用AI生成逼真光影扰动,欺骗视觉语言模型
Light as Deception: GPT-driven Natural Relighting Against Vision-Language Pre-training Models
- 用ChatGPT设计符合场景的光照初始参数
- 结合预训练重光照模型,实现多样且自然的扰动
- 在图像描述和视觉问答任务中均有效,适合研究对抗攻击
尽管视觉-语言预训练(VLP)模型的对抗攻击已受到关注,但通过真实且语义合理的扰动生成自然的对抗样本仍是一个开放挑战。现有方法主要针对分类任务设计,难以适配VLP模型,因其优化空间受限,导致攻击效果差或出现不自然伪影。为此,本文提出LightD框架,通过语义引导的重光照生成VLP模型的自然对抗样本。LightD利用ChatGPT生成上下文感知的初始光照参数,并集成预训练的重光照模型(IC-light),实现多样化的光照调整,扩展优化空间的同时确保扰动符合场景语义。此外,对参考光照图像进行梯度优化,进一步提升攻击效果并保持视觉自然性。在图像描述和视觉问答等任务中,LightD在多种VLP模型上均展现出有效性与优越性。
原文摘要 · Abstract (English)
While adversarial attacks on vision-and-language pretraining (VLP) models have been explored, generating natural adversarial samples crafted through realistic and semantically meaningful perturbations remains an open challenge. Existing methods, primarily designed for classification tasks, struggle when adapted to VLP models due to their restricted optimization spaces, leading to ineffective attacks or unnatural artifacts. To address this, we propose \textbf{LightD}, a novel framework that generates natural adversarial samples for VLP models via semantically guided relighting. Specifically, LightD leverages ChatGPT to propose context-aware initial lighting parameters and integrates a pretrained relighting model (IC-light) to enable diverse lighting adjustments. LightD expands the optimization space while ensuring perturbations align with scene semantics. Additionally, gradient-based optimization is applied to the reference lighting image to further enhance attack effectiveness while maintaining visual naturalness. The effectiveness and superiority of the proposed LightD have been demonstrated across various VLP models in tasks such as image captioning and visual question answering.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。