CosPGD: an efficient white-box adversarial attack for pixel-wise prediction tasks
Shashank Agnihotri, Steffen Jung, Margret Keuper
摘要
While neural networks allow highly accurate predictions in many tasks, their lack of robustness towards even slight input perturbations often hampers their deployment. Adversarial attacks such as the seminal projected gradient descent (PGD) offer an effective means to evaluate a model's robustness and dedicated solutions have been proposed for attacks on semantic segmentation or optical flow estimation. While they attempt to increase the attack's efficiency, a further objective is to balance its effect, so that it acts on the entire image domain instead of isolated point-wise predictions. This often comes at the cost of optimization stability and thus efficiency. Here, we propose CosPGD, an attack that encourages more balanced errors over the entire image domain while increasing the attack's overall efficiency. To this end, CosPGD leverages a simple alignment score computed from any pixel-wise prediction and its target to scale the loss in a smooth and fully differentiable way. It leads to efficient evaluations of a model's robustness for semantic segmentation as well as regression models (such as optical flow, disparity estimation, or image restoration), and it allows it to outperform the previous SotA attack on semantic segmentation. We provide code for the CosPGD algorithm and example usage at https://github.com/shashankskagnihotri/cospgd.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- RobustSpring: Benchmarking Robustness to Image Corruptions for Optical Flow, Scene Flow and StereoVictor Oei, Jenny Schmalfuss, Lukas Mehl, Madlen Bartsch 等ICLR 2026 · 被引用 9 次
- PEARL: Preprocessing Enhanced Adversarial Robust Learning of Image Deraining for Semantic SegmentationXianghao Jiao, Yaohua Liu, Jiaxin Gao, Xinyuan Chu 等ACM MM 2023 · 被引用 7 次
- AAKR: Adversarial Attack-based Knowledge Retention for Continual Semantic SegmentationZhidong Yu, Xiaoman Liu, Jiajun Hu, Zhenbo Shi 等AAAI 2025 · 被引用 1 次
- Towards Better Robustness Against Natural Corruptions in Document Tampering LocalizationHuiru Shao, Kaizhu Huang, Wei Wang, Xiaowei Huang 等AAAI 2025 · 被引用 1 次
- Attacks on Continual Semantic Segmentation by Perturbing Incremental SamplesZhidong Yu, Wei Yang, Xike Xie, Zhenbo ShiAAAI 2024 · 被引用 1 次
它引用的顶会 Paper17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- SegFormer: Simple and Efficient Design for Semantic Segmentation with TransformersEnze Xie, Wenhai Wang, Zhiding Yu, Anima Anandkumar 等NeurIPS 2021 · 被引用 9,661 次
- A ConvNet for the 2020sZhuang Liu, Hanzi Mao, Chao-Yuan Wu, Christoph Feichtenhofer 等CVPR 2022 · 被引用 6,782 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
相关 Paper
- RP-PGD: Boosting Segmentation Robustness with a Region-and-Prototype Based Adversarial AttackYuxuan Zhang, Zhenbo Shi, Shuchang Wang, Wei Yang 等AAAI 2025 · 被引用 4 次
- Stop Walking in Circles! Bailing Out Early in Projected Gradient DescentPhilip Doldo, Derek Everett, Amol Khanna, André T. Nguyen 等CVPR 2025
- BadPart: Unified Black-box Adversarial Patch Attacks against Pixel-wise Regression TasksZhiyuan Cheng, Zhaoyi Liu, Tengda Guo, Shiwei Feng 等ICML 2024 · 被引用 10 次
- Guided Adversarial Attack for Evaluating and Enhancing Adversarial DefensesGaurang Sriramanan, Sravanti Addepalli, Arya Baburaj, Venkatesh Babu R.NeurIPS 2020 · 被引用 123 次
- Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image ClassifiersFrancesco Croce, Matthias HeinICML 2021 · 被引用 68 次
