Exploring the Adversarial Robustness of Video Object Segmentation via One-shot Adversarial Attacks
Kaixun Jiang, Lingyi Hong, Zhaoyu Chen, Pinxue Guo, Zeng Tao, Yan Wang, Wenqiang Zhang
Abstract
Video object segmentation (VOS) is a fundamental task for computer vision and multimedia. Despite significant progress of VOS models in recent works, there has been little research on the VOS models' adversarial robustness, posing serious security risks in the VOS models' practical applications (e.g., autonomous driving and video surveillance). Adversarial robustness refers to the ability of the model to resist malicious attacks on adversarial examples. To address this gap, we propose a one-shot adversarial robustness evaluation framework (i.e., the adversary only perturbs the first frame) for VOS models, including white-box and black-box attacks. For white-box attacks, we introduce Objective Attention (OA) and Boundary Attention (BA) mechanisms to enhance the attention of attack on objects from both pixel and object levels while mitigating issues such as multi-objects attack imbalance, attack bias towards the background, and boundary reservation. For black-box attacks, we propose the Video Diverse Input (VDI) module, which utilizes data augmentation to simulate historical information, improving our method's black-box transferability. We conduct extensive experiments to evaluate the adversarial robustness of VOS models with different structures. Our experimental results reveal that existing VOS models are more vulnerable to our attacks (both white-box and black-box) compared to other state-of-the-art attacks. We further analyze the influence of different designs (e.g., memory and matching mechanisms) on adversarial robustness. Finally, we provide insights for designing more secure VOS models in the future.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a0d241c3-9dba-4287-8646-8e635b6c91b4Cited by top-tier papers5
- Fit the Distribution: Cross-Image/Prompt Adversarial Attacks on Multimodal Large Language ModelsHai Yan, Haijian Ma, Xiaowen Cai, Daizong Liu et al.NeurIPS 2025 · 21 citations
- Vanish into Thin Air: Cross-prompt Universal Adversarial Attacks for SAM2Ziqi Zhou, Yifan Hu, Yufei Song, Zijing Li et al.NeurIPS 2025 · 17 citations
- Enhancing Diffusion-based Unrestricted Adversarial Attacks via Adversary Preferences AlignmentKaixun Jiang, Zhaoyu Chen, Haijing Guo, Jinglun Li et al.NeurIPS 2025 · 4 citations
- Boosting Adversarial Transferability with Spatial Adversarial AlignmentZhaoyu Chen, Haijing Guo, Kaixun Jiang, Jiyuan Fu et al.NeurIPS 2025 · 4 citations
- TagOOD: A Novel Approach to Out-of-Distribution Detection via Vision-Language Representations and Class Center LearningJinglun Li, Xinyu Zhou, Kaixun Jiang, Lingyi Hong et al.ACM MM 2024 · 1 citation
Related papers
- One-Shot Adversarial Attacks on Visual Tracking With Dual AttentionXuesong Chen, Xiyu Yan, Feng Zheng, Yong Jiang et al.CVPR 2020
- Towards Robust Video Object Segmentation with Adaptive Object CalibrationXiaohao Xu, Jinglu Wang, Xiang Ming, Yan LuACM MM 2022 · 21 citations
- Heuristic Black-Box Adversarial Attacks on Video Recognition ModelsZhipeng Wei, Jingjing Chen, Xingxing Wei, Linxi Jiang et al.AAAI 2020 · 84 citations
- Ensemble-based Blackbox Attacks on Dense PredictionZikui Cai, Yaoteng Tan, M. Salman AsifCVPR 2023
- Where Can We Help? A Visual Analytics Approach to Diagnosing and Improving Semantic Segmentation of Movable ObjectsWenbin He, Lincan Zou, Arvind Kumar Shekar, Liang Gou et al.IEEE VIS 2021 · 45 citations
