arXiv:2412.03908cs.CVcs.CR2024-12被引 1

提升对抗性数据投毒在不同视角下的攻击效果

Generalizable Targeted Data Poisoning against Varying Physical Objects

  • 同时优化梯度方向与大小,增强攻击泛化能力
  • 在多视角汽车图像上成功率提升19.49%
  • 适用于真实场景中变化多端的目标物体

定向数据投毒(TDP)旨在通过扰动少量训练数据,使模型在特定测试目标上的预测失效。现有研究多基于理想化威胁模型,即投毒与推理阶段使用完全相同的图像样本。然而现实中,目标物体常因视角、背景、光照等物理条件变化而呈现多样形态。本文首次研究TDP在复杂物理条件下的泛化能力。我们发现,仅优化梯度方向的现有方法泛化能力有限。为此,提出同时优化梯度方向与幅度,实现更优的梯度匹配,显著提升攻击成功率。例如,在针对多视角汽车的投毒任务中,本方法相较当前最优方法提升19.49%。

原文摘要 · Abstract (English)

Targeted data poisoning (TDP) aims to compromise the model's prediction on a specific (test) target by perturbing a small subset of training data. Existing work on TDP has focused on an overly ideal threat model in which the same image sample of the target is used during both poisoning and inference stages. However, in the real world, a target object often appears in complex variations due to changes of physical settings such as viewpoint, background, and lighting conditions. In this work, we take the first step toward understanding the real-world threats of TDP by studying its generalizability across varying physical conditions. In particular, we observe that solely optimizing gradient directions, as adopted by the best previous TDP method, achieves limited generalization. To address this limitation, we propose optimizing both the gradient direction and magnitude for more generalizable gradient matching, thereby leading to higher poisoning success rates. For instance, our method outperforms the state of the art by 19.49% when poisoning CIFAR-10 images targeting multi-view cars.

数据投毒对抗攻击泛化能力

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。