Can Attack Difficulty Be Characterized Before Optimization? A Study of Pre-optimization Difficulty in Person-Vanishing Attacks

📅 2026-09-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge that adversarial attack difficulty can only be observed post hoc rather than assessed a priori by defining and validating the concept of "pre-optimization attack difficulty," demonstrating its predictability. Methodologically, this work proposes Quad-CLEVER, a geometric estimator based on quadratic approximation of locally vanishing margins, to quantify this difficulty. A difficulty-aware framework is further constructed to enable adaptive, dynamic allocation of computational resources under fixed budgets. Experimental results show that integrating this approach with mainstream attack algorithms improves image-level attack success rates by 5.78% and reduces average iterations by 11.42 on the BDD100K dataset. On the EventPed dataset, it maintains performance while saving 2.25 iterations, significantly enhancing overall attack efficiency.
📝 Abstract
Adversarial attacks against object detectors are traditionally studied from an optimization perspective, where attack difficulty is regarded as an outcome observed only after adversarial optimization. This raises a fundamental question: \emph{can the relative attack difficulty of different inputs be characterized before optimization begins?} In this paper, we investigate this question for person-vanishing attacks by introducing the concept of pre-optimization attack difficulty, which captures intrinsic differences in optimization effort across input images. To estimate this latent difficulty before optimization, we propose Quad-CLEVER, an efficient geometry-based estimator derived from a quadratic approximation of the local person-vanishing margin along the most attack-relevant direction. Extensive experiments across multiple attack algorithms demonstrate that Quad-CLEVER consistently correlates with the observed optimization cost, providing empirical evidence that attack difficulty exhibits a predictable pre-optimization structure. Building upon this finding, we further propose a difficulty-aware attack framework that leverages the estimated difficulty to adaptively allocate optimization budgets for a base attack under a fixed computational budget. On BDD100K, the proposed framework improves the image-level attack success rate by up to 5.78$\%$ while reducing the average optimization cost by up to 11.42 iterations. On the more challenging EventPed dataset, it saves 2.25 optimization iterations while maintaining comparable attack performance. These results demonstrate that attack difficulty can be meaningfully estimated before optimization and that exploiting such estimates enables more computationally efficient adversarial attacks.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Pre-optimization Attack Difficulty
Quad-CLEVER
Person-Vanishing Attacks
Difficulty-Aware Framework
Adversarial Optimization
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Jingyao Xu
School of Computer Science and Technology, Beijing Jiaotong University
Dongdong Wang
Dongdong Wang
University of Florida
Deep LearningComputer VisionLarge Language ModelIntelligent Transportation Systems
S
Siyang Lu
School of Computer Science and Technology, Beijing Jiaotong University