arXiv:2503.04385cs.CV2025-03中稿 · TIFS 2025被引 8

提出一种对任意尺度超分辨率的抗尺度攻击方法,效果强且通用。

Scale-Invariant Adversarial Attack against Arbitrary-scale Super-resolution

  • 利用连续表示的离散点构建节省资源的攻击
  • 在四个数据集上实现显著破坏力且低可见扰动
  • 适合研究模型鲁棒性或防御策略的学者

局部连续图像函数(LIIF)的出现引发了对任意尺度超分辨率(SR)技术的广泛关注。然而,尽管固定尺度SR的漏洞已被研究,基于连续表示的任意尺度SR在对抗攻击下的鲁棒性仍需深入探索。现有针对固定尺度的对抗攻击具有尺度依赖性,应用于任意尺度时会带来时间和内存开销。为此,我们提出一种简单有效的“尺度不变”对抗攻击方法SIAGT,具备良好迁移性。具体地,通过利用连续表示的有限离散点构建资源高效的攻击;同时设计坐标相关损失,提升跨模型攻击迁移能力。该攻击能在显著劣化超分辨率图像的同时,对目标低分辨率图像引入几乎不可察觉的扰动。在三种主流LIIF-based SR方法和四个经典SR数据集上的实验表明,SIAGT展现出卓越的攻击性能与迁移能力。

原文摘要 · Abstract (English)

The advent of local continuous image function (LIIF) has garnered significant attention for arbitrary-scale super-resolution (SR) techniques. However, while the vulnerabilities of fixed-scale SR have been assessed, the robustness of continuous representation-based arbitrary-scale SR against adversarial attacks remains an area warranting further exploration. The elaborately designed adversarial attacks for fixed-scale SR are scale-dependent, which will cause time-consuming and memory-consuming problems when applied to arbitrary-scale SR. To address this concern, we propose a simple yet effective ``scale-invariant'' SR adversarial attack method with good transferability, termed SIAGT. Specifically, we propose to construct resource-saving attacks by exploiting finite discrete points of continuous representation. In addition, we formulate a coordinate-dependent loss to enhance the cross-model transferability of the attack. The attack can significantly deteriorate the SR images while introducing imperceptible distortion to the targeted low-resolution (LR) images. Experiments carried out on three popular LIIF-based SR approaches and four classical SR datasets show remarkable attack performance and transferability of SIAGT.

超分辨率对抗攻击鲁棒性连续表示

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。