Cross-Point Adversarial Attack Based on Feature Neighborhood Disruption Against Segment Anything Model

Yan Jiang,Guisheng Yin,Ye Yuan,Jingjing Chen,Zhipeng Wei
DOI: https://doi.org/10.1109/icme57554.2024.10687491
2024-01-01
Abstract:Segment anything model (SAM) has received significant attention owing to its outstanding segmentation performance. However, it may still face security threats from adversarial examples. Since SAM interactively realizes the prediction of target areas according to user-specified prompts (e.g., points), adversarial examples generated by existing end-to-end attack methods usually exhibit limited attack performance when faced with different point prompts. To this end, we propose a cross-point adversarial attack method based on feature neighborhood disruption against SAM, called CP-FND attack. CP-FND aims to generate adversarial examples capable of effectively deceiving SAM under different user-specified point prompts. Specifically, CP-FND forces the intermediate feature of adversarial examples to be similar to the designed disruption features without relying on any specified point prompt. Subsequently, the continuity and relevance of contextual features are disrupted, thereby fooling SAM and suppressing its predicted masks. Extensive experiments demonstrate that CP-FND achieves superior cross-point adversarial attack performance against SAM compared to state-of-the-art methods.
What problem does this paper attempt to address?