arXiv:2505.12009cs.CV2025-05

提出隐空间扰动方法,让动作估计模型生成隐蔽恶意行为

LatentStealth: Unnoticeable and Efficient Adversarial Attacks on Expressive Human Pose and Shape Estimation

  • 在隐空间生成扰动,保持视觉不可见性
  • 仅需少量模型查询即可攻击成功,计算开销低
  • 揭示数字人生成系统安全漏洞,适合安全研究者参考

表达性人体姿态与形状估计(EHPS)在数字人生成中起关键作用,尤其在直播应用中。然而现有模型多关注降低估计误差,忽视潜在安全风险,如生成不当内容、暴力动作或种族歧视性姿态。当前对EHPS的对抗攻击常产生明显扰动,难以暴露真实世界威胁。为此,本文提出名为LatentStealth的隐蔽对抗攻击方法,专为EHPS设计。核心思想是利用自然图像的结构化隐表示作为扰动载体。不直接在像素空间加噪,而是将输入投影至隐空间,在优化方向上逐步生成并精炼对抗模式。该隐空间操作使攻击高度隐蔽且有效。此外,优化过程仅依赖少量模型输出查询,实现高效攻击,计算开销小,适用于真实场景。在3DPW和UBody数据集上的大量实验表明,LatentStealth性能优越,暴露出当前系统的严重安全隐患。研究强调亟需应对数字人生成技术中的安全风险。

原文摘要 · Abstract (English)

Expressive human pose and shape estimation (EHPS) plays a central role in digital human generation, particularly in live-streaming applications. However, most existing EHPS models focus primarily on minimizing estimation errors, with limited attention on potential security vulnerabilities, such as generating inappropriate content, violent actions, or racially offensive gestures and expressions. Current adversarial attacks on EHPS models often generate visually conspicuous perturbations, limiting their practicality and ability to expose real-world security threats. To address this limitation, we propose an unnoticeable adversarial method, termed \textbf{LatentStealth}, specifically tailored for EHPS models. The key idea is to exploit the structured latent representations of natural images as the medium for crafting perturbations. Instead of injecting noise directly into the pixel space, our method projects inputs into the latent space, where adversarial patterns are generated and progressively refined along optimized directions. This latent-space manipulation enables the attack to maintain high imperceptibility while preserving its effectiveness. Furthermore, as the optimization process is guided by only a small number of model output queries, the framework achieves competitive attack performance with low computational overhead, making it both practical and efficient for real-world scenarios. Extensive experiments on the 3DPW and UBody datasets demonstrate the superiority of LatentStealth, revealing critical vulnerabilities in current systems. These findings highlight the urgent need to address and mitigate security risks in digital human generation technologies.

对抗攻击人体姿态隐空间数字人安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。