arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.35022cs.CV

基于频谱特征的超分辨率模型对抗攻击检测

Detection of Adversarial Attacks on Super-Resolvers Using Spectral Features

  • Oak Ridge National Laboratory(橡树岭国家实验室)

机构由 AI 辅助整理,请以论文原文为准。

Emma J. Reid, Haley Duba-Sullivan, Tony G. Allen

AI总结:

本文提出基于径向平均功率谱密度的XGBoost检测器,用于识别超分辨率模型权重中的对抗攻击,在多数训练和跨架构场景中优于幅度和相位傅里叶频谱检测器,并发现高频特征对检测最具信息量。

AI中文摘要:

深度学习模型在图像预处理流程(如超分辨率)中的集成,为针对下游任务的攻击者引入了一个很大程度上未被探索的攻击向量。为了确保关键成像流程的可信度,我们必须能够检测预处理模型中的对抗行为。在本文中,我们提出了一种基于频谱的检测方法,用于识别嵌入在超分辨率模型权重中的对抗攻击。更具体地说,我们使用径向平均功率谱密度作为判别特征来训练极端梯度提升(XGBoost)检测器,证明了在超分辨率网络中检测模型级威胁的能力。我们进一步将我们的检测器与基于幅度和相位的傅里叶频谱检测器进行基准比较,在多种训练和跨架构场景中评估每种方法。我们提出的检测器在大多数场景中优于对比检测器,并表明高频特征对于检测跨超分辨率架构的AdvSR攻击最具信息量。

英文摘要:

The integration of deep learning models into image preprocessing pipelines such as super-resolution introduces a largely unexplored attack vector for adversaries targeting downstream tasks. To ensure trustworthiness of critical imaging pipelines, we must be able to detect adversarial behavior within preprocessing models. In this paper, we propose a spectral-based detection method for identifying adversarial attacks embedded in super-resolution model weights. More specifically, we use the radially-averaged power spectral density as a discriminative feature to train an extreme gradient boosting (XGBoost) detector, demonstrating detectability of model-level threats in super-resolution networks. We further benchmark our detector against magnitude- and phase-based Fourier spectrum detectors, evaluating each method across a range of training and cross-architecture scenarios. Our proposed detector out-performs the comparison detectors in most of these scenarios and indicates that high-frequency features are most informative for detecting AdvSR attacks across SR architectures.

补充信息

↑