发表机构
University of Maryland, College Park; University of Edinburgh; WMG, University of Warwick; Wuhan University(马里兰大学学院公园分校; 爱丁堡大学; 华威大学WMG; 武汉大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出在对抗性图像生成中引入次要视觉元素“载体”,以吸收攻击更新并保持主体完整,同时增强跨模型迁移性和攻击有效性。
AI 中文摘要
强无限制对抗攻击可能会扭曲图像的主要对象,以下简称主体。为了在不牺牲攻击强度的情况下保持主体完整性,我们引入了载体:一种次要视觉元素,提供辅助区域以在全局分类器引导下促进攻击。我们展示了三个关键发现:1. 载体通过吸收更大份额的全局归一化攻击更新来减轻主体扭曲。2. 载体改善了跨模型迁移性,这由目标相关特征的强度决定,这些特征平衡了语义分离和迁移性能。3. 成功的定向攻击保留了人类感知的主要内容的个性化主体,同时成功误导了分类器。我们的结果表明,视觉上次要的载体为对抗性变化提供了辅助空间路径,使得攻击强大且可迁移,同时改善了主体保持。
英文摘要
Strong unrestricted adversarial attacks can distort the primary object of an image, hereafter referred to as the subject. To preserve subject integrity without compromising attack magnitude, we introduce the carrier: a secondary visual element that provides an auxiliary region to facilitate the attack under global classifier guidance. We demonstrate three key findings: 1. A carrier mitigates subject distortion by absorbing a larger share of globally normalized attack updates. 2. A carrier improves cross-model transferability, governed by the strength of target-related features that balance semantic separation and transfer performance. 3. Successful targeted attacks retain the personalized subject as the primary content perceived by humans while successfully misleading the classifier. Our results demonstrate that a visually secondary carrier offers an auxiliary spatial pathway for adversarial changes, enabling strong and transferable attacks while improving subject preservation.