arXiv:2605.18058cs.CV2026-05中稿 · the IEEE 15th Imag…

发现阿拉伯手写识别模型易受隐蔽对抗攻击

Threats to Arabic Handwriting Recognition: Investigating Black-Box Adversarial Attacks on embedded ConvNet models

论文配图:Threats to Arabic Handwriting Recognition: Investigating Black-Box Adversarial Attacks on embedded ConvNet models
图 1 · 摘自论文原文
  • 针对嵌入式ConvNet模型设计黑箱对抗攻击
  • Pixle攻击成功率高达99-100%,其他攻击达50-96%
  • 攻击后字符结构几乎不变,人眼难以察觉

阿拉伯手写识别(AHR)在深度学习推动下取得显著进展,但安全问题长期被忽视。本研究首次揭示高性能AHR模型对黑箱对抗攻击的脆弱性。在两个基准手写阿拉伯字符数据集上进行大量实验,结果显示:Pixle攻击在多数模型上实现99-100%的成功率,其他较温和攻击也达到50-96%的成功率。尽管攻击效果显著,字符结构保持完整,对人眼几乎不可见。结果表明所研究模型极易被对抗扰动操纵,凸显加强AHR系统安全性、保障其在真实场景中可靠性的紧迫性。

原文摘要 · Abstract (English)

Arabic handwriting recognition (AHR) has made significant progress with deep learning models. AHR research has largely focused on performance, with security receiving little attention. This study provides what appears to be a new line of inquiry by demonstrating the vulnerability of high-performing models to adversarial black-box attacks. The focus on black-box attacks reflects real-world scenarios where the attacker has no prior knowledge of the model architecture. Extensive experiments were conducted on two benchmark AHR datasets containing Arabic handwritten Characters. Results demonstrated the effectiveness of the attacks, with the Pixle attack achieving an attack success rate of 99-100\% on most models. Other, less aggressive attacks achieved success rates of 50-96\% across most experiments. Despite the higher attack success rate, the attacks maintain the structural integrity of the characters, rendering them almost imperceptible to the human eye. The findings indicate the higher vulnerability of the studied models to adversarial manipulation. This underscores the need to strengthen efforts to secure these models and ensure their reliability in AHR real-world applications.

手写识别对抗攻击黑箱攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。