Physical Countermeasures
Physical countermeasures are real-world objects that attackers use to trick AI systems. Just like a magician uses props to create an illusion, an attacker might use specific stickers, clothing, or lights to confuse an AI's sensors or its ability to understand what it is seeing.
Physical countermeasures are tangible artifacts or environmental modifications deployed by an adversary to manipulate the input data perceived by an AI system. These include adversarial patches, such as patterns on clothing or stickers, or hardware-based interference like lasers or light sources designed to degrade sensor performance or induce misclassification.
Physical countermeasures refer to the acquisition or manufacture of physical-domain adversarial perturbations or environmental interference tools intended to compromise the integrity of an AI model's input pipeline. These countermeasures function by introducing systematic noise or adversarial features into the physical environment, thereby exploiting the discrepancy between the model's training distribution and the sensor-captured data, effectively inducing targeted misclassification or denial-of-service at the perception layer.