提出新型隐形对抗补丁攻击,让模型误判同时人眼难察觉。
IAP: Invisible Adversarial Patch Attack through Perceptibility-Aware Localization and Perturbation Optimization
- 基于感知敏感度定位补丁位置,平衡模型与人眼对干扰的响应。
- 通过颜色恒定优化和感知正则化损失,生成几乎不可见的扰动。
- 在多种模型上有效规避主流防御机制,适合隐蔽攻击场景研究。
尽管仅修改局部输入区域,对抗补丁仍可显著改变计算机视觉模型的预测结果。然而,现有方法在目标攻击场景下表现不佳,或生成的补丁缺乏上下文一致性,易被人类观察者发现,且难以抵御自动补丁检测。本文提出IAP框架,通过感知感知意识定位与扰动优化生成高度隐蔽的对抗补丁。具体而言,IAP首先利用类别感知定位和敏感度图搜索合适放置位置,权衡补丁位置对目标模型预测与人眼视觉系统的敏感性;随后采用感知正则化对抗损失和优先保持颜色恒定的梯度更新策略,优化不可见扰动。在多个图像基准数据集和模型架构上的综合实验表明,IAP在目标攻击设置中持续实现有竞争力的攻击成功率,且补丁隐蔽性显著优于现有基线。此外,IAP生成的补丁不仅对人眼几乎不可察觉,还能使多种先进补丁防御失效。
原文摘要 · Abstract (English)
Despite modifying only a small localized input region, adversarial patches can drastically change the prediction of computer vision models. However, prior methods either cannot perform satisfactorily under targeted attack scenarios or fail to produce contextually coherent adversarial patches, causing them to be easily noticeable by human examiners and insufficiently stealthy against automatic patch defenses. In this paper, we introduce IAP, a novel attack framework that generates highly invisible adversarial patches based on perceptibility-aware localization and perturbation optimization schemes. Specifically, IAP first searches for a proper location to place the patch by leveraging classwise localization and sensitivity maps, balancing the susceptibility of patch location to both victim model prediction and human visual system, then employs a perceptibility-regularized adversarial loss and a gradient update rule that prioritizes color constancy for optimizing invisible perturbations. Comprehensive experiments across various image benchmarks and model architectures demonstrate that IAP consistently achieves competitive attack success rates in targeted settings with significantly improved patch invisibility compared to existing baselines. In addition to being highly imperceptible to humans, IAP is shown to be stealthy enough to render several state-of-the-art patch defenses ineffective.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。