Attacking Optical Flow
Anurag Ranjan, Joel Janai, Andreas Geiger, Michael J. Black
Abstract
Deep neural nets achieve state-of-the-art performance on the problem of optical flow estimation. Since optical flow is used in several safety-critical applications like self-driving cars, it is important to gain insights into the robustness of those techniques. Recently, it has been shown that adversarial attacks easily fool deep neural networks to misclassify objects. The robustness of optical flow networks to adversarial attacks, however, has not been studied so far. In this paper, we extend adversarial patch attacks to optical flow networks and show that such attacks can compromise their performance. We show that corrupting a small patch of less than 1% of the image size can significantly affect optical flow estimates. Our attacks lead to noisy flow estimates that extend significantly beyond the region of the attack, in many cases even completely erasing the motion of objects in the scene. While networks using an encoder-decoder architecture are very sensitive to these attacks, we found that networks using a spatial pyramid architecture are less affected. We analyse the success and failure of attacking both architectures by visualizing their feature maps and comparing them to classical optical flow techniques which are robust to these attacks. We also demonstrate that such attacks are practical by placing a printed pattern into real scenes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8fe71464-efc8-4331-85bd-7d227f4ea9d3Cited by top-tier papers23
- Assaying Out-Of-Distribution Generalization in Transfer LearningFlorian Wenzel, Andrea Dittadi, Peter V. Gehler, Carl-Johann Simon-Gabriel et al.NeurIPS 2022 · 93 citations
- Targeted Adversarial Perturbations for Monocular Depth PredictionAlex Wong, Safa Cicek, Stefano SoattoNeurIPS 2020 · 61 citations
- Efficient Certified Defenses Against Patch Attacks on Image ClassifiersJan Hendrik Metzen, Maksym YatsuraICLR 2021 · 48 citations
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang et al.ACM MM 2020 · 40 citations
- Certified Patch Robustness via Smoothed Vision TransformersHadi Salman, Saachi Jain, Eric Wong, Aleksander MadryCVPR 2022 · 40 citations
Builds on1
Related papers
- Towards Understanding Adversarial Robustness of Optical Flow NetworksSimon Schrodi, Tonmoy Saikia, Thomas BroxCVPR 2022 · 14 citations
- Shape and Texture: What Influences Reliable Optical Flow Estimation?Libo Long, Xiao Hu, Jochen LangCVPR 2025
- BadPart: Unified Black-box Adversarial Patch Attacks against Pixel-wise Regression TasksZhiyuan Cheng, Zhaoyi Liu, Tengda Guo, Shiwei Feng et al.ICML 2024 · 10 citations
- Stereoscopic Universal Perturbations across Different Architectures and DatasetsZachary Berger, Parth Agrawal, Tian Yu Liu, Stefano Soatto et al.CVPR 2022 · 8 citations
- Fooling LiDAR Perception via Adversarial Trajectory PerturbationYiming Li, Congcong Wen, Felix Juefei-Xu, Chen FengICCV 2021 · 69 citations
