Semantically Guided Adversarial Testing of Vision Models Using Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Filus, Katarzyna, Cruz-Duarte, Jorge M.
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913993281503232
author Filus, Katarzyna
Cruz-Duarte, Jorge M.
author_facet Filus, Katarzyna
Cruz-Duarte, Jorge M.
contents In targeted adversarial attacks on vision models, the selection of the target label is a critical yet often overlooked determinant of attack success. This target label corresponds to the class that the attacker aims to force the model to predict. Now, existing strategies typically rely on randomness, model predictions, or static semantic resources, limiting interpretability, reproducibility, or flexibility. This paper then proposes a semantics-guided framework for adversarial target selection using the cross-modal knowledge transfer from pretrained language and vision-language models. We evaluate several state-of-the-art models (BERT, TinyLLAMA, and CLIP) as similarity sources to select the most and least semantically related labels with respect to the ground truth, forming best- and worst-case adversarial scenarios. Our experiments on three vision models and five attack methods reveal that these models consistently render practical adversarial targets and surpass static lexical databases, such as WordNet, particularly for distant class relationships. We also observe that static testing of target labels offers a preliminary assessment of the effectiveness of similarity sources, \textit{a priori} testing. Our results corroborate the suitability of pretrained models for constructing interpretable, standardized, and scalable adversarial benchmarks across architectures and datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2508_11341
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Semantically Guided Adversarial Testing of Vision Models Using Language Models
Filus, Katarzyna
Cruz-Duarte, Jorge M.
Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
68T45, 68T01, 68T07, 68T10, 68M25
I.2.10; I.5.4; I.2.6; I.2.7; K.6.5
In targeted adversarial attacks on vision models, the selection of the target label is a critical yet often overlooked determinant of attack success. This target label corresponds to the class that the attacker aims to force the model to predict. Now, existing strategies typically rely on randomness, model predictions, or static semantic resources, limiting interpretability, reproducibility, or flexibility. This paper then proposes a semantics-guided framework for adversarial target selection using the cross-modal knowledge transfer from pretrained language and vision-language models. We evaluate several state-of-the-art models (BERT, TinyLLAMA, and CLIP) as similarity sources to select the most and least semantically related labels with respect to the ground truth, forming best- and worst-case adversarial scenarios. Our experiments on three vision models and five attack methods reveal that these models consistently render practical adversarial targets and surpass static lexical databases, such as WordNet, particularly for distant class relationships. We also observe that static testing of target labels offers a preliminary assessment of the effectiveness of similarity sources, \textit{a priori} testing. Our results corroborate the suitability of pretrained models for constructing interpretable, standardized, and scalable adversarial benchmarks across architectures and datasets.
title Semantically Guided Adversarial Testing of Vision Models Using Language Models
topic Computer Vision and Pattern Recognition
Cryptography and Security
Machine Learning
68T45, 68T01, 68T07, 68T10, 68M25
I.2.10; I.5.4; I.2.6; I.2.7; K.6.5
url https://arxiv.org/abs/2508.11341