Universal Concept Disruption for SAM3 Image Segmentation
Existing work has not yet investigated the adversarial robustness of SAM3 in open-vocabulary concept segmentation, nor has it developed a universal attack method targeting its joint concept–image system. This work proposes Universal Concept Disruption (UCD), the first approach enabling end-to-end, universal cross-concept adversarial attacks on SAM3. UCD learns a single bounded perturbation that simultaneously disrupts textual conditioning inputs, visual feature consistency, existence gating scores, and mask spatial validity. Notably, this perturbation generalizes across datasets, model variants (e.g., SAM3.1), and video inference without re-optimization. Experiments demonstrate that UCD substantially degrades model performance, reducing average mask AP from 59.43 to 18.73 and cgF1 from 50.32 to 20.49, thereby confirming its strong transferability and effectiveness.