arXiv:2603.20777cs.LGcs.AI2026-03

提出可跨视觉变换器与卷积网络的通用对抗补丁,提升分割模型安全性。

OmniPatch: A Universal Adversarial Patch for ViT-CNN Cross-Architecture Transfer in Semantic Segmentation

  • 设计无需目标模型参数的通用对抗补丁训练框架
  • 在多种图像和模型架构上实现高攻击成功率
  • 适合研究对抗鲁棒性与模型安全的开发者

稳健的语义分割对自动驾驶安全至关重要,但部署模型在目标权重未知时仍易受黑盒对抗攻击。现有方法多生成图像级扰动或针对单一架构优化补丁,实用性与迁移性受限。本文提出OmniPatch,一种无需访问目标模型参数即可学习跨图像及视觉变换器(ViT)与卷积神经网络(CNN)架构的通用对抗补丁的训练框架,显著提升攻击的普适性与隐蔽性。

原文摘要 · Abstract (English)

Robust semantic segmentation is crucial for safe autonomous driving, yet deployed models remain vulnerable to black-box adversarial attacks when target weights are unknown. Most existing approaches either craft image-wide perturbations or optimize patches for a single architecture, which limits their practicality and transferability. We introduce OmniPatch, a training framework for learning a universal adversarial patch that generalizes across images and both ViT and CNN architectures without requiring access to target model parameters.

对抗攻击视觉变换器语义分割模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。