arXiv:2411.17936cs.CRcs.CV2024-11被引 3

精准打击特定任务,让其他任务毫发无损的对抗攻击方法

Stealthy Multi-Task Adversarial Attacks

  • 设计任务感知扰动,实现目标任务降级而其他任务不受影响
  • 在NYUv2和Cityscapes上成功攻击目标任务,非目标任务性能几乎不变
  • 自动调节损失权重,适合实际部署中对模型行为的精细控制

深度神经网络极易受到对抗扰动的影响,给现实系统带来严重安全风险。以往工作多聚焦于单任务攻击或同时降低所有任务性能,但实际场景更需要精确且隐蔽的攻击策略。为此,本文提出新型框架SMTA²,可选择性地降低目标任务性能,同时严格保持非目标任务的性能。该目标被建模为约束型多目标优化问题,通过设计任务感知的对抗扰动,在不损害非目标任务的前提下最大化目标任务的退化效果。为进一步提升实用性,引入自动化损失权重调节策略,动态平衡攻击与保护目标。在两个多任务基准数据集NYUv2和Cityscapes上的实验表明,SMTA²在未防御和对抗训练模型上均能有效攻击目标任务,同时保持非目标任务性能基本不变,首次建立了可实现隐蔽、选择性多任务攻击的系统性框架。

原文摘要 · Abstract (English)

Deep neural networks are highly vulnerable to adversarial perturbations, raising serious safety concerns in the real-world systems. While prior work mainly explores single-task attacks or jointly degrading all tasks in multi-task models, practical scenarios often demand more selective and stealthy attack strategies. To address this challenge, we propose Stealthy Multi-Task Adversarial Attack (SMTA$^{2}$), a novel framework that selectively degrades a targeted task while strictly preserving the performance of non-targeted tasks. We formulate this objective as a constrained multi-objective optimization problem and design task-aware adversarial perturbations that maximize degradation on the targeted task without causing collateral damage on non-targeted tasks. To enhance practicality, we further introduce an automated loss-weight tuning strategy that dynamically balances attack and preservation objectives. Experiments on two multi-task benchmarks NYUv2 and Cityscapes demonstrate that SMTA$^{2}$ achieves strong attack performance on targeted tasks while maintaining non-targeted tasks intact on both undefended and adversarially trained models, establishing the first systematic framework for stealthy and selective multi-task attack framework.

对抗攻击多任务学习隐蔽攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。