AdvNet is a dataset of traffic signs images. Specifically, it includes adversarial traffic sign images (i.e., pictures of traffic signs with stickers on their surface) that can fool state-of-the art neural network-based perception systems and clean traffic sign images without any stickers on them.

The physically attacked traffic signs have been generated using the attack algorithm presented in the following work:

Eykholt, Kevin, et al. "Robust physical-world attacks on deep learning visual classification." Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. 2018.

If you use AdvNet, please cite the following paper:

Y. Kantaros, T. Carpenter, K. Sridhar, I. Lee, J. Weimer: `Real-Time Detectors for Adversarial Digital and Physical Inputs to Perception Systems', 12th ACM/IEEE International Conference on Cyber-Physical Systems (ICCPS), 2021