cs.CVSep 30, 2026

Universal Cross-Prompt Adversarial Attacks on Promptable Concept Segmentation

Authors: Ziqi Zhou, Yifan Hu, Yufei Song, Haowen Jiang, Xianlong Wang, Shengshan Hu, Dezhong Yao, Leo Yu Zhang

Organizations: College of Computer Science, Chongqing University · School of Cyber Science and Engineering, Huazhong University of Science and Technology · School of Computer Science and Technology, Huazhong University of Science and Technology · Department of Computer Science, City University of Hong Kong · School of Information and Communication Technology, Griffith University

Abstract

The Segment Anything Model (SAM) achieves remarkable performance in visual segmentation. The latest SAM3 extends promptable segmentation to concept-level prediction, broadening the scope of segmentation foundation models. While recent works reveal that SAM and SAM2 are vulnerable to adversarial examples, the robustness of SAM3 under the concept segmentation paradigm remains unexplored. In addition, existing adversarial attacks on SAM-series models exhibit limited cross-prompt transferability. To this end, we propose AdvPCS, a universal cross-prompt adversarial attack for Promptable Concept Segmentation (PCS), including a min-max prompt optimization strategy, a global-local perception deception attack, and a temporal transition deviation attack. Specifically, we first identify the hardest-to-attack prompts via min-max bilevel optimization. In the inner maximization, we enhance diversity over candidate point, box, and text prompts. In the outer minimization, we select prompts with the highest responses based on the confidence scores output by the detector. Given the selected prompts, we apply the perception deception attack to minimize both global and local existence probabilities under joint prompting and employ the temporal memory misalignment attack to maximize inter-frame semantic inconsistency and corrupt memory pointers. Extensive experiments on four benchmark datasets show that a single universal adversarial perturbation (UAP) generated by our method generalizes across frames from different videos and achieves strong attack performance under point, box, and text prompts. In particular, it reduces the average mIoU of various PCS models on the SA-CO dataset to below 5% under text prompts, demonstrating strong attack ability.

Figures & tables

Appendix figures & tables2 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Universal Concept Disruption for SAM3 Image Segmentation

    Aug 6, 2026Hao Wang, Yuxuan Zhang, Wei YangSegment Anything Model

  2. From Pixels to Concepts: Do Segmentation Models Understand What They Segment?

    May 10, 2026Shuang Liang, Zeqing Wang, Yuxian Li +2Multiple Vision TasksAmbiguity

  3. Concept Alignment Contrast and Long-Short Prompt Memory for Test-Time Adaptation of SAM3 in Medical Image Segmentation

    Jun 22, 2026Yubo Zhou, Jianghao Wu, Ping Ye +2Segment Anything ModelVision-Language Model Adaptation