提出新攻击方法,利用SAM编码器弱点生成高迁移性对抗样本
SAM Encoder Breach by Adversarial Simplicial Complex Triggers Downstream Model Failures
- 通过参数化单纯复形建模SAM与下游模型的共性脆弱区域
- 在五个数据集上比现有方法提升12.7%的攻击迁移性
- 适合安全评估、鲁棒模型设计的研究者参考
尽管分割一切模型(SAM)以零样本能力革新了交互式分割,但其固有漏洞构成单点风险,可能引发众多下游应用失效。主动评估这些可迁移漏洞至关重要。以往对SAM的对抗攻击往往因未充分探索跨域共性弱点而迁移性有限。为此,本文提出顶点精炼单纯复形攻击(VeSCA),仅利用SAM编码器生成可迁移对抗样本。该方法通过参数化单纯复形显式刻画SAM与下游模型间的共享脆弱区域,并通过迭代顶点精炼识别对抗强区域。引入轻量级领域重适配策略,仅用少量参考数据弥合领域差异。最终通过随机单纯复形采样生成持续可迁移的对抗样本。大量实验表明,VeSCA在三个下游模型类别、五个特定领域数据集上相较最优方法性能提升12.7%。研究进一步揭示了SAM漏洞对下游模型的风险,凸显构建更鲁棒基础模型的紧迫性。
原文摘要 · Abstract (English)
While the Segment Anything Model (SAM) transforms interactive segmentation with zero-shot abilities, its inherent vulnerabilities present a single-point risk, potentially leading to the failure of numerous downstream applications. Proactively evaluating these transferable vulnerabilities is thus imperative. Prior adversarial attacks on SAM often present limited transferability due to insufficient exploration of common weakness across domains. To address this, we propose Vertex-Refining Simplicial Complex Attack (VeSCA), a novel method that leverages only the encoder of SAM for generating transferable adversarial examples. Specifically, it achieves this by explicitly characterizing the shared vulnerable regions between SAM and downstream models through a parametric simplicial complex. Our goal is to identify such complexes within adversarially potent regions by iterative vertex-wise refinement. A lightweight domain re-adaptation strategy is introduced to bridge domain divergence using minimal reference data during the initialization of simplicial complex. Ultimately, VeSCA generates consistently transferable adversarial examples through random simplicial complex sampling. Extensive experiments demonstrate that VeSCA achieves performance improved by 12.7% compared to state-of-the-art methods across three downstream model categories across five domain-specific datasets. Our findings further highlight the downstream model risks posed by SAM's vulnerabilities and emphasize the urgency of developing more robust foundation models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。