Why doesn't a printed patch that defeats a store camera's model need to be imperceptible?
answer
- ask what a defender could compare the frame to
- the constraint came from a different threat model
- no original scene exists to diff against
- magnitude is free; area is not
- bold structure is what survives a lens
basics
~20 sImperceptibility only matters when someone can compare the input to an original. A camera sees a real scene, with no original to compare against, so the real limits are covered area, the angles it must work from, and human inspection.
solid answer
~50 sThe imperceptibility rule comes from the digital threat model, where the attacker edits a file that already exists, so every change is measured against that original and a tiny perturbation radius keeps it invisible. Nothing like that exists in front of a camera: the model sees whatever light reached the sensor, and no clean version of the scene is ever available to diff against. So magnitude is free — the attacker can print bold, saturated, high-contrast structure, which is also what survives distance, printing and re-sampling. What replaces the radius is a geometric budget: how much of the object's surface may be covered, from which standoff distances and approach angles it has to hold, and whether it looks odd enough that a person pulls the item aside. Those are the numbers a physical evasion result has to quote; a perturbation radius is meaningless for it.
go deeper
Be ready to say where the imperceptibility rule comes from and why it does not apply in front of a camera. Naming area, viewing angle and human inspection as the real limits is enough at this level.
You are expected to explain the mechanics: a norm and a radius are a stated threat model, a scene has no reference input, and high-contrast structure is what survives printing and distance in the first place.
Show the judgment: decide whether a visible artefact is a real risk for a given deployment by asking who inspects the object, what area it covers, and over which approaches it holds — not by asking whether it looks obvious in a photograph.
Own the framing question of whether your deployment faces an adversary who can place objects at all. If nobody can reach the scene, this whole class is theoretical; if they can, imperceptibility was never the control you were relying on.
## The rule you are being asked about Most people meet adversarial examples in their digital form: an attacker takes an existing input, adds a small structured change, and the model's answer flips while a human sees nothing. The "small" there is not a vibe — it is a stated constraint, a norm plus a radius (every pixel may move at most a little, or the total change may have at most so much energy). That pair *is* the threat model, and imperceptibility is a **consequence** of choosing a tiny radius, not a law of the field. Candidates then carry the rule forward to a printed artefact placed in a scene and conclude that a visible patch is a broken attack. That is the wrong answer, and knowing why is the whole point of this question. ## Why the rule does not transfer to a camera The imperceptibility constraint is only meaningful because a **reference exists**. In the digital setting there is an original file: a defender, a reviewer or a hash can in principle compare the submitted input to it, so a large change is a change somebody could point at. In front of a lens there is no reference. A fixed overhead camera in a checkout lane photographs whatever is in the lane. There is no "unmodified" version of that moment to compare the frame against — the frame *is* the scene. An attacker who prints something and puts it on an item has not edited an input; they have arranged reality. So the quantity the digital threat model bounds is not just unbounded here, it is undefined. A second reason pushes the same way. A digital perturbation is a fragile, high-frequency pattern; sending it through optics, distance, printing and compression destroys most of it. Structure that survives capture has to be **large and high-contrast**, which is the opposite of imperceptible. The attacker is not choosing to be visible out of laziness — visibility is what buys survival through the capture pipeline. ## What the budget becomes The constraints are still real; they are just different in kind: - **Area.** What fraction of the object's visible surface the artefact may cover. This is the closest thing to a radius, and it is the number a physical result must quote. Cover the whole item and you have not evaded the model, you have replaced the object. - **Viewpoint.** The range of standoff distances and approach angles over which it must keep working. A result at one pose is a result at one pose. - **Looking unremarkable.** A *social* constraint, not a metric one: staff, other shoppers, or a reviewer looking at the footage should have no reason to single the item out. A garish label on packaging can pass where the same thing on a face would not. Notice that only the third is about being unnoticed at all, and it is about being unnoticed by **people**, under whatever inspection actually happens, not about staying within a distance bound. ## What visibility buys, and what it costs Trading imperceptibility away is a trade, not a free win. The attacker gains magnitude, and with it robustness: bold structure still reads at three metres and under bad lighting. They pay for it in every other column — the artefact has to hold across poses they do not fully control, it can be seen and removed, and the honest success rate is far below what a simulated version of the same attack reports. ## Directions to keep straight - A visible patch is **not** evidence of a weak attack; imperceptibility was never the goal outside the digital threat model. - A perturbation radius quoted for a physical artefact is a category error, not a strict number. - One photograph of a successful patch proves it worked **at that pose, that distance, that lighting** — not that the deployment is evadable. - "A person would notice" is a claim about the review that actually happens. If nobody inspects the packaging, it is not a control. ## How to answer in a loop Say where imperceptibility comes from (a digital threat model with a reference input), say why the reference is missing in a scene, then name the three things that actually bound the attacker: area, viewpoint range, and passing human inspection. That answer shows you understand the constraint rather than reciting it.
- Does that make physical evasion easier than the digital kind?No — it is a trade. The attacker gives up imperceptibility and gains magnitude, but takes on constraints the digital attacker never had: the artefact must hold across distances and angles they only partly control, it survives printing and optics imperfectly, and it can simply be seen and removed. Honest physical success rates land far below the simulated equivalent.
- Is there any physical setting where being unnoticed still constrains the attacker?Yes, but it becomes a social constraint rather than a metric one. If a person inspects the object — staff handling packaging, a guard watching footage, a reviewer sampling frames — the artefact has to look unremarkable in that specific inspection. That is a question about who looks and how hard, not about a distance bound.
- If magnitude is unbounded, why not cover the whole object?Because area is the budget that actually bites. Covering the object entirely is not evasion of the model, it is presenting a different object, and it fails the plausibility constraint immediately. A result is only interesting when the covered fraction is small enough that the item still reads as itself to a person.
Editing a photo is forgery against a known original; putting a printed card on a shelf is set dressing. Only the forger has to worry about the change being visible next to the real thing.
saying these in an interview costs you the question
- Says a patch fails as an attack because it is visible
- Quotes a perturbation radius for a printed physical artefact
- Assumes tiny digital noise survives optics and distance
- Treats one successful photograph as general evasion
- Believes the defender compares each frame to a clean original