发表机构
The University of Alabama at Birmingham; Texas A&M University(阿拉巴马大学伯明翰分校; 德克萨斯农工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出几何感知对抗攻击框架,将对比系统攻击转化为流形层面关系破坏,训练轻量级生成器实现实时攻击,使Markmatch验证系统准确率从95.4%降至38.6%并反转正负样本相似性结构。
AI 中文摘要
对比学习和连体(Siamese)嵌入模型已成为现代验证系统的基础,其决策并非由离散分类边界控制,而是由嵌入空间中的关系几何控制。然而,现有对抗攻击从根本上仍以分类为中心,忽视了关系几何的脆弱性。本文提出一种几何感知的对抗攻击框架,将对比系统的攻击重新表述为流形层面的关系破坏。该框架不针对单个预测,而是通过将正样本对推开、同时将负样本对拉近,系统性地扭曲嵌入流形内的相似性组织,最终使成对相似性结构崩溃并反转。为实现可扩展部署,我们将迭代在线优化转移到离线对抗几何变形先验学习阶段,训练一个轻量级前馈生成器,从目标模型中学习通用几何变形模式。训练完成后,该生成器仅需一次前向传播即可生成对抗扰动,无需在线梯度计算,可对基于相似性的验证系统实施实时在线攻击。在多个验证架构上的实验结果表明,该攻击会导致验证性能大幅下降,同时伴随严重的流形层面关系破坏。在Markmatch验证系统上,所提攻击将准确率从95.4%降至38.6%,同时完全反转了正负样本的相似性结构。
英文摘要
Contrastive learning and Siamese embedding models have become the foundation of modern verification systems, where decisions are governed not by discrete classification boundaries, but by relational geometry in embedding space. However, existing adversarial attacks remain fundamentally classification-centric, overlooking the vulnerability of relational geometry. In this paper, we introduce a geometry-aware adversarial attack framework that reformulates attacks on contrastive systems as manifold-level relational corruption. Instead of targeting individual predictions, the proposed framework systematically distorts similarity organization within the embedding manifold by pushing positive pairs apart while simultaneously pulling negative pairs closer, ultimately collapsing and inverting pairwise similarity structure. To enable scalable deployment, we shift iterative online optimization into an offline adversarial geometry deformation prior learning stage and train a lightweight feed-forward generator that learns generalized geometry deformation patterns from the victim model. Once trained, the generator produces adversarial perturbations through a single forward pass without requiring online gradient computation, enabling real-time online attacks against similarity-based verification systems. Experimental results across multiple verification architectures demonstrate substantial degradation of verification performance together with severe manifold-level relational corruption. On the Markmatch verification system, the proposed attack reduces accuracy from 95.4% to 38.6% while completely reversing the positive-negative similarity structure.