系统梳理十年视觉任务对抗攻击,贯通传统与大模型时代攻击范式
Adversarial Attacks of Vision Tasks in the Past 10 Years: A Survey
- 构建统一视角分析对抗性、迁移性与泛化性本质
- 提出动机驱动的攻击分类框架,涵盖传统与大模型攻击
- 融合对比传统与LVLM攻击,指导未来鲁棒性研究
随着大型视觉语言模型(LVLMs)的兴起,新型攻击向量如认知偏见、提示注入和越狱攻击不断涌现。理解这些攻击有助于提升系统鲁棒性并揭示神经网络内在机制。然而,现有综述多聚焦于攻击分类,缺乏对对抗性、迁移性与泛化性的统一洞察,也缺少详细的评估框架、动机驱动的攻击归类,以及对传统攻击与LVLM攻击的整合视角。本文填补上述空白,全面总结传统与LVLM对抗攻击,强调其关联与差异,并为未来研究提供可操作的洞见。
原文摘要 · Abstract (English)
With the advent of Large Vision-Language Models (LVLMs), new attack vectors, such as cognitive bias, prompt injection, and jailbreaking, have emerged. Understanding these attacks promotes system robustness improvement and neural networks demystification. However, existing surveys often target attack taxonomy and lack in-depth analysis like 1) unified insights into adversariality, transferability, and generalization; 2) detailed evaluations framework; 3) motivation-driven attack categorizations; and 4) an integrated perspective on both traditional and LVLM attacks. This article addresses these gaps by offering a thorough summary of traditional and LVLM adversarial attacks, emphasizing their connections and distinctions, and providing actionable insights for future research.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。