arXiv:2604.26317cs.CV2026-04中稿 · AISTATS 2026

首次构建对抗补丁与自然噪声联合数据集,提升模型物理安全防御能力

The Unseen Adversaries: Robust and Generalized Defense Against Adversarial Patches

论文配图:The Unseen Adversaries: Robust and Generalized Defense Against Adversarial Patches
图 1 · 摘自论文原文
  • 构建含对抗补丁与噪声的联合数据集,模拟真实世界威胁
  • 传统机器学习分类器在异常检测中表现优于神经网络调参方法
  • 独立防御无效,需协同应对多种奇异扰动,适合安全敏感场景研究者

深度神经网络对奇异性攻击的脆弱性引发了其在物理世界部署中的严重担忧。其中最具代表性的物理攻击是向干净图像附加补丁的对抗补丁攻击,而高斯噪声、盐椒噪声等自然干扰在现实环境中也极为普遍。当前研究空白在于缺乏对两类奇异性独立及联合处理的努力。本文首次将二者结合,提出一个新型数据集,并基于此对多种卷积神经网络特征进行奇异性数据点检测的基准测试。分类任务采用传统但高效的机器学习分类器,而非流行的神经网络参数调优。跨多种分布内/外(OOD)奇异性广泛实验揭示:若独立处理攻击且选用低效分类器,则防御效果极差。

原文摘要 · Abstract (English)

The vulnerabilities of deep neural networks against singularities have raised serious concerns regarding their deployment in the physical world. One of the most prominent and impactful physical-world adversarial perturbations is the attachment of patches to clean images, known as an adversarial patch attack. Similarly, natural noises such as Gaussian and Salt\&Pepper are highly prevalent in the real world. The current research need arises from the above vulnerabilities and the lack of efforts to tackle these two singularities independently and, especially, in combination. In this research, we have, for the first time, combined these two prominent singularities and proposed a novel dataset. Using this dataset, we have conducted a benchmark study of singularity data-point detection using features from several convolutional neural networks. For classification, rather than the popular neural network-based parameter tuning, we have used traditional yet effective machine learning classifiers. The extensive experiments across various in- and out-of-distribution (OOD) singularities reveal several interesting findings about the effectiveness of classifiers and show that it is hard to defend against adversaries when they are treated independently, and inefficient classifiers are selected.

对抗样本物理攻击异常检测鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。