arXiv:2511.07049cs.CVcs.CR2025-11AAAI被引 9

无需任务知识,直接利用视频模型漏洞发动攻击

From Pretrain to Pain: Adversarial Vulnerability of Video Foundation Models Without Task Knowledge

  • 基于视频模型的时间动态特征设计对抗扰动
  • 在24个任务上成功攻击下游模型和多模态大模型
  • 无需训练代理模型或访问数据,适合实际攻击场景

大规模视频基础模型(VFMs)虽显著推动了视频相关任务的发展,但其开放性也带来安全风险。本文研究了一种新型实用的对抗攻击场景:在不掌握目标任务、训练数据、模型查询及架构的前提下,攻击基于开源视频模型微调的下游模型或多模态大语言模型。不同于依赖任务对齐代理模型的传统迁移攻击,本文提出时间感知的可迁移视频攻击(TVA),利用视频模型的时间表示动态生成有效扰动。TVA结合双向对比学习以最大化干净与对抗特征差异,并引入时间一致性损失,利用运动线索增强扰动的序列影响。该方法无需训练昂贵的代理模型或获取领域特定数据,更具实用性与效率。大量实验表明,TVA在24个视频任务中均能有效攻击下游模型和多模态大模型,揭示了视频模型部署中此前未被重视的安全漏洞。

原文摘要 · Abstract (English)

Large-scale Video Foundation Models (VFMs) has significantly advanced various video-related tasks, either through task-specific models or Multi-modal Large Language Models (MLLMs). However, the open accessibility of VFMs also introduces critical security risks, as adversaries can exploit full knowledge of the VFMs to launch potent attacks. This paper investigates a novel and practical adversarial threat scenario: attacking downstream models or MLLMs fine-tuned from open-source VFMs, without requiring access to the victim task, training data, model query, and architecture. In contrast to conventional transfer-based attacks that rely on task-aligned surrogate models, we demonstrate that adversarial vulnerabilities can be exploited directly from the VFMs. To this end, we propose the Transferable Video Attack (TVA), a temporal-aware adversarial attack method that leverages the temporal representation dynamics of VFMs to craft effective perturbations. TVA integrates a bidirectional contrastive learning mechanism to maximize the discrepancy between the clean and adversarial features, and introduces a temporal consistency loss that exploits motion cues to enhance the sequential impact of perturbations. TVA avoids the need to train expensive surrogate models or access to domain-specific data, thereby offering a more practical and efficient attack strategy. Extensive experiments across 24 video-related tasks demonstrate the efficacy of TVA against downstream models and MLLMs, revealing a previously underexplored security vulnerability in the deployment of video models.

视频安全对抗攻击基础模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。