Practical Region-level Attack against Segment Anything Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Shen, Yifan, Li, Zhengyuan, Wang, Gang
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910732030836736
author Shen, Yifan
Li, Zhengyuan
Wang, Gang
author_facet Shen, Yifan
Li, Zhengyuan
Wang, Gang
contents Segment Anything Models (SAM) have made significant advancements in image segmentation, allowing users to segment target portions of an image with a single click (i.e., user prompt). Given its broad applications, the robustness of SAM against adversarial attacks is a critical concern. While recent works have explored adversarial attacks against a pre-defined prompt/click, their threat model is not yet realistic: (1) they often assume the user-click position is known to the attacker (point-based attack), and (2) they often operate under a white-box setting with limited transferability. In this paper, we propose a more practical region-level attack where attackers do not need to know the precise user prompt. The attack remains effective as the user clicks on any point on the target object in the image, hiding the object from SAM. Also, by adapting a spectrum transformation method, we make the attack more transferable under a black-box setting. Both control experiments and testing against real-world SAM services confirm its effectiveness.
format Preprint
id arxiv_https___arxiv_org_abs_2404_08255
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Practical Region-level Attack against Segment Anything Models
Shen, Yifan
Li, Zhengyuan
Wang, Gang
Computer Vision and Pattern Recognition
Cryptography and Security
Segment Anything Models (SAM) have made significant advancements in image segmentation, allowing users to segment target portions of an image with a single click (i.e., user prompt). Given its broad applications, the robustness of SAM against adversarial attacks is a critical concern. While recent works have explored adversarial attacks against a pre-defined prompt/click, their threat model is not yet realistic: (1) they often assume the user-click position is known to the attacker (point-based attack), and (2) they often operate under a white-box setting with limited transferability. In this paper, we propose a more practical region-level attack where attackers do not need to know the precise user prompt. The attack remains effective as the user clicks on any point on the target object in the image, hiding the object from SAM. Also, by adapting a spectrum transformation method, we make the attack more transferable under a black-box setting. Both control experiments and testing against real-world SAM services confirm its effectiveness.
title Practical Region-level Attack against Segment Anything Models
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2404.08255