Towards Universal Physical Attacks on Single Object Tracking
Li Ding, Yongwei Wang, Kaiwen Yuan, Minyang Jiang, Ping Wang, Hua Huang, Z. Jane Wang
摘要
Recent studies show that small perturbations in video frames could misguide single object trackers. However, such attacks have been mainly designed for digital-domain videos (i.e., perturbation on full images), which makes them practically infeasible to evaluate the adversarial vulnerability of trackers in real-world scenarios. Here we made the first step towards physically feasible adversarial attacks against visual tracking in real scenes with a universal patch to camouflage single object trackers. Fundamentally different from physical object detection, the essence of single object tracking lies in the feature matching between the search image and templates, and we therefore specially design the maximum textural discrepancy (MTD), a resolution-invariant and target location-independent feature de-matching loss. The MTD distills global textural information of the template and search images at hierarchical feature scales prior to performing feature attacks. Moreover, we evaluate two shape attacks, the regression dilation and shrinking, to generate stronger and more controllable attacks. Further, we employ a set of transformations to simulate diverse visual tracking scenes in the wild. Experimental results show the effectiveness of the physically feasible attacks on SiamMask and SiamRPN++ visual trackers both in digital and physical scenes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Towards Practical Certifiable Patch Defense with Vision TransformerZhaoyu Chen, Bo Li, Jianghe Xu, Shuang Wu 等CVPR 2022 · 被引用 60 次
- Physical Hijacking Attacks against Object TrackersRaymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li 等CCS 2022 · 被引用 12 次
- Full-Distance Evasion of Pedestrian Detectors in the Physical WorldZhi Cheng, Zhanhao Hu, Yuqiu Liu, Jianmin Li 等NeurIPS 2024 · 被引用 6 次
- FlyTrap: Physical Distance-Pulling Attack Towards Camera-based Autonomous Target Tracking SystemsShaoyuan Xie, Mohamad Habib Fakih, Junchi Lu, Fayzah Alshammari 等NDSS 2026 · 被引用 5 次
- Cross-Modal Stealth: A Coarse-to-Fine Attack Framework for RGB-T TrackerXinyu Xiang, Qinglong Yan, Hao Zhang, Jianfeng Ding 等AAAI 2025 · 被引用 3 次
它引用的顶会 Paper6
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Seeing isn't Believing: Towards More Robust Adversarial Attack Against Real World Object DetectorsYue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen 等CCS 2019 · 被引用 239 次
- Physical Adversarial Textures That Fool Visual Object TrackingRey Wiyatno, Anqi XuICCV 2019 · 被引用 88 次
- Cooling-Shrinking Attack: Blinding the Tracker With Imperceptible NoisesBin Yan, Dong Wang, Huchuan Lu, Xiaoyun YangCVPR 2020
- Universal Physical Camouflage Attacks on Object DetectorsLifeng Huang, Chengying Gao, Yuyin Zhou, Cihang Xie 等CVPR 2020
相关 Paper
- A Unified Multi-Scenario Attacking Network for Visual Object TrackingXuesong Chen, Canmiao Fu, Feng Zheng, Yong Zhao 等AAAI 2021 · 被引用 20 次
- One-Shot Adversarial Attacks on Visual Tracking With Dual AttentionXuesong Chen, Xiyu Yan, Feng Zheng, Yong Jiang 等CVPR 2020
- Discriminative and Robust Online Learning for Siamese Visual TrackingJinghao Zhou, Peng Wang, Haoyang SunAAAI 2020 · 被引用 66 次
- ACAttack: Adaptive Cross Attacking RGB-T Tracker via Multi-Modal Response DecouplingXinyu Xiang, Qinglong Yan, Hao Zhang, Jiayi MaCVPR 2025
- Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch DetectionJiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa 等CVPR 2022 · 被引用 99 次
