arXiv:2509.22836cs.CVcs.AI2025-09被引 3

可控生成逼真对抗补丁,让模型误判目标类别。

Seeing Isn't Believing: Context-Aware Adversarial Patch Synthesis via Conditional GAN

  • 用生成式U-Net结合梯度类激活图定位,精准控制补丁位置。
  • 在多种模型上攻击成功率超99%,目标分类成功率也超99%。
  • 兼顾真实感、定向攻击与黑盒适用性,适合安全研究者参考。

对抗补丁攻击对深度神经网络构成严重威胁,但现有方法多依赖不现实的白盒假设、非定向目标,或产生明显可见的补丁,限制实际应用。本文提出一种完全可控的对抗补丁生成框架,攻击者可自由选择输入图像x和目标类别y_target,精确控制误分类结果。方法结合生成式U-Net与Grad-CAM引导的补丁布局,实现语义感知定位,在保证视觉真实性的同时最大化攻击效果。在卷积网络(DenseNet-121、ResNet-50)和视觉变换器(ViT-B/16、Swin-B/16等)上的实验表明,本方法在所有设置下均达到当前最优性能,攻击成功率达99%以上,目标类别成功率达99%以上。重要的是,该方法不仅超越以往白盒攻击和非定向基线,还优于存在可检测伪影的非现实方法。通过同时实现真实性、定向控制与黑盒适用性——对抗补丁攻击中三大最难点——本框架为对抗鲁棒性研究树立新基准,弥合理论攻击强度与实际隐蔽性的差距。

原文摘要 · Abstract (English)

Adversarial patch attacks pose a severe threat to deep neural networks, yet most existing approaches rely on unrealistic white-box assumptions, untargeted objectives, or produce visually conspicuous patches that limit real-world applicability. In this work, we introduce a novel framework for fully controllable adversarial patch generation, where the attacker can freely choose both the input image x and the target class y target, thereby dictating the exact misclassification outcome. Our method combines a generative U-Net design with Grad-CAM-guided patch placement, enabling semantic-aware localization that maximizes attack effectiveness while preserving visual realism. Extensive experiments across convolutional networks (DenseNet-121, ResNet-50) and vision transformers (ViT-B/16, Swin-B/16, among others) demonstrate that our approach achieves state-of-the-art performance across all settings, with attack success rates (ASR) and target-class success (TCS) consistently exceeding 99%. Importantly, we show that our method not only outperforms prior white-box attacks and untargeted baselines, but also surpasses existing non-realistic approaches that produce detectable artifacts. By simultaneously ensuring realism, targeted control, and black-box applicability-the three most challenging dimensions of patch-based attacks-our framework establishes a new benchmark for adversarial robustness research, bridging the gap between theoretical attack strength and practical stealthiness.

对抗攻击生成模型视觉安全黑盒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。