提出新评估框架,衡量对抗补丁在真实场景中的稳定性表现。
AdvScene: Rethinking Adversarial Patch Evaluation Through Scene Robustness

- 构建基于真实场景重建的评估框架,量化补丁在不同视角距离下的攻击效果。
- 发现现有评估方法忽略场景变化影响,实际攻击成功率波动显著。
- 适合关注物理对抗攻击安全性的研究者与防御系统开发者。
对抗补丁是附加在真实物体上的物理图案,旨在误导人工智能视觉系统。其真实世界风险不取决于单次成功欺骗,而在于部署后面对视角、距离和场景变化时是否仍有效。我们称此为场景鲁棒性——补丁在真实环境中跨条件的有效性。然而,现有评估方法难以准确衡量:真实图像基准虽逼真但固定,模拟器虽可控却缺乏具体真实场景依据。本文提出AdvScene,一个基于真实场景重建的框架,用于测量对抗补丁的场景鲁棒性。AdvScene将评估重构为操作性度量:给定一个固定部署的补丁,刻画其在不同视角、距离和场景上下文下的成功区域,即攻击的操作包络。核心挑战在于攻击通常仅定义于单一锚点视角,而评估需保持视角变化下的表观一致性。为此,我们形式化为约束提升问题,提出对抗补丁到场景嵌入(APSE),解决跨视角模糊性,同时保留攻击关键外观特征,并强制局部性、目标表面附着性和跨视角一致性。我们使用真实物理数据验证AdvScene,并对现有对抗补丁进行全面评估。结果表明,该框架揭示了攻击有效性存在显著的场景依赖性差异,这是传统图像中心或模拟器评估无法捕捉的。
原文摘要 · Abstract (English)
Adversarial patches are physical patterns attached to real objects to mislead AI vision systems. Their real-world risk is not determined by a single successful prediction, but by whether they remain effective after deployment under changing viewpoints, distances, and scene conditions. We refer to this property as scene robustness, the effectiveness of a deployed patch across conditions in a real environment. Yet existing evaluations do not measure scene robustness well: real image benchmarks are realistic but fixed, while simulators are controllable but not grounded in a specific real scene. We present AdvScene, a scene-grounded framework for measuring the scene robustness of adversarial patches in reconstructed real environments. AdvScene reframes evaluation as operational measurement: given a fixed deployed patch, it characterizes the patch's operational envelope - where and when the attack succeeds - as a function of viewpoint, distance, and scene context. A key challenge is that the attack is typically defined only in a single anchor view, while evaluation requires a representation that remains faithful under viewpoint changes. We formalize this as a constrained lifting problem and introduce Adversarial Patch-to-Scene Embedding (APSE), which resolves cross-view ambiguity while preserving attack-critical appearance and enforcing locality, target-surface attachment, and cross-view consistency. We validate AdvScene using real-world physical data and conduct a comprehensive evaluation of existing adversarial patches. Our results show that AdvScene reveals substantial scene-dependent variation in attack effectiveness that is not captured by existing image-centric or simulator-based evaluations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。