Publication Date
Spring 2026
Degree Type
Master's Project
Degree Name
Master of Science in Computer Science (MSCS)
Department
Computer Science
First Advisor
Fabio Di Troia
Second Advisor
Thomas Austin
Third Advisor
Katerina Potika
Keywords
Adversarial Robustness, Stochastic Purification, Object Detection Models
Abstract
Machine learning algorithm advancements have brought forth advancements in adversarial perturbations that degrade performance. In many prior works, defense is done through training of classifier models, but without accounting for unseen attacks. This project proposes an extension to an adversarial patch noise based detection pipeline to explore the effectiveness of different noise perturbations as a defense and detection mechanism. Using 4 different types of noise of Gaussian, Salt & Pepper, Speckle, and Poisson, on both the clean and adversarial image, robustness is measured with IOU metrics (Standard, GIoU, DIoU, and CIoU). Additionally, 4 different types of IoU are used to measure disruption effectiveness. Experimental results demonstrate that Gaussian noise still remains as the highest accuracy rate with the standard IoU metric and highest in recall. Denoiser stands as a better defense when stricter, more accurate bounding boxes are needed. Ultimately, the study identifies the effectiveness of stochastic based defenses as a low overhead identifier for adversarial attacks, with denoisers being more suitable for recovery.
Recommended Citation
Zhen, Victor, "Evaluating Noise-Based Defenses Against Adversarial Attacks in Object Detection" (2026). Master's Projects. 1800.
DOI: https://doi.org/10.31979/etd.mxxb-kqvt
https://scholarworks.sjsu.edu/etd_projects/1800