Robust SAM: On the Adversarial Robustness of Vision Foundation Models
Jiahuan Long, Zhengqin Xu, Tingsong Jiang, Wen Yao, Shuai Jia, Chao Ma, Xiaoqian Chen
摘要
The Segment Anything Model (SAM) is a widely used vision foundation model with diverse applications, including image segmentation, detection, and tracking. Given SAM's wide applications, understanding its robustness against adversarial attacks is crucial for real-world deployment. However, research on SAM's robustness is still in its early stages. Existing attacks often overlook the role of prompts in evaluating SAM's robustness, and there has been insufficient exploration of defense methods to balance the robustness and accuracy. To address these gaps, this paper proposes an adversarial robustness framework designed to evaluate and enhance the robustness of SAM. Specifically, we introduce a cross-prompt attack method to enhance the attack transferability across different prompt types. Besides attacking, we propose a few-parameter adaptation strategy to defend SAM against various adversarial attacks. To balance robustness and accuracy, we use the singular value decomposition (SVD) to constrain the space of trainable parameters, where only singular values are adaptable. Experiments demonstrate that our cross-prompt attack method outperforms previous approaches in terms of attack success rate on both SAM and SAM 2. By adapting only 512 parameters, we achieve at least a 15% improvement in mean intersection over union (mIoU) against various adversarial attacks. Compared to previous defense methods, our approach enhances the robustness of SAM while maximally maintaining its original performance.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared DetectorsJiahuan Long, Wen Yao, Tingsong Jiang, Jiacheng Hou 等ACM MM 2025 · 被引用 7 次
- Robust-R1: Degradation-Aware Reasoning for Robust Visual UnderstandingJiaqi Tang, Jianmin Chen, Wei Wei, Xiaogang Xu 等AAAI 2026 · 被引用 4 次
- Thermally Activated Dual-Modal Adversarial Clothing against AI Surveillance SystemsJiahuan Long, Tingsong Jiang, Hanqing Liu, Chao Ma 等CVPR 2026 · 被引用 3 次
- Robust-U1: Can MLLMs Self-Recover Corrupted Visual Content for Robust Understanding?Jiaqi Tang, Jianmin Chen, Youyang Zhai, Wei Wei 等ICML 2026 · 被引用 1 次
- Fractal Camouflage: A Bio-Inspired Approach for Multi-Scale Adversarial Attacks in the Infrared DomainChengyin Hu, Xin Wang, Rui Qiu, Zhe Jia 等CVPR 2026
它引用的顶会 Paper6
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu 等ICLR 2022 · 被引用 18,833 次
- Feature Importance-aware Transferable Adversarial AttacksZhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu 等ICCV 2021 · 被引用 306 次
- FacT: Factor-Tuning for Lightweight Adaptation on Vision TransformerShibo Jie, Zhi-Hong DengAAAI 2023 · 被引用 182 次
- Parameter Efficient Fine-Tuning via Cross Block Orchestration for Segment Anything ModelZelin Peng, Zhengqin Xu, Zhilin Zeng, Lingxi Xie 等CVPR 2024 · 被引用 11 次
- RobustSAM: Segment Anything Robustly on Degraded ImagesWei-Ting Chen, Yu-Jiet Vong, Sy-Yen Kuo, Sizhuo Ma 等CVPR 2024
相关 Paper
- Vanish into Thin Air: Cross-prompt Universal Adversarial Attacks for SAM2Ziqi Zhou, Yifan Hu, Yufei Song, Zijing Li 等NeurIPS 2025 · 被引用 17 次
- Improving the Generalization of Segmentation Foundation Model under Distribution Shift via Weakly Supervised AdaptationHaojie Zhang, Yongyi Su, Xun Xu, Kui JiaCVPR 2024 · 被引用 26 次
- DarkSAM: Fooling Segment Anything Model to Segment NothingZiqi Zhou, Yufei Song, Minghui Li, Shengshan Hu 等NeurIPS 2024 · 被引用 44 次
- Attack for Defense: Adversarial Agents for Point Prompt Optimization Empowering Segment Anything ModelXueyu Liu, Xiaoyi Zhang, Meilin Liu, Guangze Shi 等CVPR 2026 · 被引用 1 次
- SAM Encoder Breach by Adversarial Simplicial Complex Triggers Downstream Model FailuresYi Qin, Rui Wang, Tao Huang, Tong Xiao 等ICCV 2025
