Meta-Attack: Class-agnostic and Model-agnostic Physical Adversarial Attack
Weiwei Feng, Baoyuan Wu, Tianzhu Zhang, Yong Zhang, Yongdong Zhang
摘要
Modern deep neural networks are often vulnerable to adversarial examples. Most exist attack methods focus on crafting adversarial examples in the digital domain, while only limited works study physical adversarial attack. However, it is more challenging to generate effective adversarial examples in the physical world due to many uncontrollable physical dynamics. Most current physical attack methods aim to generate robust physical adversarial examples by simulating all possible physical dynamics. When attacking new images or new DNN models, they require expensive manually efforts for simulating physical dynamics and considerable time for iteratively optimizing for each image. To tackle these issues, we propose a class-agnostic and model-agnostic physical adversarial attack model (Meta-Attack), which is able to not only generate robust physical adversarial examples by simulating color and shape distortions, but also generalize to attacking novel images and novel DNN models by accessing a few digital and physical images. To the best of our knowledge, this is the first work to formulate the physical attack as a few-shot learning problem. Here, the training task is redefined as the composition of a support set, a query set, and a target DNN model. Under the few-shot setting, we design a novel class-agnostic and model-agnostic meta-learning algorithm to enhance the generalization ability of our method. Extensive experimental results on two benchmark datasets with four challenging experimental settings verify the superior robustness and generalization of our method by comparing to state-of-the-art physical attack methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Adversarial Attacks Already Tell the Answer: Directional Bias-Guided Test-time Defense for Vision-Language ModelsLiangsheng Liu, Si Chen, Jiamin Wu, Weiwei Feng 等ICLR 2026 · 被引用 4 次
- 3D Gaussian Splatting Driven Multi-View Robust Physical Adversarial Camouflage GenerationTianrui Lou, Xiaojun Jia, Siyuan Liang, Jiawei Liang 等ICCV 2025 · 被引用 2 次
相关 Paper
- Beyond Digital Domain: Fooling Deep Learning Based Recognition System in Physical WorldKaichen Yang, Tzungyu Tsai, Honggang Yu, Tsung-Yi Ho 等AAAI 2020 · 被引用 29 次
- Adversarially Robust Few-Shot Learning: A Meta-Learning ApproachMicah Goldblum, Liam Fowl, Tom GoldsteinNeurIPS 2020 · 被引用 107 次
- Generate Universal Adversarial Perturbations for Few-Shot LearningYiman Hu, Yixiong Zou, Ruixuan Li, Yuhua LiNeurIPS 2024 · 被引用 3 次
- Adversarial Image Attacks Using Multi-Sample and Most-Likely Ensemble MethodsXia Du, Chi-Man PunACM MM 2020 · 被引用 9 次
- RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical WorldDonghua Wang, Wen Yao, Tingsong Jiang, Chao Li 等ICCV 2023 · 被引用 47 次
