XSPA用X形稀疏扰动攻击视觉语言模型,实现跨任务高成功率攻击。
XSPA: Crafting Imperceptible X-Shaped Sparse Adversarial Perturbations for Transferable Attacks on VLMs
- 在两条对角线构成的固定几何结构内优化扰动,提升攻击效率。
- 仅改变1.04%像素,使CLIP模型零样本准确率下降超50点。
- 适合研究模型鲁棒性,尤其关注稀疏几何扰动的影响。
视觉语言模型(VLMs)在零样本分类、图像描述和视觉问答(VQA)中共享视觉-文本表征,使得细微扰动可能引发多任务失效。本文提出X形稀疏像素攻击(XSPA),将扰动限制在两条相交对角线上。在固定支持域内,联合优化分类目标、跨任务语义引导、扰动幅度与线性平滑性。默认设置下,扰动仅涉及约1.04%图像像素。在COCO数据集上,XSPA使OpenAI CLIP ViT-L/14零样本准确率下降52.33点,OpenCLIP ViT-B/16下降67.00点;基于GPT-4的描述一致性与VQA正确率分别降低最多58.60和44.25点。对比实验显示,自适应显著性Top-k支持虽更优,但XSPA在SSIM和LPIPS指标上表现更好,而PSNR和MAE较差。同图分析表明三任务定向攻击未成功,说明强代理分类效应未必转化为输出空间失败。结果表明,XSPA是研究稀疏固定几何对VLM鲁棒性影响的可控压力测试,而非通用优越攻击方法。
原文摘要 · Abstract (English)
Vision-language models (VLMs) share visual-textual representations across zero-shot classification, image captioning, and visual question answering (VQA), creating a pathway through which subtle perturbations may cause failures across tasks. We introduce X-shaped Sparse Pixel Attack (XSPA), a structured attack that restricts perturbations to two intersecting diagonal lines. Within this fixed support, XSPA jointly optimizes a classification objective, cross-task semantic guidance, perturbation magnitude, and linewise smoothness. Under the default setting, it changes about 1.04\% of image pixels. On COCO, XSPA reduces zero-shot accuracy by 52.33 points on OpenAI CLIP ViT-L/14 and 67.00 points on OpenCLIP ViT-B/16; GPT-4-based caption consistency and VQA correctness decrease by up to 58.60 and 44.25 points, respectively. Matched-budget experiments show that an adaptive saliency Top-k support achieves higher attack success than the fixed X-shaped support, while XSPA provides better SSIM and LPIPS but worse PSNR and MAE. Same-image analysis finds no three-task targeted success, indicating that strong surrogate classification effects do not reliably translate into targeted output-space failures. These results position XSPA as a controlled stress test for studying how sparse fixed geometry affects VLM robustness, rather than as a universally superior attack.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。