arXiv:2509.22710cs.LGcs.AI2025-09

将对抗噪声限制在局部区域,让攻击更隐蔽且更难察觉。

Localizing Adversarial Attacks To Produces More Imperceptible Noise

  • 用二值掩码约束噪声只出现在特定区域,实现局部攻击。
  • 局部攻击平均像素扰动降低,PSNR和SSIM显著提升。
  • 迭代方法如PGD、C&W在局部化下表现更稳定,适合实战。

机器学习中的对抗攻击传统上聚焦于对输入数据的全局扰动,而局部对抗噪声的潜力尚未充分探索。本研究系统评估了FGSM、PGD和C&W等多种方法在局部攻击下的表现,量化其有效性、不可察觉性与计算效率。通过引入二值掩码将噪声限制在特定区域,局部攻击相比全局攻击实现了更低的均值像素扰动、更高的峰值信噪比(PSNR)和更好的结构相似性指数(SSIM)。然而,这种优势伴随着更高的计算开销以及攻击成功率(ASR)的轻微下降。结果表明,迭代方法(如PGD和C&W)在局部化约束下比单步方法(如FGSM)更具鲁棒性,能维持更高的攻击成功率与不可察觉性指标。本研究为局部对抗攻击提供了全面分析,为改进攻击策略和设计更鲁棒的防御系统提供了实践指导。

原文摘要 · Abstract (English)

Adversarial attacks in machine learning traditionally focus on global perturbations to input data, yet the potential of localized adversarial noise remains underexplored. This study systematically evaluates localized adversarial attacks across widely-used methods, including FGSM, PGD, and C&W, to quantify their effectiveness, imperceptibility, and computational efficiency. By introducing a binary mask to constrain noise to specific regions, localized attacks achieve significantly lower mean pixel perturbations, higher Peak Signal-to-Noise Ratios (PSNR), and improved Structural Similarity Index (SSIM) compared to global attacks. However, these benefits come at the cost of increased computational effort and a modest reduction in Attack Success Rate (ASR). Our results highlight that iterative methods, such as PGD and C&W, are more robust to localization constraints than single-step methods like FGSM, maintaining higher ASR and imperceptibility metrics. This work provides a comprehensive analysis of localized adversarial attacks, offering practical insights for advancing attack strategies and designing robust defensive systems.

对抗攻击局部噪声图像安全防御设计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。