arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.03453cs.CVcs.CR

深度可分离边缘视觉系统中的预处理失效与对抗检测

Preprocessing Failure and Adversarial Detection in Depthwise-Separable Edge Vision Systems

  • Bangladesh University of Business and Technology(孟加拉国孟加拉商业与技术大学)
  • University of New South Wales(新南威尔士大学)

机构由 AI 辅助整理,请以论文原文为准。

Jannatul Masruk Mukta, Rifa Sanjida, Adrita Rahman Tory, Md. Saifur Rahman, Khondokar Fida Hasan

AI总结:

本文针对边缘部署主流的深度可分离CNN,评估了六种预处理防御的对抗攻击恢复效果,发现其持续失效,且预处理可通过输出差异检测对抗样本,还指出图像质量指标不可靠并提供了部署决策框架。

AI中文摘要:

基于预处理的防御是应对边缘视觉系统对抗攻击的标准一线响应,无需重新训练、无需修改架构,作为与模型无关的缓解措施被广泛推荐。然而,这些防御的基础评估是在残差网络或Inception类架构上进行的,而非在边缘部署中占主导地位的深度可分离卷积神经网络(CNN)上开展。这一未经验证的假设在安全评估文献中留下了空白。本文通过在两类架构上评估六种预处理防御对对抗扰动的效果,填补了这一空白。在所有测试的扰动水平和防御措施下,两种深度可分离架构均表现出持续较差的恢复效果,而残差架构则表现出部分恢复; ablation(消融)结果与架构而非参数解释一致,尽管仅评估了三种架构和一类攻击。关键的是,这种失效并非仅仅是负面结果:使预处理无法作为恢复机制的相同输出差异,揭示了一种检测机会——预处理会持续干扰干净样本的预测,同时基本保留对抗样本的预测不变,这种不对称性无需重新训练或修改架构即可直接测量。我们进一步表明,标准图像质量指标是防御有效性的不可靠代理,这是当前评估实践中的一个方法学缺口。本文提供了一个从业者决策框架,用于实现对抗鲁棒的边缘视觉部署。

英文摘要:

Preprocessing-based defenses are the standard first-line response to adversarial attacks on edge vision systems, requiring no retraining, no architectural changes, and widely recommended as model-agnostic mitigations. Yet the foundational evaluations of these defenses were conducted on residual or Inception-class architectures, not on the depthwise-separable CNNs that dominate edge deployments. This untested assumption leaves a gap in the security evaluation literature. This paper closes that gap by evaluating six preprocessing defenses against adversarial perturbations across both architecture families. Across all perturbation levels and defenses tested, the two depthwise-separable architectures show consistently poor recovery while the residual architecture shows partial recovery; ablation results are consistent with an architectural rather than parametric explanation, though only three architectures and one attack family are evaluated. Crucially, this failure is not merely a negative result. The same output divergence that disqualifies preprocessing as a recovery mechanism reveals a detection opportunity: preprocessing consistently disrupts clean predictions while leaving adversarial predictions largely unchanged, an asymmetry that is directly measurable without retraining or architectural modification. We further show that standard image quality metrics are unreliable proxies for defense effectiveness, a methodological gap in current evaluation practice. A practitioner decision framework is provided for adversarially resilient edge vision deployment.

补充信息

↑