提出新框架提升物理对抗攻击跨模型通用性
Towards Universal Physical Adversarial Attacks via a Joint Multi-Objective and Multi-Model Optimization Framework

- 联合多目标多模型优化,选最优替代模型集
- 双层机制抑制输出并平滑特征分布,提升泛化能力
- 用正交梯度对齐解决模型间冲突,适合安全评估场景
物理对抗攻击常过拟合单一替代模型和优化目标。虽然集成攻击可缓解此问题,但现有方法在受限的物理纹理空间中面临严重的梯度冲突,显著降低跨模型迁移能力。为此,本文提出联合多目标多模型优化框架(JMOF),通过定量相似性分析选取最优替代模型集合。JMOF采用双层机制,同时抑制预测输出并平坦化中间特征分布,平衡攻击效率与深层泛化。此外,提出的正交梯度对齐(OGA)策略化解跨模型梯度冲突,将相互排斥的梯度转化为协同优化方向。大量模拟与真实世界实验表明,JMOF在应对多种黑盒检测器时优于当前最优基线。关键的是,JMOF展现出显著的跨视觉任务泛化能力,可同时欺骗目标检测、语义分割或单目深度估计模型。该研究推动了物理对抗攻击泛化极限,为实际部署中视觉AI漏洞评估提供了鲁棒框架。
原文摘要 · Abstract (English)
Physical adversarial attacks often overfit single surrogate models and optimization objectives. While ensemble attacks can mitigate this, existing methods struggle with severe gradient conflicts within restricted physical texture spaces, significantly degrading cross-model transferability. To bridge this gap, this paper proposes a Joint Multi-Objective and Multi-Model Optimization Framework (JMOF) that leverages quantitative similarity analysis to select the optimal surrogate model ensemble. Within JMOF, a dual-level mechanism jointly suppresses prediction outputs and flattens intermediate feature distributions, balancing attack efficiency with deep generalization. Additionally, an Orthogonal Gradient Alignment (OGA) strategy resolves cross-model gradient conflicts, transforming mutually repulsive gradients into synergistic optimization directions. Extensive simulated and real-world experiments demonstrate that JMOF outperforms state-of-the-art baselines against diverse black-box detectors. Crucially, JMOF exhibits substantial cross-vision-task generalization, generating attacks capable of simultaneously deceiving object detection and semantic segmentation or monocular depth estimation models. This research advances the generalization limits of physical adversarial attacks, providing a robust framework for evaluating visual AI vulnerabilities in real-world deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。