Related Experiment Video
Updated: Jun 26, 2026

03:31
End-To-End Deep Neural Network for Salient Object Detection in Complex Environments
Published on: December 15, 2023
Delving into the adversarial robustness of semantic segmentation with decision-based black-box attacks
Zhaoyu Chen1, Zhengyang Shan2, Jingwen Chang3
1College of Intelligent Robotics and Advanced Manufacturing, Fudan University, Shanghai, 200433, China.
Summary
This study introduces Discrete Linear Attack (DLA), a novel method to test semantic segmentation robustness. DLA effectively demonstrates vulnerabilities in AI models against practical adversarial attacks.
Area of Science:
- Computer Vision
- Artificial Intelligence
- Machine Learning
Background:
- Semantic segmentation is vital for security applications.
- Robustness against black-box adversarial attacks remains under-investigated.
Purpose of the Study:
- To explore decision-based black-box attacks on semantic segmentation.
- To propose an efficient attack method, Discrete Linear Attack (DLA).
Main Methods:
- Developed Discrete Linear Attack (DLA) using discrete linear noises.
- Employed random search and a proxy index for perturbation calibration.
- Evaluated adversarial robustness across 11 models and 4 datasets.
Main Results:
- DLA significantly reduced PSPNet's mIoU on Cityscapes from 77.83% to 2.14%.
- Achieved high attack efficiency with only 50 queries.
- Demonstrated formidable attack power in practical settings.
Conclusions:
- Semantic segmentation models are vulnerable to decision-based black-box attacks.
- DLA provides an effective method for evaluating and improving model robustness.
- Further research is needed to enhance adversarial defense strategies.