arXiv:2601.01202cs.CVcs.AI2026-01

攻击参考图像可让超分辨率模型失效,暴露其安全缺陷。

RefSR-Adv: Adversarial Attack on Reference-based Image Super-Resolution Models

  • 仅扰动参考图,通过最大化输出差异实现攻击
  • 在多个数据集上使CNN、Transformer、Mamba模型性能严重下降
  • 相似度越高攻击越有效,揭示模型过度依赖参考特征

单图超分辨率(SISR)旨在从低分辨率输入恢复高分辨率图像。与之不同,参考图像超分辨率(RefSR)利用额外的高分辨率参考图像来帮助恢复高频纹理。然而,现有研究主要关注针对RefSR的后门攻击,而对对抗攻击的脆弱性尚未充分探索。为填补这一空白,我们提出RefSR-Adv,一种仅扰动参考图像即可降低超分辨率输出质量的对抗攻击方法。通过最大化对抗输出与干净输出之间的差异,RefSR-Adv在CUFED5、WR-SR和DRefSR数据集上导致CNN、Transformer和Mamba架构显著性能下降,并生成严重伪影。实验表明,低分辨率输入与参考图像越相似,攻击效果越强,揭示了模型对参考特征的过度依赖是关键安全漏洞。本研究揭示了RefSR系统的安全隐患,旨在引起研究者对其鲁棒性的重视。

原文摘要 · Abstract (English)

Single Image Super-Resolution (SISR) aims to recover high-resolution images from low-resolution inputs. Unlike SISR, Reference-based Super-Resolution (RefSR) leverages an additional high-resolution reference image to facilitate the recovery of high-frequency textures. However, existing research mainly focuses on backdoor attacks targeting RefSR, while the vulnerability of the adversarial attacks targeting RefSR has not been fully explored. To fill this research gap, we propose RefSR-Adv, an adversarial attack that degrades SR outputs by perturbing only the reference image. By maximizing the difference between adversarial and clean outputs, RefSR-Adv induces significant performance degradation and generates severe artifacts across CNN, Transformer, and Mamba architectures on the CUFED5, WR-SR, and DRefSR datasets. Importantly, experiments confirm a positive correlation between the similarity of the low-resolution input and the reference image and attack effectiveness, revealing that the model's over-reliance on reference features is a key security flaw. This study reveals a security vulnerability in RefSR systems, aiming to urge researchers to pay attention to the robustness of RefSR.

图像超分辨率对抗攻击安全漏洞

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。