yizhe-ang/detectron2-1/blob/HEAD/train_net.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"7ac7d78c168ae77b"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}