Merry Go Round: Rotate a Frame and Fool a DNN
Daksh Thapar, Aditya Nigam, Chetan Arora
Abstract
A large proportion of videos captured today are first person videos shot from wearable cameras. Similar to other computer vision tasks, Deep Neural Networks (DNNs) are the workhorse for most state-of-the-art (SOTA) egocentric vision techniques. On the other hand DNNs are known to be susceptible to Adversarial Attacks (AAs) which add imperceptible noise to the input. Both black-box, as well as white-box attacks on image as well as video analysis tasks have been shown. We observe that most AA techniques basically add intensity perturbation to an image. Even for videos, the same process is essentially repeated for each frame independently. We note that definition of imperceptibility used for images may not be applicable for videos, where a small intensity change happening randomly in two consecutive frames may still be perceptible. In this paper we make a key novel suggestion to use perturbation in optical flow to carry out AAs on a video analysis system. Such perturbation is especially useful for egocentric videos, because there is lot of shake in the egocentric videos anyways, and adding a little more, keeps it highly imperceptible. In general our idea can be seen as adding structured, parametric noise as the adversarial perturbation. Our implementation of the idea by adding 3D rotations to the frames, reveal that using our technique, one can mount a black-box AA on an egocentric activity detection system in one-third of the queries compared to the SOTA AA technique.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ae09428e-0c12-4dc2-896e-040ff8252288Builds on5
- SlowFast Networks for Video RecognitionChristoph Feichtenhofer, Haoqi Fan, Jitendra Malik, Kaiming HeICCV 2019 · 4,104 citations
- Query-efficient Meta Attack to Deep Neural NetworksJiawei Du, Hu Zhang, Joey Tianyi Zhou, Yi Yang et al.ICLR 2020 · 87 citations
- Heuristic Black-Box Adversarial Attacks on Video Recognition ModelsZhipeng Wei, Jingjing Chen, Xingxing Wei, Linxi Jiang et al.AAAI 2020 · 84 citations
- FASTER Recurrent Networks for Efficient Video ClassificationLinchao Zhu, Du Tran, Laura Sevilla-Lara, Yi Yang et al.AAAI 2020 · 60 citations
- Concept Drift Detection for Multivariate Data Streams and Temporal Segmentation of Daylong Egocentric VideosPravin Nagar, Mansi Khemka, Chetan AroraACM MM 2020 · 9 citations
Related papers
- Anonymizing Egocentric VideosDaksh Thapar, Aditya Nigam, Chetan AroraICCV 2021 · 9 citations
- Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition SystemsShangyu Xie, Han Wang, Yu Kong, Yuan HongS&P 2022 · 32 citations
- Efficient Sparse Attacks on Videos using Reinforcement LearningHuanqian Yan, Xingxing WeiACM MM 2021 · 19 citations
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 93 citations
- Over-the-Air Adversarial Flickering Attacks Against Video Recognition NetworksRoi Pony, Itay Naeh, Shie MannorCVPR 2021
