Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

One Perturbation is Enough: On Generating Universal Adversarial Perturbations against Vision-Language Pre-training Models

About

Vision-Language Pre-training (VLP) models have exhibited unprecedented capability in many applications by taking full advantage of the multimodal alignment. However, previous studies have shown they are vulnerable to maliciously crafted adversarial samples. Despite recent success, these methods are generally instance-specific and require generating perturbations for each input sample. In this paper, we reveal that VLP models are also vulnerable to the instance-agnostic universal adversarial perturbation (UAP). Specifically, we design a novel Contrastive-training Perturbation Generator with Cross-modal conditions (C-PGC) to achieve the attack. In light that the pivotal multimodal alignment is achieved through the advanced contrastive learning technique, we devise to turn this powerful weapon against themselves, i.e., employ a malicious version of contrastive learning to train the C-PGC based on our carefully crafted positive and negative image-text pairs for essentially destroying the alignment relationship learned by VLP models. Besides, C-PGC fully utilizes the characteristics of Vision-and-Language (V+L) scenarios by incorporating both unimodal and cross-modal information as effective guidance. Extensive experiments show that C-PGC successfully forces adversarial samples to move away from their original area in the VLP model's feature space, thus essentially enhancing attacks across various victim models and V+L tasks. The GitHub repository is available at https://github.com/ffhibnese/CPGC_VLP_Universal_Attacks.

Hao Fang, Jiawei Kong, Wenbo Yu, Bin Chen, Jiawei Li, Hao Wu, Shutao Xia, Ke Xu• 2024

Related benchmarks

TaskDatasetResultRank
Text-to-Image RetrievalFlickr30K
R@153.11
559
Image-to-Text RetrievalFlickr30K
R@135.55
451
Visual GroundingRefCOCO+ (val)
Accuracy41.59
253
Visual GroundingRefCOCO+ (testA)
Accuracy44.22
245
Visual GroundingRefCOCO+ (testB)
Accuracy36.74
219
Zero-shot ClassificationCIFAR100--
65
Zero-shot ClassificationCIFAR10--
62
Image CaptioningMSCOCO (test)
CIDEr117.3
29
Zero-shot ClassificationSTL10--
21
Zero-shot ClassificationStanfordCars--
21
Showing 10 of 17 rows

Other info

Follow for update