Towards universal and sparse adversarial examples for visual object tracking

被引:4
|
作者
Sheng, Jingjing [1 ]
Zhang, Dawei [1 ]
Chen, Jianxin [2 ]
Xiao, Xin [3 ]
Zheng, Zhonglong [1 ]
机构
[1] Zhejiang Normal Univ, Sch Comp Sci & Technol, Jinhua 321000, Zhejiang, Peoples R China
[2] Jiaxing Univ, Jiaxing 314200, Zhejiang, Peoples R China
[3] Zhejiang Normal Univ, Coll Educ, Jinhua 321000, Zhejiang, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial attack; Object tracking; Adversarial examples; Black-box attack; Interference patch;
D O I
10.1016/j.asoc.2024.111252
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial attack is aimed to add small perturbations to the model that are imperceptible to humans, resulting in incorrect outputs with high confidence. Currently, adversarial attack mainly focuses on image classification and object detection tasks, but are insufficient in visual tracking. Nevertheless, existing attack methods for object tracking are limited to Siamese networks, with other types of trackers being infrequently targeted. In order to expand the usage of adversarial attacks in object tracking, we propose a model-free black-box framework for learning to generate universal and sparse adversarial examples (USAE) for tracking task. To this end, we first randomly add a noisy patch to any interference image, and then apply standard projected gradient descent to optimize the generation process of adversarial examples which is subjected to a similarity constraint with original images, making its embedding feature closer to the patched interference image in ������2-norm. Consequently, there is no significant difference between adversarial images and original images for human vision, but leading to tracking failure. Furthermore, our method just attacks 50 original images with adversarial images in each sequence, rather than an entire dataset. Numerous experiments on VOT2018, OTB2013, OTB2015, and GOT-10k datasets verify the effectiveness of USAE attack. Specifically, the number of lost reaches 1180 on VOT2018, the precision of OTB2015 decreased by 42.1%, and the success rate of GOT-10k is reduced to 1.8%, which shows the attack effect is remarkable. Moreover, USAE has a good transferability among various trackers like SiamRPN++, ATOM, DiMP, KYS, and ToMP. Notice that the proposed method is black-box and applicable to most realistic scenarios.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] Universal adversarial examples and perturbations for quantum classifiers
    Gong, Weiyuan
    Deng, Dong-Ling
    NATIONAL SCIENCE REVIEW, 2022, 9 (06)
  • [22] Targeted Universal Adversarial Examples for Remote Sensing
    Bai, Tao
    Wang, Hao
    Wen, Bihan
    REMOTE SENSING, 2022, 14 (22)
  • [23] Topology-aware universal adversarial attack on 3D object tracking
    Riran Cheng
    Xupeng Wang
    Ferdous Sohel
    Hang Lei
    Visual Intelligence, 1 (1):
  • [24] Remix: Towards the transferability of adversarial examples
    Zhao, Hongzhi
    Hao, Lingguang
    Hao, Kuangrong
    Wei, Bing
    Cai, Xin
    NEURAL NETWORKS, 2023, 163 : 367 - 378
  • [25] Towards Robust Detection of Adversarial Examples
    Pang, Tianyu
    Du, Chao
    Dong, Yinpeng
    Zhu, Jun
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 31 (NIPS 2018), 2018, 31
  • [26] Towards Transferable Targeted Adversarial Examples
    Wang, Zhibo
    Yang, Hongshan
    Feng, Yunhe
    Sun, Peng
    Guo, Hengchang
    Zhang, Zhifei
    Ren, Kui
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 20534 - 20543
  • [27] A semantic visual SLAM towards object selection and tracking optimization
    Sun, Tian
    Cheng, Lei
    Hu, Yaqi
    Yuan, Xiaoping
    Liu, Yong
    APPLIED INTELLIGENCE, 2024, 54 (22) : 11311 - 11324
  • [28] Adversarial Examples on Object Recognition: A Comprehensive Survey
    Serban, Alex
    Poll, Erik
    Visser, Joost
    ACM COMPUTING SURVEYS, 2020, 53 (03)
  • [29] Adversarial Examples for Semantic Segmentation and Object Detection
    Xie, Cihang
    Wang, Jianyu
    Zhang, Zhishuai
    Zhou, Yuyin
    Xie, Lingxi
    Yuille, Alan
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2017, : 1378 - 1387
  • [30] Visual Object Tracking via Multi-view and Group Sparse Representation
    Mo, Borui
    He, Ke
    Men, Aidong
    2016 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA (ICCC), 2016,