← Latest papers
💻 computer science

ColorFD: A Finite-Difference Guided Black-Box Physical Adversarial Attack for Remote Sensing Object Detection

This paper proposes ColorFD, a black-box physical adversarial attack method that utilizes Differential Evolution to optimize the placement and color of pure-color patches, guided by finite-difference localization and common-feature extraction, to effectively evade remote sensing object detectors in both digital and real-world scenarios.

Original authors: Tiannuo Guo, Guhang Qiu, Yuzhen Xie, Rui Feng, Ligang Li, Deliang Xiang

Published 2026-08-06
📖 3 min read☕ Coffee break read

Original authors: Tiannuo Guo, Guhang Qiu, Yuzhen Xie, Rui Feng, Ligang Li, Deliang Xiang

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where computers can "see" the sky, spotting airplanes, ships, or cars in satellite photos with incredible speed. This is the realm of artificial intelligence, specifically deep neural networks, which act like super-powered eyes for everything from self-driving cars to national defense. But here's the twist: these digital eyes are surprisingly fragile. Just like a magician can be fooled by a cleverly placed card, these AI systems can be tricked by tiny, almost invisible changes to an image. These tricks are called "adversarial attacks." While scientists have spent years figuring out how to fool these computers in the digital world (by hacking the image file itself), it's much harder to do it in the real world. You can't just "edit" a real airplane flying overhead; you have to physically stick something on it or place something nearby to confuse the camera. The big question is: Can we create a physical sticker or patch that is so effective it makes a high-tech detector completely blind to a target, even when the attacker doesn't know how the detector's brain works?

This is exactly what the paper "ColorFD" tackles. The researchers, working with the College of Information Science and Technology at Beijing University of Chemical Technology, have developed a new method to trick remote sensing object detectors (the AI eyes watching the sky) using simple, pure-color patches. Unlike previous attempts that tried to create complex, textured patterns that are hard to print or easy to spot, ColorFD uses a "black-box" approach. This means the attacker doesn't need to know the secret recipe (the internal code or math) of the AI they are trying to fool; they only need to see the final result (did it spot the plane or not?).

The team's main discovery is that by sticking a few small, solid-colored squares onto a target—like a jet or a plane—and carefully choosing their colors and positions, they can make the AI completely miss the object. They used a smart search strategy called "Differential Evolution," which is like a digital evolution lab where thousands of random patch combinations are tested, and the "fittest" (most confusing) ones are bred together to create better versions. To make this search faster and more effective, they added two clever guides: one that finds the "sensitive spots" on a specific object (like the wings or nose) by testing how the AI reacts to different colors, and another that uses general knowledge about where these sensitive spots usually are for a whole category of objects (like all jets) to skip the guesswork.

The results are quite striking. When they tested their method on popular AI detectors like YOLOv3u, YOLOv5u, and Faster R-CNN, ColorFD was significantly better at hiding objects than other black-box methods they compared it against. In fact, in some digital tests, it performed just as well as "white-box" attacks, where the attacker knows everything about the AI's inner workings. Perhaps most impressively, they took their digital designs, printed them out on colored paper, and stuck them on real alloy airplane models. When they photographed these models, the AI still failed to see them, proving that their digital trickery works in the real, physical world. The paper suggests that while this method is powerful, it isn't perfect; it works best under stable conditions and can struggle if the camera angle changes too much or if the AI has a specific two-stage architecture that hides its intermediate thinking steps. But overall, it shows that a few simple, colorful stickers can be surprisingly powerful weapons against the "eyes" of modern AI.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →