arXiv:2603.24821cs.CVcs.AI2026-03中稿 · CVPR被引 1

提出跨范式攻击方法,让人群计数模型同时失效且难以察觉。

Generative Adversarial Perturbations with Cross-paradigm Transferability on Localized Crowd Counting

  • 设计多任务损失框架,统一攻击密度图与点回归模型。
  • 平均使误差提升7倍,且在7个顶尖模型上成功迁移。
  • 攻击隐蔽性强,适合研究模型安全与防御机制者参考。

当前人群计数与定位主要基于密度图和点回归两种范式。鉴于该领域在安全上的重要性,模型对对抗攻击的鲁棒性备受关注。已有研究证明了基于密度图模型间的对抗补丁可迁移性,但跨范式攻击(即同时影响密度图与点回归模型)尚未被探索。本文提出一种新型对抗框架,通过综合多任务损失优化,同时破坏两类架构。针对点回归模型,采用场景密度特异性高置信度logit抑制;针对密度图方法,则使用峰值目标密度图抑制。两者结合模型无关的感知约束,确保扰动有效且人眼难以察觉。大量实验表明,该攻击使平均绝对误差相比干净图像提升7倍,同时保持良好视觉质量,并在7个先进人群模型上实现0.55至1.69的迁移率。相较现有可迁移攻击策略,本方法在攻击效果与隐蔽性间取得更好平衡。源代码已公开于https://github.com/simurgh7/CrowdGen。

原文摘要 · Abstract (English)

State-of-the-art crowd counting and localization are primarily modeled using two paradigms: density maps and point regression. Given the field's security ramifications, there is active interest in model robustness against adversarial attacks. Recent studies have demonstrated transferability across density-map-based approaches via adversarial patches, but cross-paradigm attacks (i.e., across both density map-based models and point regression-based models) remain unexplored. We introduce a novel adversarial framework that compromises both density map and point regression architectural paradigms through a comprehensive multi-task loss optimization. For point-regression models, we employ scene-density-specific high-confidence logit suppression; for density-map approaches, we use peak-targeted density map suppression. Both are combined with model-agnostic perceptual constraints to ensure that perturbations are effective and imperceptible to the human eye. Extensive experiments demonstrate the effectiveness of our attack, achieving on average a 7X increase in Mean Absolute Error compared to clean images while maintaining competitive visual quality, and successfully transferring across seven state-of-the-art crowd models with transfer ratios ranging from 0.55 to 1.69. Our approach strikes a balance between attack effectiveness and imperceptibility compared to state-of-the-art transferable attack strategies. The source code is available at https://github.com/simurgh7/CrowdGen

对抗攻击人群计数跨范式隐秘性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。