arXiv:2603.25230cs.CV2026-03

提出统一空间对齐框架,提升对抗攻击在分割检测任务中的迁移性。

A Unified Spatial Alignment Framework for Highly Transferable Transformation-Based Attacks on Spatially Structured Tasks

  • 同步变换输入与标签的空间位置,解决结构化任务中的空间错位问题。
  • 在Cityscapes、Kvasir-SEG和COCO上分别使mIoU降至11.34、31.80和mAP降至5.25。
  • 适用于图像分割、目标检测等空间结构任务,适合安全评估研究者。

基于变换的对抗攻击(TAAs)在分类模型上表现出强迁移性,但在语义分割和目标检测等结构化任务中表现不佳。现有方法未同步变换标签,导致输入与标签空间错位,产生错误梯度。本文提出统一空间对齐框架(SAF),通过所提空间对齐(SA)算法同步变换输入与标签的空间位置。大量实验表明,该框架显著提升攻击效果:非目标攻击下,Cityscapes的平均mIoU从24.50降至11.34,Kvasir-SEG从49.91降至31.80,COCO的平均mAP从17.89降至5.25,验证了空间对齐对结构化任务攻击迁移性的关键作用。

原文摘要 · Abstract (English)

Transformation-based adversarial attacks (TAAs) demonstrate strong transferability when deceiving classification models. However, existing TAAs often perform unsatisfactorily or even fail when applied to structured tasks such as semantic segmentation and object detection. Encouragingly, recent studies that categorize transformations into non-spatial and spatial transformations inspire us to address this challenge. We find that for non-structured tasks, labels are spatially non-structured, and thus TAAs are not required to adjust labels when applying spatial transformations. In contrast, for structured tasks, labels are spatially structured, and failing to transform labels synchronously with inputs can cause spatial misalignment and yield erroneous gradients. To address these issues, we propose a novel unified Spatial Alignment Framework (SAF) for highly transferable TAAs on spatially structured tasks, where the TAAs spatially transform labels synchronously with the input using the proposed Spatial Alignment (SA) algorithm. Extensive experiments demonstrate the crucial role of our SAF for TAAs on structured tasks. Specifically, in non-targeted attacks, our SAF degrades the average mIoU on Cityscapes from 24.50 to 11.34, and on Kvasir-SEG from 49.91 to 31.80, while reducing the average mAP of COCO from 17.89 to 5.25.

对抗攻击空间对齐分割检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。