Defending Video Recognition Model Against Adversarial Perturbations via Defense Patterns

被引:0
|
作者
Lee, Hong Joo [1 ]
Ro, Yong Man [1 ]
机构
[1] Korea Adv Inst Sci & Technol KAIST, Sch Elect Engn, Image & Video Syst Lab, Daejeon 34141, South Korea
关键词
Computational modeling; Perturbation methods; Adaptation models; Training; Analytical models; Predictive models; Pattern recognition; Defense patterns (DPs); robust video recognition; video adversarial defense; ROBUSTNESS; ENSEMBLE;
D O I
10.1109/TDSC.2023.3346064
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Deep Neural Networks (DNNs) have been widely successful in various domains, but they are vulnerable to adversarial attacks. Recent studies have also demonstrated that video recognition models are susceptible to adversarial perturbations, but the existing defense strategies in the image domain do not transfer well to the video domain due to the lack of considering temporal development and require a high computational cost for training video recognition models. This article, first, investigates the temporal vulnerability of video recognition models by quantifying the effect of temporal perturbations on the model's performance. Based on these investigations, we propose Defense Patterns (DPs) that can effectively protect video recognition models by adding them to the input video frames. The DPs are generated on top of a pre-trained model, eliminating the need for retraining or fine-tuning, which significantly reduces the computational cost. Experimental results on two benchmark datasets and various action recognition models demonstrate the effectiveness of the proposed method in enhancing the robustness of video recognition models.
引用
收藏
页码:4110 / 4121
页数:12
相关论文
共 50 条
  • [1] Defense against Adversarial Vision Perturbations via Subspace Diagnosis
    Zhu, Jinlin
    Peng, Guohao
    Fu, Wenhao
    Wang, Danwei
    PROCEEDINGS OF THE 38TH CHINESE CONTROL CONFERENCE (CCC), 2019, : 8665 - 8670
  • [2] Defense against Universal Adversarial Perturbations
    Akhtar, Naveed
    Liu, Jian
    Mian, Ajmal
    2018 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2018, : 3389 - 3398
  • [3] Defending Against Universal Perturbations With Shared Adversarial Training
    Mummadi, Chaithanya Kumar
    Brox, Thomas
    Metzen, Jan Hendrik
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 4927 - 4936
  • [4] DifFilter: Defending Against Adversarial Perturbations With Diffusion Filter
    Chen, Yong
    Li, Xuedong
    Hu, Peng
    Peng, Dezhong
    Wang, Xu
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6779 - 6794
  • [5] Fight Perturbations With Perturbations: Defending Adversarial Attacks via Neuron Influence
    Chen, Ruoxi
    Jin, Haibo
    Zheng, Haibin
    Chen, Jinyin
    Liu, Zhenguang
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 1582 - 1595
  • [6] Minority Reports Defense: Defending Against Adversarial Patches
    McCoyd, Michael
    Park, Won
    Chen, Steven
    Shah, Neil
    Roggenkemper, Ryan
    Hwang, Minjune
    Liu, Jason Xinyu
    Wagner, David
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, ACNS 2020, 2020, 12418 : 564 - 582
  • [7] Approximate Manifold Defense Against Multiple Adversarial Perturbations
    Nandy, Jay
    Hsu, Wynne
    Lee, Mong Li
    2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,
  • [8] Restoration as a Defense Against Adversarial Perturbations for Spam Image Detection
    Jiang, Jianguo
    Li, Boquan
    Yu, Min
    Liu, Chao
    Huang, Weiqing
    Fan, Lejun
    Xia, Jianfeng
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2019: IMAGE PROCESSING, PT III, 2019, 11729 : 711 - 723
  • [9] Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks
    Papernot, Nicolas
    McDaniel, Patrick
    Wu, Xi
    Jha, Somesh
    Swami, Ananthram
    2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2016, : 582 - 597
  • [10] Mape: defending against transferable adversarial attacks using multi-source adversarial perturbations elimination
    Liu, Xinlei
    Xie, Jichao
    Hu, Tao
    Yi, Peng
    Hu, Yuxiang
    Huo, Shumin
    Zhang, Zhen
    COMPLEX & INTELLIGENT SYSTEMS, 2025, 11 (02)