arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

IGME:用于可迁移语义分割攻击的高效链式方法集成

IGME: Efficient Chained Method Ensemble for Transferable Semantic Segmentation Attacks

Mengqi He, Jing Zhang

arXiv 2607.27465首次发表:更新:

AI 中文总结

本文提出仅需单个源模型的IGME方法,通过链式可微攻击组件共享梯度计算,结合路径平均方向稳定更新,在语义分割攻击中实现了可迁移性与效率的良好平衡。

AI 中文摘要

语义分割模型易受可迁移对抗扰动影响,但对密集预测模型评估迁移攻击的计算成本很高。现有集成攻击通常依赖多个代理模型,增加了计算成本,对分割任务而言更甚。本文研究针对语义分割可迁移攻击的高效单源替代方案,将可迁移攻击组合建模为可微攻击组件上的链式计算,让昂贵的源模型梯度计算可被共享。为降低链式组合带来的更新不稳定性,进一步采用集成梯度风格的路径平均方向作为经验稳定启发式方法。在Pascal VOC和Cityscapes上的实验,评估了该方法在CNN和基于Transformer的分割模型间的可迁移性与效率权衡。IGME仅需访问一个源模型,与单源基线相比实现了有竞争力的可迁移性,与模型集成攻击相比具有更优的运行时间。

英文摘要

Semantic segmentation models are vulnerable to transferable adversarial perturbations, yet evaluating transfer attacks on dense prediction models can be computationally expensive. Existing ensemble attacks often rely on multiple surrogate models, increasing the computation cost, even harder for segmentation. This paper studies an efficient single-source alternative for transferable attacks on semantic segmentation. We formulate transferable attack composition as a chained computation over differentiable attack components, allowing the expensive source-model gradient computation to be shared. To reduce the update instability introduced by chained composition, we further use an integrated-gradient-style path-averaged direction as an empirical stabilization heuristic. Experiments on Pascal VOC and Cityscapes evaluate the resulting transferability efficiency trade-off across CNN- and transformer-based segmentation models. IGME achieves competitive transferability compared with single-source baselines and favorable runtime compared with model-ensemble attacks, while requiring access to only one source model.

Comments8 pages, 3 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑