arXiv:2512.23953cs.CV2025-12被引 4

针对文本生成视频模型的对抗攻击,揭示其在语义与时间上的脆弱性

T2VAttack: Adversarial Attack on Text-to-Video Diffusion Models

  • 通过替换或插入关键词,实现对提示词的高效对抗扰动
  • 仅修改一个词就导致视频语义失真和时序混乱,严重降低生成质量
  • 适用于研究视频生成安全性的研究人员及模型开发者

文本到视频(T2V)扩散模型的快速发展推动了从自然语言描述生成高质量、时序连贯视频的重大进展。然而,这类模型对对抗攻击的脆弱性仍鲜有研究。本文提出T2VAttack,从语义和时间两个维度系统评估T2V扩散模型的对抗鲁棒性。针对视频数据的动态特性,设计两种攻击目标:语义目标用于评估视频与文本的一致性,时间目标用于分析时序动态表现。提出两种攻击方法:(i) T2VAttack-S,通过贪心搜索识别提示词中关键语义或时间词汇并替换为同义词;(ii) T2VAttack-I,迭代插入经优化的最小扰动词汇。结合多种目标与策略,在ModelScope、CogVideoX、Open-Sora和HunyuanVideo等主流T2V模型上进行全面评估。实验表明,即使仅替换或插入一个词,也会显著破坏语义保真度和时序一致性,暴露出当前T2V扩散模型的关键安全隐患。

原文摘要 · Abstract (English)

The rapid evolution of Text-to-Video (T2V) diffusion models has driven remarkable advancements in generating high-quality, temporally coherent videos from natural language descriptions. Despite these achievements, their vulnerability to adversarial attacks remains largely unexplored. In this paper, we introduce T2VAttack, a comprehensive study of adversarial attacks on T2V diffusion models from both semantic and temporal perspectives. Considering the inherently dynamic nature of video data, we propose two distinct attack objectives: a semantic objective to evaluate video-text alignment and a temporal objective to assess the temporal dynamics. To achieve an effective and efficient attack process, we propose two adversarial attack methods: (i) T2VAttack-S, which identifies semantically or temporally critical words in prompts and replaces them with synonyms via greedy search, and (ii) T2VAttack-I, which iteratively inserts optimized words with minimal perturbation to the prompt. By combining these objectives and strategies, we conduct a comprehensive evaluation on the adversarial robustness of several state-of-the-art T2V models, including ModelScope, CogVideoX, Open-Sora, and HunyuanVideo. Our experiments reveal that even minor prompt modifications, such as the substitution or insertion of a single word, can cause substantial degradation in semantic fidelity and temporal dynamics, highlighting critical vulnerabilities in current T2V diffusion models.

视频生成对抗攻击扩散模型安全性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。