b09af659784ca5d4.tex
1: \begin{abstract}
2: It has been widely substantiated that deep neural networks (DNNs) are susceptible and vulnerable to adversarial perturbations.
3: Existing studies mainly focus on performing attacks by corrupting targeted objects (physical attack) or images (digital attack), which is intuitively acceptable and understandable in terms of the attack's effectiveness.
4: In contrast, our focus lies in conducting background adversarial attacks in both digital and physical domains, without causing any disruptions to the targeted objects themselves.
5: Specifically, an effective background adversarial attack framework is proposed to attack anything, by which the attack efficacy generalizes well between diverse objects, models, and tasks.
6: Technically, we approach the background adversarial attack as an iterative optimization problem, analogous to the process of DNN learning.
7: Besides, we offer a theoretical demonstration of its convergence under a set of mild but sufficient conditions.
8: To strengthen the attack efficacy and transferability, we propose a new ensemble strategy tailored for adversarial perturbations and introduce an improved smooth constraint for the seamless connection of integrated perturbations.
9: We conduct comprehensive and rigorous experiments in both digital and physical domains across various objects, models, and tasks, demonstrating the effectiveness of attacking anything of the proposed method.
10: The findings of this research substantiate the significant discrepancy between human and machine vision on the value of background variations, which play a far more critical role than previously recognized, necessitating a reevaluation of the robustness and reliability of DNNs. 
11: The code will be publicly available at \url{https://github.com/JiaweiLian/Attack_Anything}.
12: \end{abstract}
13: