arXiv:2508.01676cs.CVcs.CR2025-08被引 1

发现图像中极小补丁即可让模型误判,提出高效定位方法提升攻击成功率。

Benchmarking Adversarial Patch Selection and Location

  • 系统评估超1.5亿次前向传播,构建首个补丁位置全面基准
  • 2%面积补丁可导致模型置信度大幅下降,存在明显易受攻击热点区
  • 利用现成分割掩码定位弱点区域,无需梯度查询,攻击成功率提升8-13%

对抗性补丁攻击威胁现代视觉模型的可靠性。我们提出 PatchMap,首个空间上全面覆盖的补丁放置基准,通过在 ImageNet 验证集上执行超过 1.5 亿次前向传播构建。PatchMap 揭示了小补丁(最小仅占图像 2%)可引发模型高度自信的误分类,并导致模型置信度显著下降的系统性热点区域。为展示其价值,我们提出一种简单的分割引导放置启发式方法,利用现成掩码识别脆弱区域,无需任何梯度查询。在五种架构(包括对抗训练的 ResNet50)上,该方法相比随机或固定放置,攻击成功率提升 8 至 13 个百分点。我们已公开发布 PatchMap 及代码实现。完整 PatchMap 基准(650 亿次预测,多种骨干网络)将于近期发布,以进一步推动位置感知防御与自适应攻击研究。

原文摘要 · Abstract (English)

Adversarial patch attacks threaten the reliability of modern vision models. We present PatchMap, the first spatially exhaustive benchmark of patch placement, built by evaluating over 1.5e8 forward passes on ImageNet validation images. PatchMap reveals systematic hot-spots where small patches (as little as 2% of the image) induce confident misclassifications and large drops in model confidence. To demonstrate its utility, we propose a simple segmentation guided placement heuristic that leverages off the shelf masks to identify vulnerable regions without any gradient queries. Across five architectures-including adversarially trained ResNet50, our method boosts attack success rates by 8 to 13 percentage points compared to random or fixed placements. We publicly release PatchMap and the code implementation. The full PatchMap bench (6.5B predictions, multiple backbones) will be released soon to further accelerate research on location-aware defenses and adaptive attacks.

对抗攻击补丁攻击图像安全定位优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。