arXiv:2609.03453cs.CVcs.CR2026-09

深度可分离模型中预处理防御失效,但可用来检测攻击。

Preprocessing Failure and Adversarial Detection in Depthwise-Separable Edge Vision Systems

  • 在边缘视觉系统中测试六种预处理防御,发现深度可分离架构恢复能力差。
  • 对抗样本下预处理能破坏正常图像预测,却保留攻击图像预测,形成检测信号。
  • 传统图像质量指标无法准确评估防御效果,需新评估方法。

基于预处理的防御是边缘视觉系统应对对抗攻击的标准第一道防线,无需重训练或结构修改,被广泛视为模型无关的缓解手段。然而,这些防御的有效性评估多基于残差或Inception类网络,而非主导边缘部署的深度可分离卷积神经网络。本文填补了这一空白,对比评估了六种预处理防御在两种架构上的表现。结果显示,在所有扰动水平和防御策略下,深度可分离架构均表现出持续的恢复失败,而残差架构则有部分恢复;消融实验表明问题源于架构而非参数差异,尽管仅测试了三种架构和一种攻击类型。关键的是,这种失败不仅是负面结果:预处理对正常预测的破坏与对对抗预测的保留之间存在明显不对称,该特性可直接用于检测攻击,无需重训练或结构改动。此外,本文揭示当前评估中常用图像质量指标不可靠,暴露方法论缺陷。最后,提出面向边缘视觉安全部署的实践决策框架。

原文摘要 · Abstract (English)

Preprocessing-based defenses are the standard first-line response to adversarial attacks on edge vision systems, requiring no retraining, no architectural changes, and widely recommended as model-agnostic mitigations. Yet the foundational evaluations of these defenses were conducted on residual or Inception-class architectures, not on the depthwise-separable CNNs that dominate edge deployments. This untested assumption leaves a gap in the security evaluation literature. This paper closes that gap by evaluating six preprocessing defenses against adversarial perturbations across both architecture families. Across all perturbation levels and defenses tested, the two depthwise-separable architectures show consistently poor recovery while the residual architecture shows partial recovery; ablation results are consistent with an architectural rather than parametric explanation, though only three architectures and one attack family are evaluated. Crucially, this failure is not merely a negative result. The same output divergence that disqualifies preprocessing as a recovery mechanism reveals a detection opportunity: preprocessing consistently disrupts clean predictions while leaving adversarial predictions largely unchanged, an asymmetry that is directly measurable without retraining or architectural modification. We further show that standard image quality metrics are unreliable proxies for defense effectiveness, a methodological gap in current evaluation practice. A practitioner decision framework is provided for adversarially resilient edge vision deployment.

对抗攻击边缘计算防御检测深度可分离

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。