主动防御框架

Search documents
具身智能体主动迎战对抗攻击,清华团队提出主动防御框架
量子位· 2025-08-12 09:35
Core Viewpoint - The article discusses the REIN-EAD framework, which enables embodied intelligent agents to actively defend against adversarial attacks by learning to perceive and interact with their environment, inspired by human visual systems [1][2][3]. Group 1: Framework Overview - REIN-EAD is designed to enhance the robustness of perception in adversarial scenarios by allowing agents to "look twice," thereby improving their ability to handle adversarial attacks [2]. - The framework integrates perception and strategy modules to simulate motion vision mechanisms, enabling continuous observation and exploration of dynamic environments [5]. - It employs a cumulative information exploration method to optimize active strategies, enhancing the agent's ability to identify high-risk areas and adjust behavior dynamically [6]. Group 2: Technical Contributions - The introduction of Offline Adversarial Patch Approximation (OAPA) significantly reduces training costs while providing robust defense capabilities against unknown or adaptive attacks in 3D environments [7]. - The framework demonstrates superior performance across multiple tasks and environments, showcasing its generalization and adaptability compared to existing passive defense methods [8]. Group 3: Experimental Results - Experimental validation indicates that REIN-EAD significantly lowers the success rate of attacks while maintaining standard model accuracy, even against unknown and adaptive attacks [4][31]. - In various tasks such as face recognition, 3D object classification, and object detection, REIN-EAD outperforms baseline defenses like SAC, PZ, and DOA [31][43]. - The framework's ability to accumulate multi-step interactions enhances its robustness and generalization, making it suitable for complex tasks in real-world scenarios [49].