Papers for

surveillance system operators

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Spectral features detect attacks on image super-resolution models

Detection of Adversarial Attacks on Super-Resolvers Using Spectral Features

Abstract: The integration of deep learning models into image preprocessing pipelines such as super-resolution introduces a largely unexplored attack vector for adversaries targeting downstream tasks. To ensure trustworthiness of critical imaging pipelines, we must be able to detect adversarial behavior within preprocessing models. In this paper, we propose a spectral-based detection method for identifying adversarial attacks embedded in super-resolution model weights. More specifically, we use the radially-averaged power spectral density as a discriminative feature to train an extreme gradient boosting (XGBoost) detector, demonstrating detectability of model-level threats in super-resolution networks. We further benchmark our detector against magnitude- and phase-based Fourier spectrum detectors, evaluating each method across a range of training and cross-architecture scenarios. Our proposed detector out-performs the comparison detectors in most of these scenarios and indicates that high-frequency features are most informative for detecting AdvSR attacks across SR architectures.

Mon 28 SeptComputer Vision and Pattern Recognition
The gist
Image super-resolution models can be secretly manipulated by hackers to trick later processing steps. The authors show a way to spot these attacks by looking at patterns in the frequencies of the model's internal weights. They use a special kind of analysis called radially-averaged power spectral density and train a machine learning detector to recognize when a model has been tampered with. Their approach works better than other similar methods in most tests, especially by focusing on high-frequency details in the model.
Open → 2609.35022v1

Adversarial attacks cause identity leaks in face de-identification systems

Adversarial Attacks and Identity Leakage in De-Identification Systems: An Empirical Study

Abstract: In this paper, we investigate the impact of adversarial attacks on identity encoders within a realistic de-identification framework. Our experiments show that the transferability of attacks transfers from an external surrogate model to the system model (e.g., CosFace to ArcFace) allows the adversary to cause identity information to leak in a sufficiently sensitive face recognition system. We present experimental evidence and propose strategies to mitigate this vulnerability. Specifically, we show how fine-tuning on adversarial examples helps to mitigate this effect for distortion-based attacks (i.e., snow, fog, etc.), while a simple low-pass filter can attenuate the effect of adversarial noise without affecting the de-identified images. Our mitigation results in a de-identification system that preserves its functionality while being significantly more robust to adversarial noise.

Tue 22 SeptComputer Vision and Pattern Recognition
The gist
Facial recognition systems that try to hide a person’s identity can still accidentally reveal it if they face subtle, tricky changes called adversarial attacks. The authors show that attacks made using one system can also fool another, exposing private identity details. They found ways to reduce this risk by training the system to resist these attacks and by filtering out harmful noise without messing up the anonymized images. This makes face de-identification safer without losing its purpose.
Open → 2609.27022v1

Image restoration improves using instructions from degraded images

ImIR: Image-Instruction Tuning for All-in-One Image Restoration

Abstract: Degradations vary widely across images, so a practical restoration system has to handle many degradation types with one model. A recent and effective recipe adapts a large pretrained image-editing model to restoration using a small low-rank adapter with a text prompt. We replace that prompt with an instruction derived from the degraded image itself. The image reaches the editor through two paths: its structure comes from the model's VAE, and its semantic instruction comes from a lightweight token mapper that shifts the degraded image's vision-language embedding toward the embedding a clean image would produce. Because the instruction is a continuous vector, scaling it yields a family of valid restorations for tasks whose target is not unique, such as low-light enhancement. We adapt one Qwen-Image-Edit model to six tasks with a single adapter trained in about three hours on one GPU. The image instruction outperforms text conditioning under a matched comparison, and it supports task agnostic restoration without a degradation label, which the text variant does not.

Mon 21 SeptComputer Vision and Pattern Recognition
The gist
Images often come with different kinds of damage, so fixing all types with one method is tricky. The authors improved an existing image-editing model by teaching it to understand instructions derived from the damaged image itself, rather than relying on text prompts. This helps the model restore images better and handle multiple repair tasks with a single setup. They showed this method works well for things like making dark images brighter and fixing other common problems.
Open → 2609.25267v1

Collaborative perception improves model adaptation in self driving

Learning from Distributed Eyes: Leveraging Collaborative Perception for Automated Model Adaptation

Abstract: In autonomous driving, perception models often struggle to generalize to new environments due to domain shifts. While unsupervised model adaptation offers a feasible solution without labor-intensive manual labeling, existing methods that rely solely on the ego-vehicle's data often lead to inferior pseudo-labeling performance. To address this critical issue, we propose LDE, Learning from Distributed ``Eyes", a novel framework that transforms collaborative perception (CP) into a source of high-quality supervision for model adaptation. This pseudo-labeling approach is hyperparameter-insensitive and relatively reliable, assuming CP often outperforms single-agent's perception. However, naively implementing this approach encounters (1) the communication bottleneck of sharing rich features under time and bandwidth constraints, (2) the view discrepancy between the CP view and the learner's Field of View (FoV), and (3) the unreliability even in CP-generated labels. To address these issues, we design an adaptation-oriented feature sharing mechanism that selectively transmits the most critical information for adaptation, an FoV filtering method that meticulously eliminates mismatched labels, and a curriculum learning strategy to progressively exploit pseudo labels. Extensive experiments on 3D object detection tasks demonstrate that LDE consistently outperforms both the pre-trained models and state-of-the-art unsupervised adaptation methods.

Wed 16 SeptComputer Vision and Pattern RecognitionMachine Learning
The gist
When self-driving cars move to new places, their computer vision systems often make mistakes because they haven't seen those environments before. The authors present a way to improve these systems by letting multiple cars share information and learn from each other's views, which usually gives better clues than just one car alone. They also design smart methods to share only the most important data, avoid confusing information when views don't match, and gradually use these shared clues to update the model. Their tests show this approach works better than previous techniques that only use data from one car.
Open → 2609.18511v1