arXiv:2508.01845cs.CVcs.AI2025-08综述被引 8

adversarial攻击既是威胁也是防御工具,揭示了视觉系统安全的双重性。

Beyond Vulnerabilities: A Survey of Adversarial Attacks as Both Threats and Defenses in Computer Vision Systems

  • 从像素、物理世界到潜空间,系统梳理三类攻击方法
  • 攻击技术演进至可迁移性强、生成更自然的对抗样本
  • 可用于检测生物识别漏洞和防御生成模型攻击,适合安全研究者

计算机视觉系统的对抗攻击已成为关键研究领域,挑战了神经网络鲁棒性与安全性的基本假设。本综述系统分析了对抗攻击在像素空间、可物理实现及潜空间三大领域的演变,涵盖从FGSM、PGD等早期梯度方法,到融合动量、自适应步长与先进迁移机制的优化技术。物理可实现攻击通过对抗贴纸、3D纹理与动态光扰动,成功连接数字漏洞与真实威胁。潜空间攻击则利用内部表征的语义结构,生成更具迁移性与意义的对抗样本。此外,对抗技术被用于生物识别系统的漏洞评估及抵御恶意生成模型。本文提出全面分类体系与未来方向,揭示神经风格迁移防护与计算效率等关键空白,旨在推动更鲁棒、可信的视觉系统发展。

原文摘要 · Abstract (English)

Adversarial attacks against computer vision systems have emerged as a critical research area that challenges the fundamental assumptions about neural network robustness and security. This comprehensive survey examines the evolving landscape of adversarial techniques, revealing their dual nature as both sophisticated security threats and valuable defensive tools. We provide a systematic analysis of adversarial attack methodologies across three primary domains: pixel-space attacks, physically realizable attacks, and latent-space attacks. Our investigation traces the technical evolution from early gradient-based methods such as FGSM and PGD to sophisticated optimization techniques incorporating momentum, adaptive step sizes, and advanced transferability mechanisms. We examine how physically realizable attacks have successfully bridged the gap between digital vulnerabilities and real-world threats through adversarial patches, 3D textures, and dynamic optical perturbations. Additionally, we explore the emergence of latent-space attacks that leverage semantic structure in internal representations to create more transferable and meaningful adversarial examples. Beyond traditional offensive applications, we investigate the constructive use of adversarial techniques for vulnerability assessment in biometric authentication systems and protection against malicious generative models. Our analysis reveals critical research gaps, particularly in neural style transfer protection and computational efficiency requirements. This survey contributes a comprehensive taxonomy, evolution analysis, and identification of future research directions, aiming to advance understanding of adversarial vulnerabilities and inform the development of more robust and trustworthy computer vision systems.

对抗攻击计算机视觉安全防御综述

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。