arXiv:2604.06954cs.CV2026-04

压缩会放大对抗攻击,让模型更易被攻破。

Compression as an Adversarial Amplifier Through Decision Space Reduction

  • 在压缩域直接攻击,比在像素域更有效。
  • 相同扰动下,压缩域攻击成功率显著提升。
  • 适合研究模型安全与压缩部署的工程师。

图像压缩是现代视觉系统中的常见环节,广泛应用于社交媒体和资源受限的系统中。尽管应用普遍,压缩对对抗鲁棒性的影响仍不明确。本文首次研究了在压缩表示上直接施加攻击的对抗场景,发现压缩会成为对抗攻击的放大器。在相同的扰动预算下,压缩感知攻击比像素空间攻击更具破坏性。我们将其归因于决策空间的压缩——压缩导致不可逆的信息丢失,缩小了分类边界,使模型对扰动更敏感。在多个标准基准和架构上的实验验证了这一现象,揭示了‘压缩-推理’闭环部署中的关键漏洞。代码将公开。

原文摘要 · Abstract (English)

Image compression is a ubiquitous component of modern visual pipelines, routinely applied by social media platforms and resource-constrained systems prior to inference. Despite its prevalence, the impact of compression on adversarial robustness remains poorly understood. We study a previously unexplored adversarial setting in which attacks are applied directly in compressed representations, and show that compression can act as an adversarial amplifier for deep image classifiers. Under identical nominal perturbation budgets, compression-aware attacks are substantially more effective than their pixel-space counterparts. We attribute this effect to decision space reduction, whereby compression induces a non-invertible, information-losing transformation that contracts classification margins and increases sensitivity to perturbations. Extensive experiments across standard benchmarks and architectures support our analysis and reveal a critical vulnerability in compression-in-the-loop deployment settings. Code will be released.

对抗攻击图像压缩模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。