arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.00125cs.CRcs.CV

单像素攻击综述:研究现状、分类法、应用、监管政策与未来方向

A Comprehensive Review of One-Pixel Attack: Research Status, Taxonomy, Applications, Regulation Policy and Future Directions

  • Bangladesh University of Business and Technology(孟加拉国商业与技术大学)
  • Universiti Sains Malaysia(马来西亚理科大学)
  • Universität Bremen(不来梅大学)
  • University of Asia Pacific(亚太大学)

机构由 AI 辅助整理,请以论文原文为准。

Mirza Niaz Morshed, Md. Masudul Islam, Galib Muhammad Shahriar Himel, Md. Aslam Uddin, Hui Liu, Md. Shafiqul Islam

AI总结:

本综述系统梳理单像素攻击的研究现状,提出多轴分类法,总结防御范式,并展望未来方向与监管框架,为理解与缓解超稀疏对抗威胁奠定基础。

AI中文摘要:

单像素攻击(One-Pixel Attacks, OPAs)是深度学习对抗脆弱性最极端的演示之一,其中修改单个像素即可可靠地诱导跨领域的高置信度错误分类,这些领域包括医学诊断、自动驾驶、生物识别和量子通信。尽管其概念简单,但在现有的对抗攻击综述中,OPAs 仍未得到充分审视,现有综述仅提供零散或粗略的覆盖。本项基于 PRISMA 指南的综述综合了 2017 年至 2026 年的高质量研究,并提供了 OPA 研究的统一、多轴分类法,涵盖算法基础、黑盒进化优化、新兴的混合与程序合成攻击、防御机制、可解释性工具以及特定领域的脆弱性。我们的分析揭示了基于差分进化(Differential Evolution)策略的主导地位、效率优化和显著性引导方法的兴起,以及数据集多样性、可迁移性和标准化评估方面的持续空白。我们总结并评估了防御范式,包括像素恢复、异常检测、输入空间变换和鲁棒训练,强调了它们在鲁棒性、不可感知性和计算开销方面的权衡。基于这些见解,我们概述了未来研究重点,涉及选择性像素恢复、Transformer 特定脆弱性分析、显著性驱动优化以及现实世界领域自适应防御。我们进一步提出了一个监管框架,强调鲁棒性测试、事件披露和 AI 安全治理。本综述为理解、评估和缓解当代 AI 系统中的超稀疏对抗威胁奠定了全面基础。

英文摘要:

One-Pixel Attacks (OPAs) represent one of the most extreme demonstrations of adversarial fragility in deep learning, where modifying a single pixel can reliably induce high-confidence misclassification across domains such as medical diagnosis, autonomous driving, biometrics, and quantum communication. Despite their conceptual simplicity, OPAs remain underexamined in existing adversarial-attack surveys, which provide only fragmented or cursory coverage. This PRISMA-guided review synthesizes high-quality studies from 2017 to 2026 and delivers a unified, multi-axis taxonomy of OPA research spanning algorithmic foundations, black-box evolutionary optimization, emerging hybrid and program-synthesis attacks, defence mechanisms, interpretability tools, and domain-specific vulnerabilities. Our analysis reveals the dominance of Differential Evolution-based strategies, the rise of efficiency-optimized and saliency-guided methods, and persistent gaps in dataset diversity, transferability, and standardized evaluation. We summarized and assess defence paradigms including pixel restoration, anomaly detection, input-space transformations, and robust training highlighting their trade-offs in robustness, imperceptibility, and computational overhead. Building on these insights, we outline future research priorities involving selective pixel recovery, transformer-specific vulnerability analysis, saliency-driven optimization, and real-world domain-adaptive defences. We further propose a regulatory framework emphasizing robustness testing, incident disclosure, and AI security governance. This review establishes a comprehensive foundation for understanding, evaluating, and mitigating ultra-sparse adversarial threats in contemporary AI systems.

补充信息

↑