arXiv:2601.02228cs.CV2026-01

用掩码流匹配修复视频对抗攻击,提升净化效果与鲁棒性。

FMVP: Masked Flow Matching for Adversarial Video Purification

  • 通过掩码策略物理破坏全局对抗结构,结合条件流匹配重建清晰动态。
  • 对PGD攻击实现超87%鲁棒准确率,对CW攻击达89%,超越现有方法。
  • 可零样本检测对抗攻击,对微弱干扰的检测AUC达0.79,适合安全防御场景。

视频识别模型仍易受对抗攻击影响,现有基于扩散的净化方法存在采样效率低和轨迹弯曲的问题。直接从对抗输入回归干净视频常因扰动细微而无法恢复真实内容,因此需物理上破坏对抗结构。为此,我们提出用于对抗视频净化的流匹配方法(FMVP)。FMVP通过掩码策略物理破坏全局对抗结构,并利用条件流匹配(CFM)结合图像修复目标重建干净视频动态。为进一步解耦语义内容与对抗噪声,设计频域门控损失(FGL),显式抑制高频对抗残差,同时保留低频保真度。构建针对已知威胁的攻击感知训练与针对未知威胁的通用训练范式。在UCF-101和HMDB-51上的大量实验表明,FMVP优于当前最优方法(DiffPure、Defense Patterns (DP)、Temporal Shuffling (TS) 和 FlowPure),在PGD攻击下达到超过87%的鲁棒准确率,在CW攻击下达89%。此外,FMVP对自适应攻击(DiffHammer)表现出更强鲁棒性,且可作为零样本对抗检测器,对PGD攻击的AUC-ROC达0.98,对极难察觉的CW攻击达0.79。

原文摘要 · Abstract (English)

Video recognition models remain vulnerable to adversarial attacks, while existing diffusion-based purification methods suffer from inefficient sampling and curved trajectories. Directly regressing clean videos from adversarial inputs often fails to recover faithful content due to the subtle nature of perturbations; this necessitates physically shattering the adversarial structure. Therefore, we propose Flow Matching for Adversarial Video Purification FMVP. FMVP physically shatters global adversarial structures via a masking strategy and reconstructs clean video dynamics using Conditional Flow Matching (CFM) with an inpainting objective. To further decouple semantic content from adversarial noise, we design a Frequency-Gated Loss (FGL) that explicitly suppresses high-frequency adversarial residuals while preserving low-frequency fidelity. We design Attack-Aware and Generalist training paradigms to handle known and unknown threats, respectively. Extensive experiments on UCF-101 and HMDB-51 demonstrate that FMVP outperforms state-of-the-art methods (DiffPure, Defense Patterns (DP), Temporal Shuffling (TS) and FlowPure), achieving robust accuracy exceeding 87% against PGD and 89% against CW attacks. Furthermore, FMVP demonstrates superior robustness against adaptive attacks (DiffHammer) and functions as a zero-shot adversarial detector, attaining AUC-ROC scores of 0.98 for PGD and 0.79 for highly imperceptible CW attacks.

视频净化对抗防御流匹配扩散模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。