用于SAM3图像分割的通用概念干扰
Universal Concept Disruption for SAM3 Image Segmentation
浏览论文内容
中文总结 AI 辅助
针对SAM3图像分割的对抗鲁棒性空白,提出通用概念干扰(UCD)攻击方法,在多数据集上显著降低SAM3的分割性能,且扰动可跨SAM3.1及视频推理迁移,仅有限恢复。
中文摘要 AI 辅助
SAM3将可提示的分割从几何驱动的掩码预测扩展到开放词汇概念分割,其中文本条件接地模型会判断某个概念是否存在并分割所有匹配实例。尽管这种存在门控设计提升了概念级预测能力,但其对抗鲁棒性仍未被探索。本文提出通用概念干扰(Universal Concept Disruption, UCD),这是首个专为SAM3图像分割定制的通用跨概念对抗攻击方法。UCD从(图像、名词短语)对中学习单个有界图像扰动,将SAM3作为集成概念接地系统进行攻击,它会联合破坏文本条件输入路径,最大化提示共享视觉特征的差异,抑制最终存在门控的概念分数,并通过面积坍塌和干净掩码的Dice干扰破坏保留掩码的空间有效性。在SACo-Gold、LVIS、RefCOCO、PhraseCut和OpenImages数据集上,UCD在匹配评估协议下始终优于所有基线方法,将平均掩码AP从59.43降至18.73,平均cgF1从50.32降至20.49。学习到的扰动还可在不重新优化的情况下迁移到SAM3.1和SAM3视频推理,而提示集成、轻量级头部微调及时序滤波仅能提供有限的恢复效果。
英文摘要
SAM3 extends promptable segmentation from geometry-driven mask prediction to open-vocabulary concept segmentation, where a text-conditioned grounding model decides whether a concept is present and segments all matching instances. While this presence-gated design improves concept-level prediction, its adversarial robustness remains unexplored. In this paper, we introduce Universal Concept Disruption (UCD), the first universal cross-concept adversarial attack tailored to SAM3 image segmentation. UCD learns a single bounded image perturbation from (image, noun-phrase) pairs and attacks SAM3 as an integrated concept-grounding system. It jointly disrupts the text-conditioned input path, maximizes divergence in prompt-shared visual features, suppresses the final presence-gated concept scores, and corrupts the spatial validity of retained masks through area collapse and clean-mask Dice disruption. Across SACo-Gold, LVIS, RefCOCO, PhraseCut, and OpenImages datasets, UCD consistently outperforms all baselines under a matched evaluation protocol, reducing average mask AP from 59.43 to 18.73 and average cgF1 from 50.32 to 20.49. The learned perturbation also transfers to SAM3.1 and to SAM3 video inference without re-optimization, while prompt ensembling, lightweight head fine-tuning, and temporal filtering provide limited recovery.