Skip to content
Conference

A training-free threshold-based method for adversarial patch detection on RISC-V edge vision processors

Aug 2026 · International Conference on Industrial IoT, Big Data, and Smart Cities · Vol 14325, pp. 143250L - 143250L-7 · 0 citations
Engineering

Abstract

RISC-V chip based SoCs are increasingly used in many perception applications due to edge deployment of solutions for camera sensor in lightweight scene. In these scenarios, low latency, power consumption and on-chip memory are more important for decreasing the model capacity weight. Meanwhile, in real visual application, a small region can bring in strong local activation in shallow neural network so that mislead the following remaining inference pipeline. For edge devices that cannot afford a large auxiliary defense network, a compact input-side screening mechanism is therefore desirable. This paper presents a clean-calibrated front-end detector for adversarial patch screening on RISC-V edge-vision processors. The detector reads the activation tensor from a shallow convolutional layer and compresses the channel responses into a two-dimensional attention map. The largest spatial response in this map is used as a peak indicator, since patch attacks tend to create a local region whose aggregated activation is much stronger than the surrounding area. The threshold is selected from clean calibration samples by using an empirical confidence quantile. As a result, calibration does not require adversarial examples and does not modify the target inference model. The online computation is restricted to channel accumulation, constant scaling, spatial maximum reduction, and one threshold comparison. These operations can execute procedures that after spatial position is adopted to update the maximum value, the attention value is discarded immediately. A fixed point which is more suitable for the system can further replace division by the different channels with multiplication and shift. Experiment results reveal that the VGG-16 Conv2 can maintains detection rate of more than 97.36 % according to the test of threat models. And Conv1 remains available but has a worse result with hardware budgets. The MobileNetV2 used in the training shows Unsatisfactory result, which suggest the layer selection and threshold should be optimized for practical deployment.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.