SAM Encoder Breach by Adversarial Simplicial Complex Triggers Downstream Model Failures
Yi Qin, Rui Wang, Tao Huang, Tong Xiao, Liping Jing

TL;DR
This paper introduces VeSCA, a novel adversarial attack method targeting SAM's encoder to generate transferable adversarial examples, revealing vulnerabilities that can cause downstream model failures across various domains.
Contribution
We propose VeSCA, a new simplicial complex-based attack leveraging SAM's encoder for transferable adversarial examples, addressing prior transferability limitations.
Findings
VeSCA improves attack transferability by 12.7% over state-of-the-art methods.
It effectively exposes vulnerabilities in downstream models across multiple datasets.
The study underscores the need for more robust foundation models.
Abstract
While the Segment Anything Model (SAM) transforms interactive segmentation with zero-shot abilities, its inherent vulnerabilities present a single-point risk, potentially leading to the failure of numerous downstream applications. Proactively evaluating these transferable vulnerabilities is thus imperative. Prior adversarial attacks on SAM often present limited transferability due to insufficient exploration of common weakness across domains. To address this, we propose Vertex-Refining Simplicial Complex Attack (VeSCA), a novel method that leverages only the encoder of SAM for generating transferable adversarial examples. Specifically, it achieves this by explicitly characterizing the shared vulnerable regions between SAM and downstream models through a parametric simplicial complex. Our goal is to identify such complexes within adversarially potent regions by iterative vertex-wise…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPhysical Unclonable Functions (PUFs) and Hardware Security · Cryptographic Implementations and Security · Integrated Circuits and Semiconductor Failure Analysis
