Defending Black-Box Skeleton-Based Human Activity Classifiers
He Wang, Yunfeng Diao, Zichang Tan, Guodong Guo
Abstract
Skeletal motions have been heavily relied upon for human activity recognition (HAR). Recently, a universal vulnerability of skeleton-based HAR has been identified across a variety of classifiers and data, calling for mitigation. To this end, we propose the first black-box defense method for skeletonbased HAR to our best knowledge. Our method is featured by full Bayesian treatments of the clean data, the adversaries and the classifier, leading to (1) a new Bayesian Energy-based formulation of robust discriminative classifiers, (2) a new adversary sampling scheme based on natural motion manifolds, and (3) a new post-train Bayesian strategy for black-box defense. We name our framework Bayesian Energy-based Adversarial Training or BEAT. BEAT is straightforward but elegant, which turns vulnerable black-box classifiers into robust ones without sacrificing accuracy. It demonstrates surprising and universal effectiveness across a wide range of skeletal HAR classifiers and datasets, under various attacks. Code is available at https://github.com/realcrane/Defending- Black-box-Skeleton-based-Human-Activity-Classifiers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 01663134-2197-4490-9a80-a10bc2e25e0eCited by top-tier papers2
- Hard No-Box Adversarial Attack on Skeleton-Based Human Action Recognition with Skeleton-Motion-Informed GradientZhengzhi Lu, He Wang, Ziyi Chang, Guoan Yang et al.ICCV 2023 · 17 citations
- TASAR: Transfer-based Attack on Skeletal Action RecognitionYunfeng Diao, Baiqi Wu, Ruixuan Zhang, Ajian Liu et al.ICLR 2025
Builds on25
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Channel-wise Topology Refinement Graph Convolution for Skeleton-Based Action RecognitionYuxin Chen, Ziqi Zhang, Chunfeng Yuan, Bing Li et al.ICCV 2021 · 871 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- Your classifier is secretly an energy based model and you should treat it like oneWill Grathwohl, Kuan-Chieh Wang, Jörn-Henrik Jacobsen, David Duvenaud et al.ICLR 2020 · 643 citations
Related papers
- BASAR: Black-Box Attack on Skeletal Action RecognitionYunfeng Diao, Tianjia Shao, Yongliang Yang, Kun Zhou et al.CVPR 2021
- Understanding the Robustness of Skeleton-Based Action Recognition Under Adversarial AttackHe Wang, Feixiang He, Zhexi Peng, Tianjia Shao et al.CVPR 2021
- Adversarial Bone Length Attack on Action RecognitionNariki Tanaka, Hiroshi Kera, Kazuhiko KawamotoAAAI 2022 · 18 citations
- Universal Targeted Adversarial Attacks Against mmWave-based Human Activity RecognitionYucheng Xie, Ruizhe Jiang, Xiaonan Guo, Yan Wang et al.INFOCOM 2023 · 11 citations
- Stochastic Security: Adversarial Defense Using Long-Run Dynamics of Energy-Based ModelsMitch Hill, Jonathan Craig Mitchell, Song-Chun ZhuICLR 2021 · 93 citations
