arXiv:2508.10946cs.CVcs.AI2025-08被引 1

提出高效生成对抗补丁的新方法,速度提升11.1倍且效果不减。

IPG: Incremental Patch Generation for Generalized Adversarial Patch Training

  • 分步生成补丁,逐步优化,大幅提升生成效率。
  • 在YOLO等模型上验证,补丁泛化能力强,覆盖更多漏洞。
  • 适合研究对抗攻击防御、自动驾驶与医疗影像安全的团队。

对抗补丁对计算机视觉任务中的AI模型鲁棒性构成重大挑战。与传统对抗样本不同,这类补丁针对图像特定区域,导致模型失效。本文提出增量补丁生成(IPG)方法,在保持攻击性能的同时,生成效率比现有方法高11.1倍。实验与消融研究(包括YOLO特征分布可视化和对抗训练结果)表明,IPG生成的补丁具有良好的泛化能力,能有效覆盖更广泛的模型漏洞。此外,由IPG生成的数据集可作为构建鲁棒模型的坚实知识基础,支持结构化表示、高级推理与主动防御,推动人工智能安全生态发展。研究结果表明,IPG不仅适用于对抗补丁防御,还可应用于自动驾驶、安防系统及医学影像等高动态、高风险场景中,保障AI模型在真实世界中的抗攻击能力。

原文摘要 · Abstract (English)

The advent of adversarial patches poses a significant challenge to the robustness of AI models, particularly in the domain of computer vision tasks such as object detection. In contradistinction to traditional adversarial examples, these patches target specific regions of an image, resulting in the malfunction of AI models. This paper proposes Incremental Patch Generation (IPG), a method that generates adversarial patches up to 11.1 times more efficiently than existing approaches while maintaining comparable attack performance. The efficacy of IPG is demonstrated by experiments and ablation studies including YOLO's feature distribution visualization and adversarial training results, which show that it produces well-generalized patches that effectively cover a broader range of model vulnerabilities. Furthermore, IPG-generated datasets can serve as a robust knowledge foundation for constructing a robust model, enabling structured representation, advanced reasoning, and proactive defenses in AI security ecosystems. The findings of this study suggest that IPG has considerable potential for future utilization not only in adversarial patch defense but also in real-world applications such as autonomous vehicles, security systems, and medical imaging, where AI models must remain resilient to adversarial attacks in dynamic and high-stakes environments.

对抗补丁生成效率模型鲁棒性安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。