DarkSAM: Fooling Segment Anything Model to Segment Nothing
Ziqi Zhou, Yufei Song, Minghui Li, Shengshan Hu, Xianlong Wang, Leo Yu Zhang, Dezhong Yao, Hai Jin
Abstract
Segment Anything Model (SAM) has recently gained much attention for its outstanding generalization to unseen data and tasks. Despite its promising prospect, the vulnerabilities of SAM, especially to universal adversarial perturbation (UAP) have not been thoroughly investigated yet. In this paper, we propose DarkSAM, the first prompt-free universal attack framework against SAM, including a semantic decoupling-based spatial attack and a texture distortion-based frequency attack. We first divide the output of SAM into foreground and background. Then, we design a shadow target strategy to obtain the semantic blueprint of the image as the attack target. DarkSAM is dedicated to fooling SAM by extracting and destroying crucial object features from images in both spatial and frequency domains. In the spatial domain, we disrupt the semantics of both the foreground and background in the image to confuse SAM. In the frequency domain, we further enhance the attack effectiveness by distorting the high-frequency components (i.e., texture information) of the image. Consequently, with a single UAP, DarkSAM renders SAM incapable of segmenting objects across diverse images with varying prompts. Experimental results on four datasets for SAM and its two variant models demonstrate the powerful attack capability and transferability of DarkSAM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a5d9ff35-2158-4f44-95dd-ec45890ebc03Cited by top-tier papers12
- Transferable Adversarial Attacks on SAM and Its Downstream ModelsSong Xia, Wenhan Yang, Yi Yu, Xun Lin et al.NeurIPS 2024 · 29 citations
- AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied AgentsYichen Wang, Hangtao Zhang, Hewen Pan, Ziqi Zhou et al.NeurIPS 2025 · 27 citations
- Unlearnable 3D Point Clouds: Class-wise Transformation Is All You NeedXianlong Wang, Minghui Li, Wei Liu, Hangtao Zhang et al.NeurIPS 2024 · 23 citations
- Vanish into Thin Air: Cross-prompt Universal Adversarial Attacks for SAM2Ziqi Zhou, Yifan Hu, Yufei Song, Zijing Li et al.NeurIPS 2025 · 17 citations
- When Robots Obey the Patch: Universal Transferable Patch Attacks on Vision-Language-Action ModelsHui Lu, Yi Yu, Yiming Yang, Chenyu Yi et al.CVPR 2026 · 12 citations
Builds on11
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Segment AnythingAlexander Kirillov, Eric Mintun, Nikhila Ravi, Hanzi Mao et al.ICCV 2023 · 13,211 citations
- Segment Anything in High QualityLei Ke, Mingqiao Ye, Martin Danelljan, Yifan Liu et al.NeurIPS 2023 · 709 citations
- Personalize Segment Anything Model with One ShotRenrui Zhang, Zhengkai Jiang, Ziyu Guo, Shilin Yan et al.ICLR 2024 · 333 citations
- AdvCLIP: Downstream-agnostic Adversarial Examples in Multimodal Contrastive LearningZiqi Zhou, Shengshan Hu, Minghui Li, Hangtao Zhang et al.ACM MM 2023 · 62 citations
Related papers
- Unsegment Anything by Simulating DeformationJiahao Lu, Xingyi Yang, Xinchao WangCVPR 2024 · 1 citation
- Robust SAM: On the Adversarial Robustness of Vision Foundation ModelsJiahuan Long, Zhengqin Xu, Tingsong Jiang, Wen Yao et al.AAAI 2025 · 5 citations
- Creating Blank Canvas Against AI-enabled Image ForgeryQi Song, Ziyuan Luo, Renjie WanAAAI 2026
- Stable Segment Anything ModelQi Fan, Xin Tao, Lei Ke, Mingqiao Ye et al.ICLR 2025 · 1 citation
- MaskSAM: Auto-Prompt SAM with Mask Classification for Volumetric Medical Image SegmentationBin Xie, Hao Tang, Bin Duan, Dawen Cai et al.ICCV 2025 · 7 citations
