🤖 AI Summary
This study addresses the severe distortion of primary image subjects caused by strong adversarial attacks. We propose a novel "carrier"-based paradigm for hosting adversarial perturbations, which introduces secondary visual elements as auxiliary carriers. Guided by a global classifier, the method generates adversarial examples such that these carriers absorb the majority of perturbation updates, thereby preserving the semantic integrity of the primary subject while maintaining attack strength. Experimental results demonstrate that this approach significantly improves subject preservation and cross-model transferability. It effectively misleads target classifiers while sustaining consistency in human visual perception, achieving a synergistic optimization of semantic disentanglement and attack efficacy.
📝 Abstract
Strong unrestricted adversarial attacks can distort the primary object of an image, hereafter referred to as the subject. To preserve subject integrity without compromising attack magnitude, we introduce the carrier: a secondary visual element that provides an auxiliary region to facilitate the attack under global classifier guidance. We demonstrate three key findings: 1. A carrier mitigates subject distortion by absorbing a larger share of globally normalized attack updates. 2. A carrier improves cross-model transferability, governed by the strength of target-related features that balance semantic separation and transfer performance. 3. Successful targeted attacks retain the personalized subject as the primary content perceived by humans while successfully misleading the classifier. Our results demonstrate that a visually secondary carrier offers an auxiliary spatial pathway for adversarial changes, enabling strong and transferable attacks while improving subject preservation.