Proximal Splitting Adversarial Attack for Semantic Segmentation
Jérôme Rony, Jean-Christophe Pesquet, Ismail Ben Ayed
Abstract
Classification has been the focal point of research on adversarial attacks, but only a few works investigate methods suited to denser prediction tasks, such as semantic segmentation. The methods proposed in these works do not accurately solve the adversarial segmentation problem and, therefore, overestimate the size of the perturbations required to fool models. Here, we propose a white-box attack for these models based on a proximal splitting to produce adversarial perturbations with much smaller ℓ ∞ norms. Our attack can handle large numbers of constraints within a nonconvex minimization framework via an Augmented Lagrangian approach, coupled with adaptive constraint scaling and masking strategies. We demonstrate that our attack significantly outperforms previously proposed ones, as well as classification attacks that we adapted for segmentation, providing a first comprehensive benchmark for this dense task.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- CosPGD: an efficient white-box adversarial attack for pixel-wise prediction tasksShashank Agnihotri, Steffen Jung, Margret KeuperICML 2024 · 35 citations
- RP-PGD: Boosting Segmentation Robustness with a Region-and-Prototype Based Adversarial AttackYuxuan Zhang, Zhenbo Shi, Shuchang Wang, Wei Yang et al.AAAI 2025 · 4 citations
- AAKR: Adversarial Attack-based Knowledge Retention for Continual Semantic SegmentationZhidong Yu, Xiaoman Liu, Jiajun Hu, Zhenbo Shi et al.AAAI 2025 · 1 citation
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- SegFormer: Simple and Efficient Design for Semantic Segmentation with TransformersEnze Xie, Wenhai Wang, Zhiding Yu, Anima Anandkumar et al.NeurIPS 2021 · 9,661 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
- Dynamic Divide-and-Conquer Adversarial Training for Robust Semantic SegmentationXiaogang Xu, Hengshuang Zhao, Jiaya JiaICCV 2021 · 47 citations
Related papers
- Augmented Lagrangian Adversarial AttacksJérôme Rony, Eric Granger, Marco Pedersoli, Ismail Ben AyedICCV 2021 · 45 citations
- Towards Efficient Training and Evaluation of Robust Models against l0 Bounded Adversarial PerturbationsXuyang Zhong, Yixiao Huang, Chen LiuICML 2024 · 3 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- Ensemble-based Blackbox Attacks on Dense PredictionZikui Cai, Yaoteng Tan, M. Salman AsifCVPR 2023
- PAT: Geometry-Aware Hard-Label Black-Box Adversarial Attacks on TextMuchao Ye, Jinghui Chen, Chenglin Miao, Han Liu et al.KDD 2023 · 8 citations
