arXiv:2608.04314cs.CRcs.CV2026-08综述

用对抗扰动保护视觉内容,防滥用、控访问、追溯源。

Adversarial Attacks for Good: A Survey of Proactive Protection across the Visual Content Lifecycle

论文配图:Adversarial Attacks for Good: A Survey of Proactive Protection across the Visual Content Lifecycle
图 1 · 摘自论文原文
  • 数据主人用对抗扰动干扰未经授权的自动化使用。
  • 五类保护机制覆盖分享、训练、编辑、访问、溯源全生命周期。
  • 适合关注内容安全与版权保护的研究者和平台开发者。

视觉内容一旦进入人工智能处理流程,其所有者往往难以控制使用方式。法律手段可事后追责,但技术防护需在内容发布或访问阶段提前介入。本文综述了这一干预点上的保护范式——"对抗攻击为善":原本用于攻击模型的扰动与结构化信号,被内容所有者、创作者、平台或审计方用于破坏未经授权的自动化行为,或支持后续责任追溯。五个研究领域独立发展出不同阶段的防护方案:分享时的隐私滤波、训练时的不可学习样本、生成时的防护机制、访问时的对抗验证码、传播后的溯源系统。尽管各领域标准不一,但均利用人类感知、语义理解与机器推理之间的差异,表明该范式在多模态模型和自主代理演进中仍具价值。我们从迁移性、适应性和部署成熟度三方面评估各方法,发现多数防护仍仅针对静态或弱适应性对手,真实场景证据稀缺。最后提出跨阶段协同防御与开放问题,推动可鲁棒、可组合、可部署的主人端保护体系。

原文摘要 · Abstract (English)

Once visual content enters an AI pipeline, its owner often retains little technical control over how it is used. Legal and regulatory remedies can address misuse, but many technical interventions must be applied earlier, when content is released or accessed. This survey examines the protective paradigm that has grown around this intervention point, which we call \emph{adversarial attacks for good}. Perturbations and structured signals long studied as attacks on learned models are instead applied by data owners, creators, platforms, or auditors to disrupt unauthorized automation or support later accountability. Five research communities have arrived at this inversion largely independently, each addressing a different stage of a visual asset's lifecycle: privacy filters against unwanted recognition at sharing time, unlearnable examples against unauthorized training, generative safeguards against malicious editing or imitation, adversarial CAPTCHAs for access control against automated agents, and provenance mechanisms for post-circulation attribution. Although developed in separate venues with incompatible success criteria, many of these methods exploit persistent gaps between human perception, semantic interpretation, and machine inference, suggesting that the paradigm remains relevant as visual pipelines evolve toward multimodal models and autonomous agents. To make their claims comparable, we evaluate all five families along shared axes of transferability, adaptability, and deployment readiness. Across the lifecycle, we find that most protections are still validated mainly against static or weakly adaptive adversaries, while evidence beyond controlled benchmarks remains scarce. We close by consolidating cross-stage countermeasures and open problems for robust, composable, and deployable owner-side protection.

对抗攻击内容安全版权保护生命周期防护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。