提出梯度演化多形态攻击,提升红外、可见光等跨模态攻击迁移性。
Cross-Modality Attack Boosted by Gradient-Evolutionary Multiform Optimization
- 分层优化:先用梯度学模态内通用扰动,再用进化算法找跨模态共享扰动。
- 在多个异构数据集上验证,新方法攻击迁移率显著高于现有技术。
- 适用于研究跨模态系统安全漏洞的学者,尤其关注多传感器防御。
近年来,尽管对抗攻击研究进展显著,但红外、热成像与可见光图像间跨模态攻击的迁移性问题仍被忽视。这些由不同硬件采集的异构图像模态在实际应用中广泛存在,模态间的巨大差异严重制约了攻击的迁移能力。本文提出一种新型跨模态对抗攻击策略——多形态攻击(Multiform Attack),设计基于梯度演化的双层优化框架,实现模态间高效扰动传递。第一层利用图像梯度学习各模态内的通用扰动,第二层通过进化算法进行二次优化,搜索具备跨模态迁移性的共享扰动。在多个异构数据集上的大量实验表明,该方法在攻击迁移性和鲁棒性方面均优于现有技术。本工作不仅提升了跨模态对抗攻击的迁移能力,也为理解多模态系统中的安全漏洞提供了新视角。
原文摘要 · Abstract (English)
In recent years, despite significant advancements in adversarial attack research, the security challenges in cross-modal scenarios, such as the transferability of adversarial attacks between infrared, thermal, and RGB images, have been overlooked. These heterogeneous image modalities collected by different hardware devices are widely prevalent in practical applications, and the substantial differences between modalities pose significant challenges to attack transferability. In this work, we explore a novel cross-modal adversarial attack strategy, termed multiform attack. We propose a dual-layer optimization framework based on gradient-evolution, facilitating efficient perturbation transfer between modalities. In the first layer of optimization, the framework utilizes image gradients to learn universal perturbations within each modality and employs evolutionary algorithms to search for shared perturbations with transferability across different modalities through secondary optimization. Through extensive testing on multiple heterogeneous datasets, we demonstrate the superiority and robustness of Multiform Attack compared to existing techniques. This work not only enhances the transferability of cross-modal adversarial attacks but also provides a new perspective for understanding security vulnerabilities in cross-modal systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。