BREPS: Bounding-Box Robustness Evaluation of Promptable Segmentation
Andrey Moskalenko, Danil Kuznetsov, Irina Dudko, Anastasiia Iasakova, Nikita Boldyrev, Denis Shepelev, Andrei Spiridonov, Andrey Kuznetsov, Vlad Shakhuro
Abstract
Promptable segmentation models such as SAM have established a powerful paradigm, enabling strong generalization to unseen objects and domains with minimal user input, including points, bounding boxes, and text prompts. Among these, bounding boxes stand out as particularly effective, often outperforming points while significantly reducing annotation costs. However, current training and evaluation protocols typically rely on synthetic prompts generated through simple heuristics, offering limited insight into real-world robustness. In this paper, we investigate the robustness of promptable segmentation models to natural variations in bounding box prompts. First, we conduct a controlled user study and collect thousands of real bounding box annotations. Our analysis reveals substantial variability in segmentation quality across users for the same model and instance, indicating that SAM-like models are highly sensitive to natural prompt noise. Then, since exhaustive testing of all possible user inputs is computationally prohibitive, we reformulate robustness evaluation as a white-box optimization problem over the bounding box prompt space. We introduce BREPS, a method for generating adversarial bounding boxes that minimize or maximize segmentation error while adhering to naturalness constraints. Finally, we benchmark state-of-the-art models across 10 datasets, spanning everyday scenes to medical imaging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on8
- Distance-IoU Loss: Faster and Better Learning for Bounding Box RegressionZhaohui Zheng, Ping Wang, Wei Liu, Jinze Li et al.AAAI 2020 · 4,823 citations
- Segment Anything in High QualityLei Ke, Mingqiao Ye, Martin Danelljan, Yifan Liu et al.NeurIPS 2023 · 709 citations
- SimpleClick: Interactive Image Segmentation with Simple Vision TransformersQin Liu, Zhenlin Xu, Gedas Bertasius, Marc NiethammerICCV 2023 · 161 citations
- FocalClick: Towards Practical Interactive Image SegmentationXi Chen, Zhiyan Zhao, Yilei Zhang, Manni Duan et al.CVPR 2022 · 153 citations
- DarkSAM: Fooling Segment Anything Model to Segment NothingZiqi Zhou, Yufei Song, Minghui Li, Shengshan Hu et al.NeurIPS 2024 · 44 citations
Related papers
- ProSAM: Enhancing the Robustness of Sam-Based Visual Reference Segmentation with Probabilistic PromptsXiaoqi Wang, Clint Sebastian, Wenbin He, Liu RenICCV 2025 · 1 citation
- Stable Segment Anything ModelQi Fan, Xin Tao, Lei Ke, Mingqiao Ye et al.ICLR 2025 · 1 citation
- BLO-SAM: Bi-level Optimization Based Finetuning of the Segment Anything Model for Overfitting-Preventing Semantic SegmentationLi Zhang, Youwei Liang, Ruiyi Zhang, Amirhosein Javadi et al.ICML 2024 · 14 citations
- Attack for Defense: Adversarial Agents for Point Prompt Optimization Empowering Segment Anything ModelXueyu Liu, Xiaoyi Zhang, Meilin Liu, Guangze Shi et al.CVPR 2026 · 1 citation
- VRP-SAM: SAM with Visual Reference PromptYanpeng Sun, Jiahui Chen, Shan Zhang, Xinyu Zhang et al.CVPR 2024 · 49 citations
