Adversarial Patch and Camouflage Attacks on Aerial Object Detection: A Geometry-Aware Review
Uncrewed aerial vehicles increasingly rely on on-board deep object detectors for applications such as surveillance, delivery, agriculture, and traffic monitoring. The vulnerability of these detectors to adversarial patches has therefore become a practical safety concern. Research on adversarial patch and camouflage attacks against aerial object detection has expanded rapidly, yet existing reviews consider aerial systems only as one application domain among many and do not examine the unique geometric conditions of aerial imagery. This review surveys adversarial patch and camouflage attacks, together with the corresponding defense mechanisms, for aerial, UAV, and remote sensing object detection. The literature is organized using a taxonomy based on two dimensions: the physical medium of the perturbation and the application domain it targets. Existing methods are then compared with respect to physical robustness, evaluation datasets and detectors, threat models, and their treatment of viewpoint variation. A recurring observation across the literature is that viewpoint variation is represented primarily through object scale, while explicit modeling of viewing geometry remains limited. This trend is closely linked to the characteristics of the aerial datasets used for evaluation, which typically provide realistic imagery but limited geometric information. Consequently, questions concerning viewpoint-dependent placement, degradation, and naturalness remain only partially explored. The review concludes by identifying the major research gaps, future directions, and deployment challenges that are likely to shape the next generation of aerial adversarial attack and defense research.
Authors
- Asanka G. Perera (ORCID: https://orcid.org/0000-0003-4021-3943)
- K. T. Y. Mahima (ORCID: https://orcid.org/0000-0003-4975-9408)
- Sandesh Shrestha (ORCID: https://orcid.org/0000-0001-5298-4468)
Institutions
- University of Southern Queensland (AU)
- University of Canberra (AU)
- UNSW Sydney (AU)
- Asian Institute of Technology (TH)
Publication Details
- Journal
- Sensors
- Published
- 2026-09-24
- DOI
- https://doi.org/10.3390/s26196057
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00