arXiv:2506.23676cs.CV2025-06被引 1

将扩散模型与迁移增强结合,生成更隐蔽的对抗样本。

A Unified Framework for Stealthy Adversarial Generation via Latent Optimization and Transferability Enhancement

  • 用潜在空间优化+迁移增强,统一改进扩散模型生成对抗样本。
  • 在深度伪造检测任务中表现优异,竞赛夺冠验证效果。
  • 适合研究对抗攻击、AI安全或生成模型鲁棒性的研究人员。

由于强大的图像生成能力,基于扩散模型的图像编辑式对抗样本生成方法正迅速流行。然而,这些方法依赖于扩散模型的判别能力,在常规图像分类任务之外(如深度伪造检测)难以泛化。此外,传统提升对抗样本迁移性的策略难以适配此类方法。为此,我们提出一个统一框架,将传统迁移增强策略无缝集成到基于扩散模型的对抗样本生成中,使其可应用于更广泛的下游任务。该方法在ACM MM25举办的「首个针对深度伪造检测的对抗攻击挑战赛」中夺得第一名,验证了其有效性。

原文摘要 · Abstract (English)

Due to their powerful image generation capabilities, diffusion-based adversarial example generation methods through image editing are rapidly gaining popularity. However, due to reliance on the discriminative capability of the diffusion model, these diffusion-based methods often struggle to generalize beyond conventional image classification tasks, such as in Deepfake detection. Moreover, traditional strategies for enhancing adversarial example transferability are challenging to adapt to these methods. To address these challenges, we propose a unified framework that seamlessly incorporates traditional transferability enhancement strategies into diffusion model-based adversarial example generation via image editing, enabling their application across a wider range of downstream tasks. Our method won first place in the "1st Adversarial Attacks on Deepfake Detectors: A Challenge in the Era of AI-Generated Media" competition at ACM MM25, which validates the effectiveness of our approach.

对抗攻击扩散模型深度伪造

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。