Towards universal and sparse adversarial examples for visual object tracking

被引:4
|
作者
Sheng, Jingjing [1 ]
Zhang, Dawei [1 ]
Chen, Jianxin [2 ]
Xiao, Xin [3 ]
Zheng, Zhonglong [1 ]
机构
[1] Zhejiang Normal Univ, Sch Comp Sci & Technol, Jinhua 321000, Zhejiang, Peoples R China
[2] Jiaxing Univ, Jiaxing 314200, Zhejiang, Peoples R China
[3] Zhejiang Normal Univ, Coll Educ, Jinhua 321000, Zhejiang, Peoples R China
基金
中国国家自然科学基金;
关键词
Adversarial attack; Object tracking; Adversarial examples; Black-box attack; Interference patch;
D O I
10.1016/j.asoc.2024.111252
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial attack is aimed to add small perturbations to the model that are imperceptible to humans, resulting in incorrect outputs with high confidence. Currently, adversarial attack mainly focuses on image classification and object detection tasks, but are insufficient in visual tracking. Nevertheless, existing attack methods for object tracking are limited to Siamese networks, with other types of trackers being infrequently targeted. In order to expand the usage of adversarial attacks in object tracking, we propose a model-free black-box framework for learning to generate universal and sparse adversarial examples (USAE) for tracking task. To this end, we first randomly add a noisy patch to any interference image, and then apply standard projected gradient descent to optimize the generation process of adversarial examples which is subjected to a similarity constraint with original images, making its embedding feature closer to the patched interference image in ������2-norm. Consequently, there is no significant difference between adversarial images and original images for human vision, but leading to tracking failure. Furthermore, our method just attacks 50 original images with adversarial images in each sequence, rather than an entire dataset. Numerous experiments on VOT2018, OTB2013, OTB2015, and GOT-10k datasets verify the effectiveness of USAE attack. Specifically, the number of lost reaches 1180 on VOT2018, the precision of OTB2015 decreased by 42.1%, and the success rate of GOT-10k is reduced to 1.8%, which shows the attack effect is remarkable. Moreover, USAE has a good transferability among various trackers like SiamRPN++, ATOM, DiMP, KYS, and ToMP. Notice that the proposed method is black-box and applicable to most realistic scenarios.
引用
收藏
页数:12
相关论文
共 50 条
  • [41] Physically Realizable Adversarial Examples for LiDAR Object Detection
    Tu, James
    Ren, Mengye
    Manivasagam, Sivabalan
    Liang, Ming
    Yang, Bin
    Du, Richard
    Cheng, Frank
    Urtasun, Raquel
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2020), 2020, : 13713 - 13722
  • [42] Adversarial examples based on object detection tasks: A survey
    Mi, Jian-Xun
    Wang, Xu-Dong
    Zhou, Li -Fang
    Cheng, Kun
    NEUROCOMPUTING, 2023, 519 : 114 - 126
  • [43] Universal Sparse Adversarial Attack on Video Recognition Models
    Li, Haoxuan
    Wang, Zheng
    INTERNATIONAL JOURNAL OF MULTIMEDIA DATA ENGINEERING & MANAGEMENT, 2021, 12 (03):
  • [44] On the Relationship Between Universal Adversarial Attacks and Sparse Representations
    Weitzner, Dana
    Giryes, Raja
    IEEE OPEN JOURNAL OF SIGNAL PROCESSING, 2023, 4 : 99 - 107
  • [45] Visual Moving Object Tracking via Sparse Representation Based Trackers: A Comparative Study
    Moujahid, Driss
    Elharrouss, Omar
    Tairi, Hamid
    PROCEEDINGS OF 2015 THIRD IEEE WORLD CONFERENCE ON COMPLEX SYSTEMS (WCCS), 2015,
  • [46] Visual object tracking via sample-based Adaptive Sparse Representation (AdaSR)
    Han, Zhenjun
    Jiao, Jianbin
    Zhang, Baochang
    Ye, Qixiang
    Liu, Jianzhuang
    PATTERN RECOGNITION, 2011, 44 (09) : 2170 - 2183
  • [47] Online Object Tracking With Sparse Prototypes
    Wang, Dong
    Lu, Huchuan
    Yang, Ming-Hsuan
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2013, 22 (01) : 314 - 325
  • [48] Visual Tracking Based on the Adaptive Color Attention Tuned Sparse Generative Object Model
    Tian, Chunna
    Gao, Xinbo
    Wei, Wei
    Zheng, Hong
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2015, 24 (12) : 5236 - 5248
  • [49] Visual object tracking via time-space constraints and sparse representation classification
    Kuang, Jin-Jun
    Chai, Yi
    Xiong, Qing-Yu
    Kongzhi yu Juece/Control and Decision, 2013, 28 (09): : 1355 - 1360
  • [50] Generating Black-Box Adversarial Examples in Sparse Domain
    Zanddizari, Hadi
    Zeinali, Behnam
    Chang, J. Morris
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTATIONAL INTELLIGENCE, 2022, 6 (04): : 795 - 804