TIGA: Trajectory-Injected Generative Attack against Black-box AIGC Detectors
TIGA:针对黑盒AIGC检测器的轨迹注入生成攻击
机构 * School of Computer and Information Engineering, Xiamen University of Technology(厦门理工学院计算机与信息工程学院) ; Interdisciplinary Centre for Security, Reliability and Trust (SnT), University of Luxembourg(卢森堡大学安全、可靠性和信任跨学科中心) ; School of Computer Science, Engineering Research Center of Machine Learning and Industry Intelligence, Sichuan University(四川大学计算机学院机器学习与工业智能工程研究中心) ; PCA Laboratory, Key Laboratory of Intelligent Perception and Systems for High-Dimensional Information of Ministry of Education, School of Computer Science and Engineering, Nanjing University of Science and Technology(南京理工大学计算机科学与工程学院高维信息智能感知与系统教育部重点实验室PCA实验室) ; Department of Computer and Information Science, Faculty of Science and Technology, University of Macau(澳门大学科技学院计算机与信息科学系) ; School of Engineering, Edith Cowan University(伊迪斯科文大学工程学院) ; College of Computing and Data Science, Nanyang Technological University(南洋理工大学计算与数据科学学院)
AI总结 针对黑盒AIGC检测器,TIGA提出无需源图像和训练的框架,通过操纵DDIM轨迹、聚合梯度及方向搜索估计目标响应,实现强大黑盒攻击性能、可转移性及高鲁棒性,且无需源图像或扩散模型再训练。
Comments 14 pages, 5 figures