F&F Attack: Adversarial Attack against Multiple Object Trackers by Inducing False Negatives and False Positives
Tao Zhou, Qi Ye, Wenhan Luo, Kaihao Zhang, Zhiguo Shi, Jiming Chen
Abstract
Multi-object tracking (MOT) aims to build moving trajectories for number-agnostic objects. Modern multi-object trackers commonly follow the tracking-by-detection strategy. Therefore, fooling detectors can be an effective solution but it usually requires attacks in multiple successive frames, resulting in low efficiency. Attacking association processes improves efficiency but may require model-specific design, leading to poor generalization. In this paper, we propose a novel False negative and False positive attack (F&F attack) mechanism: it perturbs the input image to erase original detections and to inject deceptive false alarms around original ones while integrating the association attack implicitly. The mechanism can produce effective identity switches against multi-object trackers by only fooling detectors in a few frames. To demonstrate the flexibility of the mechanism, we deploy it to three multi-object trackers (Byte-Track, SORT, and CenterTrack) which are enabled by two representative detectors (YOLOX and CenterNet). Comprehensive experiments on MOT17 and MOT20 datasets show that our method significantly outperforms existing attackers, revealing the vulnerability of the tracking-by-detection paradigm to detection attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2734a1ac-e05f-4df0-a230-9d90cc05a658Cited by top-tier papers1
Ask how each one uses itBuilds on10
- TrackFormer: Multi-Object Tracking with TransformersTim Meinhardt, Alexander Kirillov, Laura Leal-Taixé, Christoph FeichtenhoferCVPR 2022 · 927 citations
- Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural PhenomenonYiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang et al.CVPR 2022 · 148 citations
- Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object TrackingYunhan Jia, Yantao Lu, Junjie Shen, Qi Alfred Chen et al.ICLR 2020 · 113 citations
- APPTracker: Improving Tracking Multiple Objects in Low-Frame-Rate VideosTao Zhou, Wenhan Luo, Zhiguo Shi, Jiming Chen et al.ACM MM 2022 · 10 citations
- Cooling-Shrinking Attack: Blinding the Tracker With Imperceptible NoisesBin Yan, Dong Wang, Huchuan Lu, Xiaoyun YangCVPR 2020
Related papers
- UTM: A Unified Multiple Object Tracking Model with Identity-Aware Feature EnhancementSisi You, Hantao Yao, Bing-Kun Bao, Changsheng XuCVPR 2023
- DeconfuseTrack: Dealing with Confusion for Multi-Object TrackingCheng Huang, Shoudong Han, Mengyu He, Wenbo Zheng et al.CVPR 2024
- DiffusionTrack: Diffusion Model for Multi-Object TrackingRun Luo, Zikai Song, Lintao Ma, Jinlin Wei et al.AAAI 2024 · 77 citations
- NumbOD: A Spatial-Frequency Fusion Attack Against Object DetectorsZiqi Zhou, Bowen Li, Yufei Song, Zhifei Yu et al.AAAI 2025 · 20 citations
- Follow-me: Deceiving Trackers with Fabricated PathsShengtao Lou, Buyu Liu, Jun Bao, Jiajun Ding et al.ACM MM 2023
