Watch out! Motion is Blurring the Vision of Your Deep Neural Networks
Qing Guo, Felix Juefei-Xu, Xiaofei Xie, Lei Ma, Jian Wang, Bing Yu, Wei Feng, Yang Liu
Abstract
The state-of-the-art deep neural networks (DNNs) are vulnerable to adversarial examples with additive random noise-like perturbations. While such examples are hardly found in the physical world, the image blurring effect caused by object motion, on the other hand, commonly occurs in practice, making the study of which greatly important especially for the widely adopted real-time image processing tasks (e.g., object detection, tracking). In this paper, we initiate the first step to comprehensively investigate the potential hazards of blur effect for DNN, caused by object motion. We propose a novel adversarial attack method that can generate visually natural motion-blurred adversarial examples, named motion-based adversarial blur attack (ABBA). To this end, we first formulate the kernel-prediction-based attack where an input image is convolved with kernels in a pixel-wise way, and the misclassification capability is achieved by tuning the kernel weights. To generate visually more natural and plausible examples, we further propose the saliency-regularized adversarial kernel prediction, where the salient region serves as a moving object, and the predicted kernel is regularized to achieve visual effects that are natural. Besides, the attack is further enhanced by adaptively tuning the translations of object and background. A comprehensive evaluation on the NeurIPS'17 adversarial competition dataset demonstrates the effectiveness of AB BA by considering various kernel sizes, translations, and regions. The in-depth study further confirms that our method shows more effective penetrating capability to the state-of-the-art GAN-based deblurring mechanisms compared with other blurring methods. We release the code to https://github.com/tsingqguo/ABBA .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cf60efec-9740-4976-b5c2-accc773ce580Cited by top-tier papers14
- DeepRhythm: Exposing DeepFakes with Attentional Visual Heartbeat RhythmsHua Qi, Qing Guo, Felix Juefei-Xu, Xiaofei Xie et al.ACM MM 2020 · 224 citations
- AdvDrop: Adversarial Attack to DNNs by Dropping InformationRanjie Duan, Yuefeng Chen, Dantong Niu, Yun Yang et al.ICCV 2021 · 127 citations
- FakeTagger: Robust Safeguards against DeepFake Dissemination via Provenance TrackingRun Wang, Felix Juefei-Xu, Meng Luo, Yang Liu et al.ACM MM 2021 · 77 citations
- Learning to Adversarially Blur Visual Object TrackingQing Guo, Ziyi Cheng, Felix Juefei-Xu, Lei Ma et al.ICCV 2021 · 52 citations
- Background-Mixed Augmentation for Weakly Supervised Change DetectionRui Huang, Ruofei Wang, Qing Guo, Jieda Wei et al.AAAI 2023 · 38 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- DeblurGAN-v2: Deblurring (Orders-of-Magnitude) Faster and BetterOrest Kupyn, Tetiana Martyniuk, Junru Wu, Zhangyang WangICCV 2019 · 1,100 citations
- Unrestricted Adversarial Examples via Semantic ManipulationAnand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li et al.ICLR 2020 · 177 citations
- Amora: Black-box Adversarial Morphing AttackRun Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang et al.ACM MM 2020 · 40 citations
Related papers
- FAB-Attack: Fabric-Aware Adversarial Attacks on Person Detectors under Motion BlurJiaqi Hou, Kewei Zhang, Tianyu Yang, Chengyu Jia et al.ACM MM 2025
- A Unified Multi-Scenario Attacking Network for Visual Object TrackingXuesong Chen, Canmiao Fu, Feng Zheng, Yong Zhao et al.AAAI 2021 · 20 citations
- Semantically-Consistent Dynamic Blurry Image Generation for Image DeblurringZhaohui Jing, Youjian Zhang, Chaoyue Wang, Daqing Liu et al.ACM MM 2022 · 4 citations
- Adversarial Pixel Masking: A Defense against Physical Attacks for Pre-trained Object DetectorsPing-Han Chiang, Chi-Shen Chan, Shan-Hung WuACM MM 2021 · 30 citations
- Robust Superpixel-Guided Attentional Adversarial AttackXiaoyi Dong, Jiangfan Han, Dongdong Chen, Jiayang Liu et al.CVPR 2020
