arXiv:2607.17077cs.CVcs.AI2026-07

ALLUDE统一评估视觉模型对抗攻击,支持多场景自定义配置。

ALLUDE: A Unified Evaluation System for Configurable Attacks in Differentiable Environments

论文配图:ALLUDE: A Unified Evaluation System for Configurable Attacks in Differentiable Environments
图 1 · 摘自论文原文
  • 基于可微渲染构建统一评估系统,支持多环境参数配置
  • 从5400种配置中采样测试,发现所有攻击在复杂条件下成功率下降
  • 跨平台开源,适合研究真实部署环境下攻击鲁棒性

针对视觉模型(如目标检测器)的对抗攻击常在有限条件下评估,导致性能刻画不充分。结合仿真与可微渲染,可实现更稳健的端到端评估,但目前尚无易用的统一系统,能对多种场景、物体、环境光照条件及相机轨迹进行灵活配置。本文提出ALLUDE,首次实现跨平台(Linux与Windows)的统一评估能力。通过双策略验证其评估广度:(1) 使用拉丁超立方采样,从10个场景-物体组合、9种天气条件、4种优化器、5条相机轨迹和3个检测模型组成的5400种配置中选取代表性子集;(2) 在多样天气与连续相机轨迹下压力测试现有攻击(CAMOU、RAUCA、FCA),均发现攻击成功率显著下降,揭示了以往评估的不足。借助ALLUDE的端到端可微渲染,对抗攻击可针对动态现实部署条件进行优化。代码已开源。

原文摘要 · Abstract (English)

Adversarial attacks against vision models like object detectors are often evaluated under limited conditions, leaving their performance under-characterized. Bridging simulation and differentiable rendering enables more robust, end-to-end evaluation of these adversarial attacks, yet there is no easy-to-use, unified system that offers a rich set of customizable configurations for adversarial attacks across multiple scenes, objects, environmental and lighting conditions, and camera trajectories. We present ALLUDE, which addresses these gaps, offering first-of-its-kind evaluation capabilities across Linux and Windows. We comprehensively demonstrate ALLUDE's evaluation breadth through a two-pronged strategy: (1) using Latin Hypercube Sampling, we draw a representative subset from 5,400 configurations spanning 10 scene-object pairs, 9 weather conditions, 4 optimizers, 5 camera trajectories, and 3 detection models; (2) we stress-test existing attacks (CAMOU, RAUCA, FCA) under diverse weather conditions and continuous camera trajectories, revealing degradation of attack success across every attack, exposing evaluation gaps in prior work. Through ALLUDE's end-to-end differentiable rendering, adversarial attacks can be optimized against shifting real-world deployment conditions. Our cross-platform code is open source.

对抗攻击可微渲染评估系统目标检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。