arXiv:2504.12255cs.CVeess.IV2025-04被引 1

用人类感知对齐的压缩防御图像模型对抗攻击

Human Aligned Compression for Robust Models

  • 用学习型压缩(HiFiC/ELIC)替代传统JPEG,保留语义信息
  • 在ImageNet子集上显著提升ViT模型抗攻击能力
  • 多轮压缩可增强防御效果,适合实际部署

图像模型面临的对抗攻击通过引入人眼不可察觉的扰动导致错误预测,威胁系统鲁棒性。本文研究以人类感知对齐的有损压缩作为防御机制,对比了两种学习型压缩模型(HiFiC和ELIC)与传统JPEG在不同质量等级下的表现。在ImageNet子集上的实验表明,学习型压缩方法优于JPEG,尤其在视觉变换器(Vision Transformer)架构上表现突出,能在保留语义内容的同时去除对抗噪声。即使在白盒攻击场景下(攻击者可访问防御机制),该方法仍保持显著有效性。此外,多轮压缩(即反复压缩-解压)能显著提升防御性能,同时维持分类准确率。结果表明,人类对齐的压缩提供了一种高效、计算开销低的防御方案,保护对人类与机器理解都重要的图像特征,为提升模型鲁棒性提供了实用路径。

原文摘要 · Abstract (English)

Adversarial attacks on image models threaten system robustness by introducing imperceptible perturbations that cause incorrect predictions. We investigate human-aligned learned lossy compression as a defense mechanism, comparing two learned models (HiFiC and ELIC) against traditional JPEG across various quality levels. Our experiments on ImageNet subsets demonstrate that learned compression methods outperform JPEG, particularly for Vision Transformer architectures, by preserving semantically meaningful content while removing adversarial noise. Even in white-box settings where attackers can access the defense, these methods maintain substantial effectiveness. We also show that sequential compression--applying rounds of compression/decompression--significantly enhances defense efficacy while maintaining classification performance. Our findings reveal that human-aligned compression provides an effective, computationally efficient defense that protects the image features most relevant to human and machine understanding. It offers a practical approach to improving model robustness against adversarial threats.

对抗防御图像压缩视觉模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。