arXiv:2410.14089cs.CV2024-10被引 1

提出高效多模态攻击框架,提升攻击精度与速度。

MMAD-Purify: A Precision-Optimized Framework for Efficient and Scalable Multi-Modal Attacks

  • 利用蒸馏扩散模型骨干+优化噪声预测器,非迭代生成攻击
  • 攻击成功率高,计算成本降低,生成高质量对抗样本
  • 适合研究模型鲁棒性或防御机制的开发者使用

神经网络在众多任务中表现卓越,但对对抗扰动仍敏感,尤其在安全关键场景中风险显著。随着多模态发展,扩散模型被广泛用于图像编辑、修复和超分辨率等任务,但其抗攻击能力研究不足。传统基于梯度的攻击和扩散模型方法因迭代特性导致计算效率低、难以扩展。为此,本文提出一种创新框架,利用扩散模型的蒸馏骨干结构,并引入精度优化的噪声预测器,实现非迭代式高效攻击。该方法在保持高攻击成功率的同时大幅降低计算开销,生成高保真对抗样本。实验表明,本框架在跨模型迁移性和对抗净化防御下均表现优异,优于现有基于梯度的攻击方法,在有效性和效率上全面领先。

原文摘要 · Abstract (English)

Neural networks have achieved remarkable performance across a wide range of tasks, yet they remain susceptible to adversarial perturbations, which pose significant risks in safety-critical applications. With the rise of multimodality, diffusion models have emerged as powerful tools not only for generative tasks but also for various applications such as image editing, inpainting, and super-resolution. However, these models still lack robustness due to limited research on attacking them to enhance their resilience. Traditional attack techniques, such as gradient-based adversarial attacks and diffusion model-based methods, are hindered by computational inefficiencies and scalability issues due to their iterative nature. To address these challenges, we introduce an innovative framework that leverages the distilled backbone of diffusion models and incorporates a precision-optimized noise predictor to enhance the effectiveness of our attack framework. This approach not only enhances the attack's potency but also significantly reduces computational costs. Our framework provides a cutting-edge solution for multi-modal adversarial attacks, ensuring reduced latency and the generation of high-fidelity adversarial examples with superior success rates. Furthermore, we demonstrate that our framework achieves outstanding transferability and robustness against purification defenses, outperforming existing gradient-based attack models in both effectiveness and efficiency.

多模态攻击扩散模型对抗样本高效攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。