arXiv:2412.07274cs.CV2024-12

用生成模型造攻击,无需专用分割模型也能高效生成对抗样本。

A Generative Victim Model for Segmentation

  • 用图像生成思路构造分割任务的对抗攻击模型
  • 生成的攻击在多种场景下均有良好迁移能力
  • 适合研究对抗攻击策略或缺乏目标模型的场景

我们发现,针对对抗攻击所构建的高质量分割受害者模型(VMs)是生成有效攻击的基础。传统方法依赖于具备鲁棒性的特定任务模型,而本文转向图像生成视角,提出一种新型通用分割受害者模型,可在不依赖专门设计的分割模型情况下,生成针对分割任务的有效对抗扰动。该方法突破了传统白盒或黑盒攻击范式,为对抗攻击提供了新思路。实验表明,所提方法生成的攻击具有良好的有效性与迁移性,在多个测试场景中表现优异。

原文摘要 · Abstract (English)

We find that the well-trained victim models (VMs), against which the attacks are generated, serve as fundamental prerequisites for adversarial attacks, i.e. a segmentation VM is needed to generate attacks for segmentation. In this context, the victim model is assumed to be robust to achieve effective adversarial perturbation generation. Instead of focusing on improving the robustness of the task-specific victim models, we shift our attention to image generation. From an image generation perspective, we derive a novel VM for segmentation, aiming to generate adversarial perturbations for segmentation tasks without requiring models explicitly designed for image segmentation. Our approach to adversarial attack generation diverges from conventional white-box or black-box attacks, offering a fresh outlook on adversarial attack strategies. Experiments show that our attack method is able to generate effective adversarial attacks with good transferability.

对抗攻击生成模型分割任务

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。