arXiv:2409.00029cs.CVcs.CR2024-09被引 3

无需干扰目标,通过背景扰动即可攻击任意深度模型。

Attack Anything: Blind DNNs via Universal Background Adversarial Attack

  • 将背景对抗攻击建模为迭代优化问题,模拟DNN学习过程。
  • 在数字与物理域均实现跨对象、跨模型、跨任务的强迁移性攻击。
  • 揭示背景变化对机器视觉的决定性影响,警示模型脆弱性。

深度神经网络(DNN)易受对抗扰动的影响已得到广泛证实。现有研究主要聚焦于对目标物体(物理攻击)或图像(数字攻击)进行扰动,其攻击效果直观且易于理解。本文关注的是在数字和物理域中不干扰目标本身,仅通过背景进行对抗攻击,实现‘攻击一切’的目标。我们提出一种有效的背景对抗攻击框架,使攻击效果在不同物体、模型和任务间具有良好的泛化能力。技术上,我们将背景对抗攻击视为一个迭代优化问题,类比DNN的学习过程,并在一组温和但充分的条件下提供收敛性理论证明。为增强攻击效力与迁移性,我们设计了针对对抗扰动的新集成策略,并引入改进的平滑约束以实现扰动的无缝融合。我们在数字与物理域中对多种物体、模型和任务进行了全面严格的实验,验证了该方法的有效性。研究结果表明,人类与机器视觉对背景变化的价值认知存在显著差异,背景因素的作用远超以往认识,亟需重新评估DNN的鲁棒性与可靠性。代码将公开于 https://github.com/JiaweiLian/Attack_Anything。

原文摘要 · Abstract (English)

It has been widely substantiated that deep neural networks (DNNs) are susceptible and vulnerable to adversarial perturbations. Existing studies mainly focus on performing attacks by corrupting targeted objects (physical attack) or images (digital attack), which is intuitively acceptable and understandable in terms of the attack's effectiveness. In contrast, our focus lies in conducting background adversarial attacks in both digital and physical domains, without causing any disruptions to the targeted objects themselves. Specifically, an effective background adversarial attack framework is proposed to attack anything, by which the attack efficacy generalizes well between diverse objects, models, and tasks. Technically, we approach the background adversarial attack as an iterative optimization problem, analogous to the process of DNN learning. Besides, we offer a theoretical demonstration of its convergence under a set of mild but sufficient conditions. To strengthen the attack efficacy and transferability, we propose a new ensemble strategy tailored for adversarial perturbations and introduce an improved smooth constraint for the seamless connection of integrated perturbations. We conduct comprehensive and rigorous experiments in both digital and physical domains across various objects, models, and tasks, demonstrating the effectiveness of attacking anything of the proposed method. The findings of this research substantiate the significant discrepancy between human and machine vision on the value of background variations, which play a far more critical role than previously recognized, necessitating a reevaluation of the robustness and reliability of DNNs. The code will be publicly available at https://github.com/JiaweiLian/Attack_Anything

对抗攻击背景扰动DNN脆弱性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。