ICASSP 2025accepted0 citations

GPA: Enhancing Generalizable Physical Adversarial Attacks Across Multiple Vision Tasks

Mingye Xie, Suncheng Xiang, Jiacheng Ruan, Xian Gao, Zefang Yu, Ting Liu, Yuzhuo Fu

Abstract

Adversarial attacks pose a significant challenge in deep learning, as carefully crafted perturbations can severely degrade even the most advanced models. In real-world scenarios, where the target models are often unknown, previous works often focus on creating adversarial patterns for specific known models, with the goal of generalizing these patterns to other models. However, such attacks rely heavily on prior model information, leading to poor generalization. To overcome this, we propose a novel method called GPA. Our solution includes an attention extraction module based on a pre-trained vision encoder, which captures precise and generalizable features of model attention on objects. We also introduce attack loss functions that divert attention away from target objects. Compared to state-of-the-art methods, our approach achieves superior attack performance across various downstream vision tasks, including object detection, instance segmentation, and depth estimation. Moreover, the adversarial patterns generated by GPA maintain their effectiveness in real-world scenarios.

BibTeX
@inproceedings{icassp2025_gpaenhancinggene,
  title = {GPA: Enhancing Generalizable Physical Adversarial Attacks Across Multiple Vision Tasks},
  author = {Mingye Xie and Suncheng Xiang and Jiacheng Ruan and Xian Gao and Zefang Yu and Ting Liu and Yuzhuo Fu},
  booktitle = {ICASSP 2025},
  year = {2025}
}
GPA: Enhancing Generalizable Physical Adversarial Attacks Across Multiple Vision Tasks · ICASSP 2025