Skip to content
Open access

Fspgd: rethinking black-box attacks on semantic segmentation

Feb 2025 · Machine Vision and Applications · Vol 37 · 0 citations · 52 references
Computer Science

TL;DR

Findings establish FSPGD as a principled and practical framework for advancing black-box adversarial attacks in semantic segmentation, consistently outperforming conventional logit-level methods as well as recent segmentation-specific baselines such as SegPGD, CosPGD, and RP-PGD.

Abstract

Black-box adversarial attacks on semantic segmentation remain a challenging problem, particularly in the black-box transfer attack setting where perturbations crafted on a surrogate model are expected to mislead unseen target models. Existing methods typically operate only on output logits and thus fail to account for the spatial structure and class-wise feature relationships that are crucial for dense prediction. To address this limitation, we propose Feature Similarity Projected Gradient Descent (FSPGD), a feature-space black-box attack that explicitly disrupts intermediate representations. FSPGD employs a dual loss design: an external loss that enforces discrepancy between clean and adversarial features to weaken cross-model alignment, and an internal loss that reduces feature consistency among spatially separated instances of the same class. Comprehensive experiments on Pascal VOC 2012 and Cityscapes across both CNN-based and Transformer-based backbones demonstrate that FSPGD achieves state-of-the-art transferability, consistently outperforming conventional logit-level methods as well as recent segmentation-specific baselines such as SegPGD, CosPGD, and RP-PGD. Moreover, adversarial training with FSPGD examples enhances robustness against unseen attacks across multiple architectures, further validating the effectiveness of our design. These findings establish FSPGD as a principled and practical framework for advancing black-box adversarial attacks in semantic segmentation. Code is available at https://github.com/KU-AIVS/FSPGD.

Read PDF

Similar papers

Conference Sep 2026

CLIP-guided structure-semantic collaborative adversarial erasure for weakly supervised semantic segmentation

Adversarial erasing (AE) is commonly used to expand class activation maps (CAM) in Weakly Supervised Semantic Segmentation (WSSS), but existing AE methods struggle with semantic drift, background over-activation, and boundary blur due to limited structural awareness. We propose a CAM optimization method that combines c...

Ya-Wen Shi, Xu Chen, Jin-Ping Tang et al. · 0 citations
Preprint Aug 2026

SegPAR: Class-Centric Decision-Based Sparse Attack for Semantic Segmentation

Despite the practical relevance of sparse decision-based black-box threats, they have received limited attention in semantic segmentation. To bridge this gap, we adapt the most representative decision-based black-box sparse attacks from the classification domain to serve as baselines, establishing a rigorous benchmark...

Dong-Su Song, Dae-Yoo Go, Boseung Seo et al. · 0 citations
Preprint Aug 2026

Universal Concept Disruption for SAM3 Image Segmentation

SAM3 extends promptable segmentation from geometry-driven mask prediction to open-vocabulary concept segmentation, where a text-conditioned grounding model decides whether a concept is present and segments all matching instances. While this presence-gated design improves concept-level prediction, its adversarial robust...

Hao Wang, Yuxuan Zhang, Wei Yang · 0 citations
Aug 2026

A Hybrid CNN–LSTM Framework with Explainable AI for Robust Deepfake Detection

A robust, explainable detection framework is presented that combines a CNN backbone for extracting spatial artifacts with an LSTM module for modeling temporal inconsistencies across frames that enhances forensic decision support and increases practical readiness for content verification systems.

Lastone Banda, Esther J. · 0 citations
Preprint Aug 2026

Scalable Black-Box Model Attribution for Images

The rapid proliferation of generative models raises the model attribution problem: given only an image, can we determine which model produced it? We propose a lightweight CNN to solve this problem in a strict black box setting. The CNN operates on multiple image patches to handle varying image size and improve accuracy...

Asaf Livne, Amir Jevnisek, S. Avidan · 0 citations
#artificial intelligence Preprint Sep 2026

Discovering Natural Transformation Vulnerabilities in Black-Box Vision Models

Natural adversarial examples (NAEs) reveal that vision models can fail under realistic semantic changes beyond norm-bounded perturbations. However, generating NAEs in a black-box setting remains challenging because existing generative attacks often rely on surrogate models, learned attack priors, or costly query-based...

Dong-Su Song, Dae-Yoo Go, J. Jung · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.