IoU Attack: Towards Temporally Coherent Black-Box Adversarial Attack for Visual Object Tracking
Shuai Jia, Yibing Song, Chao Ma, Xiaokang Yang
Abstract
Adversarial attack arises due to the vulnerability of deep neural networks to perceive input samples injected with imperceptible perturbations. Recently, adversarial attack has been applied to visual object tracking to evaluate the robustness of deep trackers. Assuming that the model structures of deep trackers are known, a variety of white-box attack approaches to visual tracking have demonstrated promising results. However, the model knowledge about deep trackers is usually unavailable in real applications. In this paper, we propose a decision-based black-box attack method for visual object tracking. In contrast to existing black-box adversarial attack methods that deal with static images for image classification, we propose IoU attack that sequentially generates perturbations based on the predicted IoU scores from both current and historical frames. By decreasing the IoU scores, the proposed attack method degrades the accuracy of temporal coherent bounding boxes (i.e., object motions) accordingly. In addition, we transfer the learned perturbations to the next few frames to initialize temporal motion attack. We validate the proposed IoU attack on stateof-the-art deep trackers (i.e., detection based, correlation filter based, and long-term trackers). Extensive experiments on the benchmark datasets indicate the effectiveness of the proposed IoU attack method. The source code is available at https://github.com/VISION-SJTU/IoUattack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c8b49580-3f78-4188-9799-e2cf336c5db7Cited by top-tier papers12
- RULER: discriminative and iterative adversarial training for deep neural network fairnessGuanhong Tao, Weisong Sun, Tingxu Han, Chunrong Fang et al.FSE 2022 · 29 citations
- Appearance and Structure Aware Robust Deep Visual Graph Matching: Attack, Defense and BeyondQibing Ren, Qingquan Bao, Runzhong Wang, Junchi YanCVPR 2022 · 10 citations
- On the Robustness of Neural-Enhanced Video Streaming against Adversarial AttacksQihua Zhou, Jingcai Guo, Song Guo, Ruibin Li et al.AAAI 2024 · 7 citations
- CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared DetectorsJiahuan Long, Wen Yao, Tingsong Jiang, Jiacheng Hou et al.ACM MM 2025 · 7 citations
- LRR: Language-Driven Resamplable Continuous Representation against Adversarial Tracking AttacksJianlang Chen, Xuhong Ren, Qing Guo, Felix Juefei-Xu et al.ICLR 2024 · 6 citations
Builds on14
- Learning Discriminative Model Prediction for TrackingGoutam Bhat, Martin Danelljan, Luc Van Gool, Radu TimofteICCV 2019 · 1,294 citations
- Learning the Model Update for Siamese TrackersLichao Zhang, Abel Gonzalez-Garcia, Joost van de Weijer, Martin Danelljan et al.ICCV 2019 · 371 citations
- 'Skimming-Perusal' Tracking: A Framework for Real-Time and Robust Long-Term TrackingBin Yan, Haojie Zhao, Dong Wang, Huchuan Lu et al.ICCV 2019 · 177 citations
- Physical Adversarial Textures That Fool Visual Object TrackingRey Wiyatno, Anqi XuICCV 2019 · 88 citations
- Stabilized Medical Image AttacksGege Qi, Lijun Gong, Yibing Song, Kai Ma et al.ICLR 2021 · 34 citations
Related papers
- Follow-me: Deceiving Trackers with Fabricated PathsShengtao Lou, Buyu Liu, Jun Bao, Jiajun Ding et al.ACM MM 2023
- A Unified Multi-Scenario Attacking Network for Visual Object TrackingXuesong Chen, Canmiao Fu, Feng Zheng, Yong Zhao et al.AAAI 2021 · 20 citations
- One-Shot Adversarial Attacks on Visual Tracking With Dual AttentionXuesong Chen, Xiyu Yan, Feng Zheng, Yong Jiang et al.CVPR 2020
- Learning to Adversarially Blur Visual Object TrackingQing Guo, Ziyi Cheng, Felix Juefei-Xu, Lei Ma et al.ICCV 2021 · 52 citations
- ColorFool: Semantic Adversarial ColorizationAli Shahin Shamsabadi, Ricardo Sánchez-Matilla, Andrea CavallaroCVPR 2020
