arXiv:2603.05604cs.CVcs.LG2026-03

首次实现关键点检测联合鲁棒性验证,更真实地评估模型抗干扰能力。

From Decoupled to Coupled: Robustness Verification for Learning-based Keypoint Detection with Joint Specifications

  • 将所有关键点联合建模,捕捉其相互依赖关系
  • 在严格误差阈值下验证率远超传统独立验证方法
  • 适用于对精度要求高的姿态估计等下游任务

关键点检测支撑姿态估计、视角恢复和3D重建等多种视觉任务,但现代神经网络对微小输入扰动仍敏感。由于输入维度高且输出为连续坐标,关键点检测的正式鲁棒性验证尚未被充分探索。本文提出首个基于热图的关键点检测联合鲁棒性验证框架,通过约束所有关键点的联合偏移来捕获其相互依赖性及下游任务需求。与以往独立验证每个关键点的解耦方法不同,本方法将验证问题转化为混合整数线性规划(MILP),结合可达热图集与联合偏移约束多面体。不可行性可证明鲁棒性,可行性则生成反例,且方法具有完备性:若判定模型鲁棒,则实际模型必鲁棒。实验表明,该联合方法在严格误差阈值下仍保持高验证率,而解耦方法已失效。

原文摘要 · Abstract (English)

Keypoint detection underpins many vision tasks, including pose estimation, viewpoint recovery, and 3D reconstruction, yet modern neural models remain vulnerable to small input perturbations. Despite its importance, formal robustness verification for keypoint detectors is largely unexplored due to high-dimensional inputs and continuous coordinate outputs. We propose the first coupled robustness verification framework for heatmap-based keypoint detectors that bounds the joint deviation across all keypoints, capturing their interdependencies and downstream task requirements. Unlike prior decoupled, classification-style approaches that verify each keypoint independently and yield conservative guarantees, our method verifies collective behavior. We formulate verification as a falsification problem using a mixed-integer linear program (MILP) that combines reachable heatmap sets with a polytope encoding joint deviation constraints. Infeasibility certifies robustness, while feasibility provides counterexamples, and we prove the method is sound: if it certifies the model as robust, then the keypoint detection model is guaranteed to be robust. Experiments show that our coupled approach achieves high verified rates and remains effective under strict error thresholds where decoupled methods fail.

关键点检测鲁棒性验证联合约束对抗防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。