One-Shot Adversarial Attacks on Visual Tracking With Dual Attention
Xuesong Chen, Xiyu Yan, Feng Zheng, Yong Jiang, Shu-Tao Xia, Yong Zhao, Rongrong Ji
Abstract
Almost all adversarial attacks in computer vision are aimed at pre-known object categories, which could be offline trained for generating perturbations. But as for visual object tracking, the tracked target categories are normally unknown in advance. However, the tracking algorithms also have potential risks of being attacked, which could be maliciously used to fool the surveillance systems. Meanwhile, it is still a challenging task that adversarial attacks on tracking since it has the free-model tracked target. Therefore, to help draw more attention to the potential risks, we study adversarial attacks on tracking algorithms. In this paper, we propose a novel one-shot adversarial attack method to generate adversarial examples for free-model single object tracking, where merely adding slight perturbations on the target patch in the initial frame causes state-of-the-art trackers to lose the target in subsequent frames. Specifically, the optimization objective of the proposed attack consists of two components and leverages the dual attention mechanisms. The first component adopts a targeted attack strategy by optimizing the batch confidence loss with confidence attention while the second one applies a general perturbation strategy by optimizing the feature loss with channel attention. Experimental results show that our approach can significantly lower the accuracy of the most advanced Siamese network-based trackers on three benchmarks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a3a0986e-dc0e-4d8b-8233-7d1fa3e4ba3eCited by top-tier papers12
- MLVSNet: Multi-level Voting Siamese Network for 3D Visual TrackingZhoutao Wang, Qian Xie, Yu-Kun Lai, Jing Wu et al.ICCV 2021 · 60 citations
- Learning to Adversarially Blur Visual Object TrackingQing Guo, Ziyi Cheng, Felix Juefei-Xu, Lei Ma et al.ICCV 2021 · 52 citations
- Towards Universal Physical Attacks on Single Object TrackingLi Ding, Yongwei Wang, Kaiwen Yuan, Minyang Jiang et al.AAAI 2021 · 48 citations
- A Unified Multi-Scenario Attacking Network for Visual Object TrackingXuesong Chen, Canmiao Fu, Feng Zheng, Yong Zhao et al.AAAI 2021 · 20 citations
- F&F Attack: Adversarial Attack against Multiple Object Trackers by Inducing False Negatives and False PositivesTao Zhou, Qi Ye, Wenhan Luo, Kaihao Zhang et al.ICCV 2023 · 13 citations
Builds on2
Related papers
- Follow-me: Deceiving Trackers with Fabricated PathsShengtao Lou, Buyu Liu, Jun Bao, Jiajun Ding et al.ACM MM 2023
- Cooling-Shrinking Attack: Blinding the Tracker With Imperceptible NoisesBin Yan, Dong Wang, Huchuan Lu, Xiaoyun YangCVPR 2020
- BadTrack: A Poison-Only Backdoor Attack on Visual Object TrackingBin Huang, Jiaqian Yu, Yiwei Chen, Siyang Pan et al.NeurIPS 2023 · 7 citations
- IoU Attack: Towards Temporally Coherent Black-Box Adversarial Attack for Visual Object TrackingShuai Jia, Yibing Song, Chao Ma, Xiaokang YangCVPR 2021
- Discriminative and Robust Online Learning for Siamese Visual TrackingJinghao Zhou, Peng Wang, Haoyang SunAAAI 2020 · 66 citations
