The primary tools used to monitor and defend object detectors under adversarial attack assume that when accuracy degrades, detection count drops in tandem. This coupling was assumed, not measured. We report a counterexample observed on a single model: under standard PGD, EMS-YOLO, a spiking neural network (SNN) object detector, retains more than 70% of its detections while mAP collapses from 0.528 to 0.042. We term this count-preserving accuracy collapse Quality Corruption (QC), to distinguish it from the suppression that dominates untargeted evaluation. Across four SNN architectures and two threat models (l-infinity and l-2), QC appears only in one of the four detectors tested (EMS-YOLO). On this model, all five standard defense components fail to detect or mitigate QC, suggesting the defense ecosystem may rely on a shared assumption calibrated on a single substrate. These results provide, to our knowledge, the first evidence that adversarial failure modes can be substrate-dependent.
翻译:用于监控和防御受对抗攻击目标检测器的主要工具假设,当精度下降时,检测数量会同步减少。这种耦合关系是假设的,而非经过测量的。我们报告在一个单一模型上观察到的反例:在标准PGD攻击下,脉冲神经网络(SNN)目标检测器EMS-YOLO保留了超过70%的检测结果,而其mAP从0.528骤降至0.042。我们将这种保持计数但精度崩溃的现象称为质量破坏(Quality Corruption, QC),以区别于在非定向评估中占主导地位的抑制效应。在四个SNN架构和两种威胁模型(l-无穷范数和l-2范数)中,QC仅出现在受测的四个检测器之一(EMS-YOLO)上。在该模型上,所有五种标准防御组件均未能检测或缓解QC,这表明防御生态系统可能依赖于一种基于单一基板校准的共享假设。据我们所知,这些结果首次证明了对抗性失效模式可能具有基板依赖性。