Physical Hijacking Attacks against Object Trackers
Raymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li, Ryan M. Gerdes
Abstract
Modern autonomous systems rely on both object detection and object tracking in their visual perception pipelines. Although many recent works have attacked the object detection component of autonomous vehicles, these attacks do not work on full pipelines that integrate object tracking to enhance the object detector's accuracy. Meanwhile, existing attacks against object tracking either lack real-world applicability or do not work against a powerful class of object trackers, Siamese trackers. In this paper, we present AttrackZone, a new physically-realizable tracker hijacking attack against Siamese trackers that systematically determines valid regions in an environment that can be used for physical perturbations. AttrackZone exploits the heatmap generation process of Siamese Region Proposal Networks in order to take control of an object's bounding box, resulting in physical consequences including vehicle collisions and masked intrusion of pedestrians into unauthorized areas. Evaluations in both the digital and physical domain show that AttrackZone achieves its attack goals 92% of the time, requiring only 0.3-3 seconds on average. CCS CONCEPTS • Computing methodologies → Machine learning algorithms; • Security and privacy → Systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 338f4923-69d9-41cc-a3d1-737a6ec88004Cited by top-tier papers15
- SlowTrack: Increasing the Latency of Camera-Based Perception in Autonomous Driving Using Adversarial ExamplesChen Ma, Ningfei Wang, Qi Alfred Chen, Chao ShenAAAI 2024 · 44 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- A First Physical-World Trajectory Prediction Attack via LiDAR-induced Deceptions in Autonomous DrivingYang Lou, Yi Zhu, Qun Song, Rui Tan et al.USENIX Security 2024 · 11 citations
- VOGUES: Validation of Object Guise using Estimated ComponentsRaymond Muller, Yanmao Man, Ming Li, Ryan M. Gerdes et al.USENIX Security 2024 · 10 citations
- FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking SystemsShaoyuan Xie, Mohamad Habib Fakih, Junchi Lu, Fayzah Alshammari et al.NDSS 2026 · 5 citations
Builds on13
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Seeing isn't Believing: Towards More Robust Adversarial Attack Against Real World Object DetectorsYue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen et al.CCS 2019 · 239 citations
- Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object TrackingYunhan Jia, Yantao Lu, Junjie Shen, Qi Alfred Chen et al.ICLR 2020 · 113 citations
- Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer VisionXiaoyu Ji, Yushi Cheng, Yuepeng Zhang, Kai Wang et al.S&P 2021 · 99 citations
Related papers
- ControlLoc: Physical-World Hijacking Attack on Camera-based Perception in Autonomous DrivingChen Ma, Ningfei Wang, Zhengyu Zhao, Qian Wang et al.CCS 2025
- One-Shot Adversarial Attacks on Visual Tracking With Dual AttentionXuesong Chen, Xiyu Yan, Feng Zheng, Yong Jiang et al.CVPR 2020
- Follow-me: Deceiving Trackers with Fabricated PathsShengtao Lou, Buyu Liu, Jun Bao, Jiajun Ding et al.ACM MM 2023
- A Unified Multi-Scenario Attacking Network for Visual Object TrackingXuesong Chen, Canmiao Fu, Feng Zheng, Yong Zhao et al.AAAI 2021 · 20 citations
- Phantom: Physical Object Interactions as Dynamic Triggers for NMS-Exploited BackdoorsTianlin Huo, Dongchuan Ran, Ranjie Duan, Yao Zhu et al.CVPR 2026
