让对抗补丁自然融入环境,提升物理攻击隐蔽性
Prompt-Guided Environmentally Consistent Adversarial Patch
- 用扩散模型生成贴合环境的对抗补丁
- 攻击成功率更高,且视觉上更难被发现
- 适合研究物理世界对抗攻击的学者
物理世界中的对抗攻击对基于视觉的系统(如人脸识别和自动驾驶)构成重大威胁。现有对抗补丁方法多关注攻击效果,但生成的补丁常易被人眼察觉,难以实现环境一致性,即与背景自然融合。本文提出一种新方法——提示引导的环境一致对抗补丁(PG-ECAP),通过扩散模型生成既具环境一致性又具备强攻击性的补丁。引入提示对齐损失和潜在空间对齐损失,确保补丁在保持对抗性的同时自然融入场景。数字与物理实验均表明,PG-ECAP在攻击成功率和环境一致性方面优于现有方法。
原文摘要 · Abstract (English)
Adversarial attacks in the physical world pose a significant threat to the security of vision-based systems, such as facial recognition and autonomous driving. Existing adversarial patch methods primarily focus on improving attack performance, but they often produce patches that are easily detectable by humans and struggle to achieve environmental consistency, i.e., blending patches into the environment. This paper introduces a novel approach for generating adversarial patches, which addresses both the visual naturalness and environmental consistency of the patches. We propose Prompt-Guided Environmentally Consistent Adversarial Patch (PG-ECAP), a method that aligns the patch with the environment to ensure seamless integration into the environment. The approach leverages diffusion models to generate patches that are both environmental consistency and effective in evading detection. To further enhance the naturalness and consistency, we introduce two alignment losses: Prompt Alignment Loss and Latent Space Alignment Loss, ensuring that the generated patch maintains its adversarial properties while fitting naturally within its environment. Extensive experiments in both digital and physical domains demonstrate that PG-ECAP outperforms existing methods in attack success rate and environmental consistency.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。