PapMOT: Exploring Adversarial Patch Attack Against Multiple Object Tracking

被引:0
|
作者
Long, Jiahuan [1 ,2 ]
Jiang, Tingsong [2 ]
Yao, Wen [2 ]
Jia, Shuai [1 ]
Zhang, Weijia [1 ]
Zhou, Weien [2 ]
Ma, Chao [1 ]
Chen, Xiaoqian [2 ]
机构
[1] Shanghai Jiao Tong Univ, AI Inst, MoE Key Lab Artificial Intelligence, Shanghai, Peoples R China
[2] Chinese Acad Mil Sci, Def Innovat Inst, Beijing, Peoples R China
来源
关键词
Physical adversarial patches; Multiple object tracking; Evaluation metrics;
D O I
10.1007/978-3-031-72983-6_8
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Tracking multiple objects in a continuous video stream is crucial for many computer vision tasks. It involves detecting and associating objects with their respective identities across successive frames. Despite significant progress made in multiple object tracking (MOT), recent studies have revealed the vulnerability of existing MOT methods to adversarial attacks. Nevertheless, all of these attacks belong to digital attacks that inject pixel-level noise into input images, and are therefore ineffective in physical scenarios. To fill this gap, we propose PapMOT, which can generate physical adversarial patches against MOT for both digital and physical scenarios. Besides attacking the detection mechanism, PapMOT also optimizes a printable patch that can be detected as new targets to mislead the identity association process. Moreover, we introduce a patch enhancement strategy to further degrade the temporal consistency of tracking results across video frames, resulting in more aggressive attacks. We further develop new evaluation metrics to assess the robustness of MOT against such attacks. Extensive evaluations on multiple datasets demonstrate that our PapMOT can successfully attack various architectures of MOT trackers in digital scenarios. We also validate the effectiveness of PapMOT for physical attacks by deploying printed adversarial patches in the real world.
引用
收藏
页码:128 / 144
页数:17
相关论文
共 50 条
  • [31] Defending Person Detection Against Adversarial Patch Attack by Using Universal Defensive Frame
    Yu, Youngjoon
    Lee, Hong Joo
    Lee, Hakmin
    Ro, Yong Man
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2022, 31 : 6976 - 6990
  • [32] Cross-Shaped Adversarial Patch Attack
    Ran, Yu
    Wang, Weijia
    Li, Mingjie
    Li, Lin-Cheng
    Wang, Yuan-Gen
    Li, Jin
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (04) : 2289 - 2303
  • [33] Adversarial Attack against Modeling Attack on PUFs
    Wang, Sying-Jyan
    Chen, Yu-Shen
    Li, Katherine Shu-Min
    PROCEEDINGS OF THE 2019 56TH ACM/EDAC/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2019,
  • [34] Hardening RGB-D object recognition systems against adversarial patch attacks
    Zheng, Yang
    Demetrio, Luca
    Cina, Antonio Emanuele
    Feng, Xiaoyi
    Xia, Zhaoqiang
    Jiang, Xiaoyue
    Demontis, Ambra
    Biggio, Battista
    Roli, Fabio
    INFORMATION SCIENCES, 2023, 651
  • [35] Pick-Object-Attack: Type-specific adversarial attack for object detection
    Nezami, Omid Mohamad
    Chaturvedi, Akshay
    Dras, Mark
    Garain, Utpal
    COMPUTER VISION AND IMAGE UNDERSTANDING, 2021, 211
  • [36] PICK-OBJECT-ATTACK: Type-specific adversarial attack for object detection
    Mohamad Nezami, Omid
    Chaturvedi, Akshay
    Dras, Mark
    Garain, Utpal
    Computer Vision and Image Understanding, 2021, 211
  • [37] Multi-level loss object tracking adversarial attack method based on spatial perception
    Cheng X.
    Wang Y.
    Zhang N.
    Fu Z.
    Chen B.
    Zhao G.
    Tongxin Xuebao/Journal on Communications, 2021, 42 (11): : 242 - 254
  • [38] Naturalistic Physical Adversarial Patch for Object Detectors
    Hu, Yu-Chih-Tuan
    Kung, Bo-Han
    Tan, Daniel Stanley
    Chen, Jun-Cheng
    Hua, Kai-Lung
    Cheng, Wen-Huang
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7828 - 7837
  • [39] Transferable Black-Box Attack Against Face Recognition With Spatial Mutable Adversarial Patch
    Ma, Haotian
    Xu, Ke
    Jiang, Xinghao
    Zhao, Zeyu
    Sun, Tanfeng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5636 - 5650
  • [40] Object-attentional untargeted adversarial attack
    Zhou, Chao
    Wang, Yuan -Gen
    Zhu, Guopu
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 81