TL;DR: We propose the REAP (REalistic Adversarial Patch) benchmark for evaluating patch attacks and defenses on real images under real-world conditions. Built on top of the Mapillary Vistas dataset, our benchmark contains over 14,000 traffic signs. Each sign is augmented with geometric and lighting transformations for rendering a generated patch realistically onto the sign.
Authors: Nabeel Hingun*, Chawin Sitawarin*, Jerry Li, David Wagner