Towards universal and sparse adversarial examples for visual object tracking

被引:4
|
作者
Sheng, Jingjing [1 ]
Zhang, Dawei [1 ]
Chen, Jianxin [2 ]
Xiao, Xin [3 ]
Zheng, Zhonglong [1 ]
机构
[1] Zhejiang Normal Univ, Sch Comp Sci & Technol, Jinhua 321000, Zhejiang, Peoples R China
[2] Jiaxing Univ, Jiaxing 314200, Zhejiang, Peoples R China
[3] Zhejiang Normal Univ, Coll Educ, Jinhua 321000, Zhejiang, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial attack; Object tracking; Adversarial examples; Black-box attack; Interference patch;
D O I
10.1016/j.asoc.2024.111252
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial attack is aimed to add small perturbations to the model that are imperceptible to humans, resulting in incorrect outputs with high confidence. Currently, adversarial attack mainly focuses on image classification and object detection tasks, but are insufficient in visual tracking. Nevertheless, existing attack methods for object tracking are limited to Siamese networks, with other types of trackers being infrequently targeted. In order to expand the usage of adversarial attacks in object tracking, we propose a model-free black-box framework for learning to generate universal and sparse adversarial examples (USAE) for tracking task. To this end, we first randomly add a noisy patch to any interference image, and then apply standard projected gradient descent to optimize the generation process of adversarial examples which is subjected to a similarity constraint with original images, making its embedding feature closer to the patched interference image in ������2-norm. Consequently, there is no significant difference between adversarial images and original images for human vision, but leading to tracking failure. Furthermore, our method just attacks 50 original images with adversarial images in each sequence, rather than an entire dataset. Numerous experiments on VOT2018, OTB2013, OTB2015, and GOT-10k datasets verify the effectiveness of USAE attack. Specifically, the number of lost reaches 1180 on VOT2018, the precision of OTB2015 decreased by 42.1%, and the success rate of GOT-10k is reduced to 1.8%, which shows the attack effect is remarkable. Moreover, USAE has a good transferability among various trackers like SiamRPN++, ATOM, DiMP, KYS, and ToMP. Notice that the proposed method is black-box and applicable to most realistic scenarios.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Accumulation of adversarial examples for underwater visual object tracking
    Zhang, Yu
    Li, Jin
    Zhang, Chenghao
    PROCEEDINGS OF 2022 IEEE INTERNATIONAL CONFERENCE ON MECHATRONICS AND AUTOMATION (IEEE ICMA 2022), 2022, : 986 - 990
  • [2] Towards Universal Adversarial Examples and Defenses
    Rakin, Adnan Siraj
    Wang, Ye
    Aeron, Shuchin
    Koike-Akino, Toshiaki
    Moulin, Pierre
    Parsons, Kieran
    2021 IEEE INFORMATION THEORY WORKSHOP (ITW), 2021,
  • [3] Adversarial Examples in Visual Object Tracking in Satellite Videos: Cross-Frame Momentum Accumulation for Adversarial Examples Generation
    Zhang, Yu
    Wang, Lingfei
    Zhang, Chenghao
    Li, Jin
    REMOTE SENSING, 2023, 15 (13)
  • [4] Physical Adversarial Textures That Fool Visual Object Tracking
    Wiyatno, Rey Reza
    Xu, Anqi
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 4821 - 4830
  • [5] Visual Object Tracking Using Positive and Negative Examples
    Wada, Toshikazu
    ROBOTICS RESEARCH, 2010, 66 : 189 - 199
  • [6] Discriminative Sparse Representation for Online Visual Object Tracking
    Bai, Tianxiang
    Li, Y. F.
    Zhou, Xiaolong
    2012 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND BIOMIMETICS (ROBIO 2012), 2012,
  • [7] EFFICIENT UNIVERSAL SHUFFLE ATTACK FOR VISUAL OBJECT TRACKING
    Liu, Siao
    Chen, Zhaoyu
    Li, Wei
    Zhu, Jiwei
    Wang, Jiafeng
    Zhang, Wenqiang
    Gan, Zhongxue
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 2739 - 2743
  • [8] IoU Attack: Towards Temporally Coherent Black-Box Adversarial Attack for Visual Object Tracking
    Jia, Shuai
    Song, Yibing
    Ma, Chao
    Yang, Xiaokang
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 6705 - 6714
  • [9] Towards Universal Physical Attacks on Single Object Tracking
    Ding, Li
    Wang, Yongwei
    Yuan, Kaiwen
    Jiang, Minyang
    Wang, Ping
    Huang, Hua
    Wang, Z. Jane
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 1236 - 1245
  • [10] Visual object tracking via online sparse instance learning
    Yan, Jia
    Chen, Xi
    Deng, Dexiang
    Zhu, Qiuping
    JOURNAL OF VISUAL COMMUNICATION AND IMAGE REPRESENTATION, 2015, 26 : 231 - 246