RP-PGD: Boosting Segmentation Robustness with a Region-and-Prototype Based Adversarial Attack

Authors

  • Yuxuan Zhang University of Science and Technology of China
  • Zhenbo Shi University of Science and Technology of China Laboratory for Advanced Computing and Intelligence Engineering
  • Shuchang Wang University of Science and Technology of China
  • Wei Yang University of Science and Technology of China
  • Shaowei Wang Guangzhou University
  • Yinxing Xue University of Science and Technology of China

DOI:

https://doi.org/10.1609/aaai.v39i10.33122

Abstract

Adversarial attack and defense have been extensively explored in classification tasks, but their study in semantic segmentation remains limited. Moreover, current attacks fail to act as strong underlying attacks for adversarial training (AT), making it difficult to achieve segmentation robustness against strong attacks. In this paper, we present RP-PGD, a novel Region-and-Prototype based Projected Gradient Descent attack tailored to fool segmentation models. In particular, we propose a region-based attack, which leverages a spatial-temporal way to separate the pixels into three disjoint regions, and highlights the attack on the crucial True Region and Boundary Region. Moreover, we introduce a prototype-based attack to disrupt the feature space, further enhancing the attack capability. To boost the robustness of segmentation models, we inject adversaries generated by RP-PGD into the clean data and perform AT. Extensive experiments on multiple datasets showcase that RP-PGD generates adversaries with faster convergence and stronger attack effectiveness, surpassing state-of-the-art attacks by a large margin. Consequently, RP-PGD serves as a strong underlying attack for segmentation models to perform AT, assisting them in defending against a variety of strong attacks without incurring additional computational costs during inference.

Published

2025-04-11

How to Cite

Zhang, Y., Shi, Z., Wang, S., Yang, W., Wang, S., & Xue, Y. (2025). RP-PGD: Boosting Segmentation Robustness with a Region-and-Prototype Based Adversarial Attack. Proceedings of the AAAI Conference on Artificial Intelligence, 39(10), 10338-10347. https://doi.org/10.1609/aaai.v39i10.33122

Issue

Section

AAAI Technical Track on Computer Vision IX