attack input
A The algorithm for Moiré Attack (MA) Algorithm 1 Moiré Attack Input: clean image x; targeted label x; ground truth label y
It not only has high success rate, but seems more natural compared with common physical attacks in the perspective of the probability to catch people's attention. As mentioned in Section 3.1, moiré pattern can be a potential threat to DNNs. However, it hardly arouses humans' attention when it is inevitably generated through shooting on the LCD screens, It is also the exact precondition and motivation of the proposed MA. We strictly follow the same procedure in our simulation of moiré pattern. We find that the synthesis images are darker and distorted to some degree compared with the original ones.