Papers › Natural Adversarial Objects

Natural Adversarial Objects

7 Nov 2021arXiv:2111.04204archive 2025-07-28

Felix Lau, Nishant Subramani, Sasha Harrison, Aerin Kim, Elliot Branson, Rosanne Liu

Although state-of-the-art object detection methods have shown compelling performance, models often are not robust to adversarial attacks and out-of-distribution data. We introduce a new dataset, Natural Adversarial Objects (NAO), to evaluate the robustness of object detection models. NAO contains 7,934 images and 9,943 objects that are unmodified and representative of real-world scenarios, but cause state-of-the-art detection models to misclassify with high confidence. The mean average precision (mAP) of EfficientDet-D7 drops 74.5% when evaluated on NAO compared to the standard MSCOCO validation set. Moreover, by comparing a variety of object detection architectures, we find that better performance on MSCOCO validation set does not necessarily translate to better performance on NAO, suggesting that robustness cannot be simply achieved by training a more accurate model. We further investigate why examples in NAO are difficult to detect and classify. Experiments of shuffling image patches reveal that models are overly sensitive to local texture. Additionally, using integrated gradients and background replacement, we find that the detection model is reliant on pixel information within the bounding box, and insensitive to the background context when predicting class labels. NAO can be downloaded at https://drive.google.com/drive/folders/15P8sOWoJku6SSEiHLEts86ORfytGezi8.

PaperPDF

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

No code repository is listed for this paper in the archive or in Syntology's graph.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

ObjectObject Detectionobject-detection

Datasets

Introduced by this paper, per the archive.

NAO

Results from the paper archive 2025-07-28

TaskDatasetModelMetricValueRank at snapshotLeaderboardReport
Object Detection NAO Mask RCNN R50 mAP 15.2 #1 of 7 Archive leaderboard report
Object Detection NAO Mask RCNN R50 mAP w/o OOD 24.6 #1 of 7 Archive leaderboard report
Object Detection NAO Mask RCNN R50 mAR 43.8 #1 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D4 mAP 15.0 #2 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D4 mAP w/o OOD 29.6 #2 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D4 mAR 42.7 #2 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D7 mAP 13.6 #3 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D7 mAP w/o OOD 26.6 #3 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D7 mAR 40.8 #3 of 7 Archive leaderboard report
Object Detection NAO Faster RCNN mAP 13.5 #4 of 7 Archive leaderboard report
Object Detection NAO Faster RCNN mAP w/o OOD 22.8 #4 of 7 Archive leaderboard report
Object Detection NAO Faster RCNN mAR 41.4 #4 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D2 mAP 12.8 #5 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D2 mAP w/o OOD 25.4 #5 of 7 Archive leaderboard report
Object Detection NAO EfficientDet-D2 mAR 40.2 #5 of 7 Archive leaderboard report
Object Detection NAO RetinaNet-R50 mAP 11.1 #6 of 7 Archive leaderboard report
Object Detection NAO RetinaNet-R50 mAP w/o OOD 19.5 #6 of 7 Archive leaderboard report
Object Detection NAO RetinaNet-R50 mAR 37.2 #6 of 7 Archive leaderboard report
Object Detection NAO YOLOv3 mAP 10.0 #7 of 7 Archive leaderboard report
Object Detection NAO YOLOv3 mAP w/o OOD 17.5 #7 of 7 Archive leaderboard report
Object Detection NAO YOLOv3 mAR 28.4 #7 of 7 Archive leaderboard report

Ranks are positions in the archive's leaderboards as they stood at the 2025-07-28 snapshot. Results published since then are not among these rows, so a rank here is not a current standing.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections