arXiv:2502.08079cs.CV2025-02被引 5

提出细粒度对抗攻击方法,提升跨模型泛化能力

MAA: Meticulous Adversarial Attack against Vision-Language Pre-trained Models

  • 通过新滑动裁剪与多粒度相似性破坏策略,聚焦样本自身弱点
  • 在多个视觉语言模型上实现更高攻击成功率与更强迁移性
  • 适合研究模型鲁棒性或对抗攻击的学者参考

当前针对多模态任务中视觉语言预训练(VLP)模型的对抗攻击存在迁移能力有限的问题,即为特定模型设计的攻击难以有效泛化到其他模型,限制了其在广泛评估鲁棒性方面的应用。这主要归因于对模型特异性特征和图像区域的过度依赖。本文提出一种名为细致对抗攻击(MAA)的方法,充分挖掘个体样本的模型无关特征与漏洞,显著提升攻击的泛化能力并降低模型依赖性。MAA通过创新的重缩放与滑动裁剪(RScrop)技术,结合多粒度相似性破坏(MGSD)策略,实现对抗图像的精细化优化。在多种VLP模型、多个基准数据集及多样化下游任务上的大量实验表明,MAA显著增强了对抗攻击的有效性与可迁移性。同时,通过大规模性能分析,揭示了不同模型配置的影响,为该领域未来发展提供洞见。

原文摘要 · Abstract (English)

Current adversarial attacks for evaluating the robustness of vision-language pre-trained (VLP) models in multi-modal tasks suffer from limited transferability, where attacks crafted for a specific model often struggle to generalize effectively across different models, limiting their utility in assessing robustness more broadly. This is mainly attributed to the over-reliance on model-specific features and regions, particularly in the image modality. In this paper, we propose an elegant yet highly effective method termed Meticulous Adversarial Attack (MAA) to fully exploit model-independent characteristics and vulnerabilities of individual samples, achieving enhanced generalizability and reduced model dependence. MAA emphasizes fine-grained optimization of adversarial images by developing a novel resizing and sliding crop (RScrop) technique, incorporating a multi-granularity similarity disruption (MGSD) strategy. Extensive experiments across diverse VLP models, multiple benchmark datasets, and a variety of downstream tasks demonstrate that MAA significantly enhances the effectiveness and transferability of adversarial attacks. A large cohort of performance studies is conducted to generate insights into the effectiveness of various model configurations, guiding future advancements in this domain.

对抗攻击视觉语言模型鲁棒性多模态

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。