Recently, deep networks have achieved impressive semantic segmentationperformance, in particular thanks to their use of larger contextualinformation. In this paper, we show that the resulting networks are sensitivenot only to global attacks, where perturbations affect the entire input image,but also to indirect local attacks where perturbations are confined to a smallimage region that does not overlap with the area that we aim to fool. To thisend, we introduce several indirect attack strategies, including adaptive localattacks, aiming to find the best image location to perturb, and universal localattacks. Furthermore, we propose attack detection techniques both for theglobal image level and to obtain a pixel-wise localization of the fooledregions. Our results are unsettling: Because they exploit a larger context,more accurate semantic segmentation networks are more sensitive to indirectlocal attacks.