arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

攻击难度能否在优化之前被刻画?针对人物消失攻击的优化前难度研究

Can Attack Difficulty Be Characterized Before Optimization? A Study of Pre-optimization Difficulty in Person-Vanishing Attacks

Jingyao Xu, Dongdong Wang, Siyang Lu

arXiv 2609.34501首次发表:更新:

发表机构

Beijing Jiaotong University; University of Florida(北京交通大学; 佛罗里达大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出优化前攻击难度概念及Quad-CLEVER估计器,证明攻击难度可在优化前预测,并据此构建难度感知攻击框架,在固定预算下提升攻击成功率并降低计算成本。

AI 中文摘要

针对目标检测器的对抗攻击传统上是从优化角度研究的,其中攻击难度被视为仅在对抗优化之后才能观察到的结果。这引出了一个基本问题:不同输入的相对攻击难度能否在优化开始之前就被刻画?在本文中,我们通过引入优化前攻击难度的概念来研究人物消失攻击中的这一问题,该概念捕捉了不同输入图像在优化努力上的内在差异。为了在优化前估计这一潜在难度,我们提出了Quad-CLEVER,一种基于几何的估计器,它源自沿最相关攻击方向对局部人物消失边距的二次近似。跨多种攻击算法的广泛实验表明,Quad-CLEVER与观察到的优化成本持续相关,为攻击难度具有可预测的优化前结构提供了经验证据。基于这一发现,我们进一步提出了一种难度感知攻击框架,该框架利用估计的难度在固定计算预算下为基础攻击自适应地分配优化预算。在BDD100K上,所提出的框架将图像级攻击成功率提高了高达5.78%,同时将平均优化成本降低了多达11.42次迭代。在更具挑战性的EventPed数据集上,它节省了2.25次优化迭代,同时保持了相当的攻击性能。这些结果表明,攻击难度可以在优化前被有意义地估计,并且利用这些估计能够实现更计算高效的对抗攻击。

英文摘要

Adversarial attacks against object detectors are traditionally studied from an optimization perspective, where attack difficulty is regarded as an outcome observed only after adversarial optimization. This raises a fundamental question: \emph{can the relative attack difficulty of different inputs be characterized before optimization begins?} In this paper, we investigate this question for person-vanishing attacks by introducing the concept of pre-optimization attack difficulty, which captures intrinsic differences in optimization effort across input images. To estimate this latent difficulty before optimization, we propose Quad-CLEVER, an efficient geometry-based estimator derived from a quadratic approximation of the local person-vanishing margin along the most attack-relevant direction. Extensive experiments across multiple attack algorithms demonstrate that Quad-CLEVER consistently correlates with the observed optimization cost, providing empirical evidence that attack difficulty exhibits a predictable pre-optimization structure. Building upon this finding, we further propose a difficulty-aware attack framework that leverages the estimated difficulty to adaptively allocate optimization budgets for a base attack under a fixed computational budget. On BDD100K, the proposed framework improves the image-level attack success rate by up to 5.78$\%$ while reducing the average optimization cost by up to 11.42 iterations. On the more challenging EventPed dataset, it saves 2.25 optimization iterations while maintaining comparable attack performance. These results demonstrate that attack difficulty can be meaningfully estimated before optimization and that exploiting such estimates enables more computationally efficient adversarial attacks.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑