跳到正文
arXiv:cs.AI· Heyam Bin Jahlan Areej Alhothali Abeer Alhothali·· 6 小时前AI 评分40

STCA:针对自动驾驶黑盒视觉语言模型的可迁移时空连贯性对抗攻击

Transferable Spatial Temporal Coherence Adversarial Attack on Black-Box Vision Language Models for Autonomous Driving

AI 导读

研究者提出时空连贯性对抗攻击(STCA),针对自动驾驶场景中的黑盒视觉语言模型,通过模态扩展、空间攻击和STCA三阶段,利用运动引导掩码破坏跨帧时间连贯性。在BDD100K和nuScenes数据集上对Video LLaVA-7B、Qwen2.5-VL-7B和Dolphin三个模型的实验显示,空间攻击在高SSIM下实现了较高的攻击成功率,表明现有视频语言模型在自动驾驶场景中仍高度易受对抗攻击。

正文

View PDF HTML (experimental)

Abstract:The rapid integration of Vision Language Models (VLMs) into sensitive systems introduces critical safety vulnerabilities that remain unexplored in exist studies. While adversarial attack robustness has been extensively studied for image-based models, the susceptibility of VLMs to temporally-aware adversarial attacks against video in driving context poses a distinct and under examined threat. In this paper, we introduce novel adversarial attack against video targeting VLM models used for autonomous driving scenes named Spatial Temporal Coherence Adversarial Attack (STCA). Our attack comprise from three stages: modalities expansion, Spatial attack, and STCA attack. In modalities expansion, we propose caption-guided frame selection method in order to ensure that adversarial perturbation target the most semantically significant frames. this http URL spatial attack, we craft effective perturbation and preserve high similarity. Then the perturbed video generated fed into STCA stage that disrupt cross-frame temporal coherence using motion guided mask. Our method operate under black box threat model against victim target VLMs, relying solely on transferability from white-box surrogate this http URL conduct our experiments on the BDD100K and nuScenes autonomous driving datasets across three VLM models: Video LLaVA-7B, Qwen2.5-VL-7B, and Dolphin. Experimental results demonstrate spatial attack achieves an ASR with high SSIM. Our finding reveal that existing video language model, remain highly susceptible to adversarial attack in autonomous driving scenarios, underscoring the urgent need for robust defense for VLM models.
Subjects: Computer Vision and Pattern Recognition (cs.CV); Artificial Intelligence (cs.AI)
Cite as: arXiv:2610.08331 [cs.CV]
  (or arXiv:2610.08331v1 [cs.CV] for this version)
  https://doi.org/10.48550/arXiv.2610.08331

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Heyam Bin Jahlan [view email]
[v1] Tue, 6 Oct 2026 13:30:06 UTC (28,257 KB)

来源:arXiv:cs.AI · arxiv.org