用智能代理动态组合攻击方法,让对抗样本更难被防御。
ARMOR: Agentic Reasoning for Methods Orchestration and Reparameterization for Robust Adversarial Attacks
- 通过视觉语言模型指挥多个攻击代理协同工作,实时调整策略。
- 在多种模型上测试,对白盒和黑盒目标的攻击成功率均提升。
- 能自动选择最佳攻击方式或融合多方法,适合研究对抗攻击的学者。
现有自动化攻击工具以固定顺序运行,缺乏策略适应性和语义感知能力。本文提出基于智能体推理的方法编排与重参数化框架(ARMOR),通过视觉语言模型引导的智能体协同控制三种经典对抗攻击方法:Carlini-Wagner(CW)、基于雅可比显著性图攻击(JSMA)和空间变换攻击(STA),在共享的“混音台”中生成并融合扰动。大型语言模型在闭环系统中实时调节并重设并行攻击代理参数,利用图像特定的语义漏洞进行优化。在标准基准测试中,ARMOR提升了跨架构迁移能力,在两种场景下均表现出更强的鲁棒性,对盲目标生成融合输出,对白盒目标则根据置信度与结构相似性(SSIM)分数选择最优攻击或混合攻击方案。
原文摘要 · Abstract (English)
Existing automated attack suites operate as static ensembles with fixed sequences, lacking strategic adaptation and semantic awareness. This paper introduces the Agentic Reasoning for Methods Orchestration and Reparameterization (ARMOR) framework to address these limitations. ARMOR orchestrates three canonical adversarial primitives, Carlini-Wagner (CW), Jacobian-based Saliency Map Attack (JSMA), and Spatially Transformed Attacks (STA) via Vision Language Models (VLM)-guided agents that collaboratively generate and synthesize perturbations through a shared ``Mixing Desk". Large Language Models (LLMs) adaptively tune and reparameterize parallel attack agents in a real-time, closed-loop system that exploits image-specific semantic vulnerabilities. On standard benchmarks, ARMOR achieves improved cross-architecture transfer and reliably fools both settings, delivering a blended output for blind targets and selecting the best attack or blended attacks for white-box targets using a confidence-and-SSIM score.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。