| CPC G06V 10/751 (2022.01) [B60W 60/00188 (2020.02); G06F 18/214 (2023.01); G06F 18/24 (2023.01); G06N 3/08 (2013.01); G06V 10/764 (2022.01); G06V 10/7715 (2022.01); G06V 10/774 (2022.01); G06V 10/82 (2022.01); B60W 2420/403 (2013.01)] | 18 Claims |

|
1. An image classification (IC) computing system for defending against physically realizable attacks, the IC computing system comprising at least one processor in communication with at least one memory device, wherein the at least one processor is programmed to:
retrieve, from the at least one memory device, a training dataset of one or more input images, each input image including a real-world object to be identified;
generate at least one adversarial image from a selected image from the training dataset of one or more input images by:
selecting a location on the selected image; and
generating adversarial noise inside a predetermined shape positioned at the selected location using projected gradient descent (PGD), wherein the predetermined shape with the generated adversarial noise occludes a portion of the real-world object to be identified;
train a classify images classifier to by identifying the real-world object in images, wherein the classifier is trained using the training dataset and the generated at least one adversarial image; and
store the trained classifier in the at least one memory device.
|