Adversarial Bone Length Attack on Action Recognition
Nariki Tanaka, Hiroshi Kera, Kazuhiko Kawamoto
摘要
Skeleton-based action recognition models have recently been shown to be vulnerable to adversarial attacks. Compared to adversarial attacks on images, perturbations to skeletons are typically bounded to a lower dimension of approximately 100 per frame. This lower-dimensional setting makes it more difficult to generate imperceptible perturbations. Existing attacks resolve this by exploiting the temporal structure of the skeleton motion so that the perturbation dimension increases to thousands. In this paper, we show that adversarial attacks can be performed on skeleton-based action recognition models, even in a significantly low-dimensional setting without any temporal manipulation. Specifically, we restrict the perturbations to the lengths of the skeleton's bones, which allows an adversary to manipulate only approximately 30 effective dimensions. We conducted experiments on the NTU RGB+D and HDM05 datasets and demonstrate that the proposed attack successfully deceived models with sometimes greater than 90% success rate by small perturbations. Furthermore, we discovered an interesting phenomenon: in our low-dimensional setting, the adversarial training with the bone length attack shares a similar property with data augmentation, and it not only improves the adversarial robustness but also improves the classification accuracy on the original data. This is an interesting counterexample of the trade-off between adversarial robustness and clean accuracy, which has been widely observed in studies on adversarial training in the high-dimensional regime.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Hard No-Box Adversarial Attack on Skeleton-Based Human Action Recognition with Skeleton-Motion-Informed GradientZhengzhi Lu, He Wang, Ziyi Chang, Guoan Yang 等ICCV 2023 · 被引用 17 次
- Defending Black-Box Skeleton-Based Human Activity ClassifiersHe Wang, Yunfeng Diao, Zichang Tan, Guodong GuoAAAI 2023 · 被引用 13 次
- Self-Supervised Learning for Multilevel Skeleton-Based Forgery Detection via Temporal-Causal Consistency of ActionsLiang Hu, Dora D. Liu, Qi Zhang, Usman Naseem 等AAAI 2023 · 被引用 1 次
- TASAR: Transfer-based Attack on Skeletal Action RecognitionYunfeng Diao, Baiqi Wu, Ruixuan Zhang, Ajian Liu 等ICLR 2025
它引用的顶会 Paper9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh 等ICCV 2019 · 被引用 5,843 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- Semantics-Guided Neural Networks for Efficient Skeleton-Based Human Action RecognitionPengfei Zhang, Cuiling Lan, Wenjun Zeng, Junliang Xing 等CVPR 2020
- Graph Stacked Hourglass Networks for 3D Human Pose EstimationTianhan Xu, Wataru TakanoCVPR 2021
相关 Paper
- Understanding the Robustness of Skeleton-Based Action Recognition Under Adversarial AttackHe Wang, Feixiang He, Zhexi Peng, Tianjia Shao 等CVPR 2021
- Finding Achilles' Heel: Adversarial Attack on Multi-modal Action RecognitionDeepak Kumar, Chetan Kumar, Chun-Wei Seah, Siyu Xia 等ACM MM 2020 · 被引用 13 次
- BASAR: Black-Box Attack on Skeletal Action RecognitionYunfeng Diao, Tianjia Shao, Yongliang Yang, Kun Zhou 等CVPR 2021
- Skeleton-Contrastive 3D Action Representation LearningFida Mohammad Thoker, Hazel Doughty, Cees G. M. SnoekACM MM 2021 · 被引用 158 次
- Hierarchical Consistent Contrastive Learning for Skeleton-Based Action Recognition with Growing AugmentationsJiahang Zhang, Lilang Lin, Jiaying LiuAAAI 2023 · 被引用 84 次
