Related Experiment Video
Updated: Aug 14, 2026

05:03
Direct Observation and Automated Measurement of Stomatal Responses to Pseudomonas syringae pv. tomato DC3000 in Arabidopsis thaliana
Published on: February 9, 2024
AgroPatch AutoStrike for adversarial patch attacks on plant disease detection models
Yuting Wu1, Mingxing Wang1, Xiu Jin1
1School of Information and Artificial Intelligence, Anhui Agricultural University, Hefei, Anhui 230036, China.
Iscience
|August 13, 2026
Summary
AgroPatch-AutoStrike (APA) effectively deceives vision transformers (ViTs) in plant disease detection using adversarial patches. This research highlights critical vulnerabilities in AI for agriculture, necessitating domain-specific robustness evaluations.
Area of Science:
- Agricultural AI
- Computer Vision
- Machine Learning Security
Background:
- Plant diseases pose significant threats to global food security and agricultural economies.
- Automated detection systems using artificial intelligence (AI), particularly vision transformers (ViTs), show promise but are susceptible to adversarial attacks.
- Existing adversarial patch attacks are not optimized for the unique characteristics of plant disease imagery.
Purpose of the Study:
- To introduce AgroPatch-AutoStrike (APA), a novel adversarial patch attack framework tailored for ViT-based plant disease detection.
- To evaluate the effectiveness of APA in compromising the performance of ViT models in agricultural applications.
- To underscore the need for domain-specific adversarial robustness testing in agricultural AI.
Main Methods:
- APA integrates the variance driven feature patch attack (VDFPA) for optimized patch placement.
- Adversarial focal loss (AFL) is employed to prioritize and emphasize challenging-to-attack categories.
- The framework was tested on a cassava leaf disease dataset using ViT models.
Main Results:
- APA significantly reduced the robust accuracy (RA) of most ViT models to near zero with minimal image perturbation (4 patches, 2% image coverage).
- APA demonstrated superior or comparable performance to existing methods like patch-fool and LaVAN in reducing RA.
- The attack achieved a 1-2% lower RA compared to other methods while maintaining similar inference times.
Conclusions:
- ViT-based plant disease detection models exhibit significant robustness gaps against targeted adversarial patch attacks.
- APA proves effective in demonstrating these vulnerabilities, even with limited adversarial perturbations.
- Domain-specific adversarial robustness evaluations are crucial for developing reliable AI systems in agriculture.
Related Concept Videos
Defenses Against Pathogens and Herbivores
Plants present a rich source of nutrients for many organisms, making it a target for herbivores and infectious agents. Plants, though lacking a proper immune system, have developed an array of constitutive and inducible defenses to fend off these attacks.
Introduction to Plant Diversity
From Water to Land