arXiv:2605.01718cs.CV2026-05被引 1

提出双分支扰动方法,让模型无法学习图像特征,有效对抗主流防御机制。

Dual-branch Robust Unlearnable Examples

论文配图:Dual-branch Robust Unlearnable Examples
图 1 · 摘自论文原文
  • 分空间与颜色域优化扰动,扩大干扰范围提升鲁棒性
  • 在7种主流防御下平均测试准确率降至14.95%~50.82%
  • 适合研究对抗样本、模型安全的学者参考

不可学习样本(Unlearnable Examples, UEs)通过向干净样本注入人眼难以察觉的扰动,旨在破坏模型训练。然而,现有方案因启发式设计或扰动范围受限,对先进防御手段缺乏鲁棒性。为此,本文提出 exttt{DUNE}——一种双分支不可学习集成扰动优化方法。具体而言, exttt{DUNE} 在空间域和颜色域分别优化扰动,建立扰动与漂移标签间的映射关系。该设计拓展了扰动域,增强噪声强度以提升鲁棒性,并促使模型学习与扰动相关的特征,导致泛化能力下降,从而实现不可学习性。为进一步提升性能,我们提出了一个增强不可学习性的集成策略,在双分支优化中融合多样预训练模型。在基准数据集 CIFAR-10 与 ImageNet 上的大量实验表明, exttt{DUNE} 在7种主流防御下优于12种当前最优(SOTA)UE方案,平均测试准确率降至14.95%至50.82%。

原文摘要 · Abstract (English)

Unlearnable examples (UEs) aim to compromise model training by injecting imperceptible perturbations to clean samples. However, existing UE schemes exhibit limited robustness against advanced defenses due to their heuristic design or narrowly scoped domain perturbations. To address this, we propose \texttt{DUNE}, a \underline{\textbf{D}}ual-branch \underline{\textbf{UN}}learnable \underline{\textbf{E}}nsemble perturbation optimization approach. Specifically, \texttt{DUNE} separately optimizes perturbations in the spatial and color domains to establish the mapping between perturbations and shift-induced labels. This design extends the perturbation domain to increase noise intensity for improving robustness and drives the models to learn perturbation-oriented features with degraded generalization, thereby achieving unlearnability. To strengthen \texttt{DUNE}'s performance, we further propose an unlearnability-enhancing ensemble strategy that aggregates diverse pre-trained models during the dual-branch optimization. Extensive experiments on benchmark datasets CIFAR-10 and ImageNet verify that \texttt{DUNE}'s robustness outperforms 12 SOTA UE schemes under 7 mainstream defenses, yielding a lower average test accuracy of 14.95% to 50.82%.

对抗样本模型安全不可学习双分支

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。