On the Robustness of Neural-Enhanced Video Streaming against Adversarial Attacks
Qihua Zhou, Jingcai Guo, Song Guo, Ruibin Li, Jie Zhang, Bingjie Wang, Zhenda Xu
Abstract
The explosive growth of video traffic on today's Internet promotes the rise of Neural-enhanced Video Streaming (NeVS), which effectively improves the rate-distortion trade-off by employing a cheap neural super-resolution model for quality enhancement on the receiver side. Missing by existing work, we reveal that the NeVS pipeline may suffer from a practical threat, where the crucial codec component (i.e., encoder for compression and decoder for restoration) can trigger adversarial attacks in a man-in-the-middle manner to significantly destroy video recovery performance and finally incurs the malfunction of downstream video perception tasks. In this paper, we are the first attempt to inspect the vulnerability of NeVS and discover a novel adversarial attack, called codec hijacking, where the injected invisible perturbation conspires with the malicious encoding matrix by reorganizing the spatial-temporal bit allocation within the bitstream size budget. Such a zero-day vulnerability makes our attack hard to defend because there is no visual distortion on the recovered videos until the attack happens. More seriously, this attack can be extended to diverse enhancement models, thus exposing a wide range of video perception tasks under threat. Evaluation based on state-of-the-art video codec benchmark illustrates that our attack significantly degrades the recovery performance of NeVS over previous attack methods. The damaged video quality finally leads to obvious malfunction of downstream tasks with over 75% success rate. We hope to arouse public attention on codec hijacking and its defence.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6bf2f25e-2219-4f94-9581-4bb971a3f4a8Builds on16
- BasicVSR++: Improving Video Super-Resolution with Enhanced Propagation and AlignmentKelvin C. K. Chan, Shangchen Zhou, Xiangyu Xu, Chen Change LoyCVPR 2022 · 522 citations
- Deep Contextual Video CompressionJiahao Li, Bin Li, Yan LuNeurIPS 2021 · 518 citations
- Towards Transferable Adversarial Attacks on Vision TransformersZhipeng Wei, Jingjing Chen, Micah Goldblum, Zuxuan Wu et al.AAAI 2022 · 156 citations
- FDA: Feature Disruptive AttackAditya Ganeshan, Vivek B. S., Venkatesh Babu RadhakrishnanICCV 2019 · 136 citations
- YuZu: Neural-Enhanced Volumetric Video StreamingAnlan Zhang, Chendong Wang, Bo Han, Feng QianNSDI 2022 · 115 citations
Related papers
- DeNC: Unleash Neural Codecs in Video Streaming with Diffusion EnhancementQihua Zhou, Ruibin Li, Jingcai Guo, Yaodong Huang et al.AAAI 2025 · 2 citations
- DeNC++: Efficient Diffusion-Enhanced Neural Codec for End-to-end Semantic Streaming at the EdgeQihua Zhou, Wangjiang Gong, Zili Meng, Yaxiong Xie et al.AAAI 2026
- RoVISQ: Reduction of Video Service Quality via Adversarial Attacks on Deep Learning-based Video CompressionJung-Woo Chang, Mojan Javaheripi, Seira Hidano, Farinaz KoushanfarNDSS 2023
- VideoFlip: Adversarial Bit Flips for Reducing Video Service QualityJung-Woo Chang, Mojan Javaheripi, Farinaz KoushanfarDAC 2023 · 3 citations
- Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object TrackingYunhan Jia, Yantao Lu, Junjie Shen, Qi Alfred Chen et al.ICLR 2020 · 113 citations
