BASAR: Black-Box Attack on Skeletal Action Recognition
Yunfeng Diao, Tianjia Shao, Yongliang Yang, Kun Zhou, He Wang
摘要
Skeletal motion plays a vital role in human activity recognition as either an independent data source or a complement [33] . The robustness of skeleton-based activity recognizers has been questioned recently [29, 50] , which shows that they are vulnerable to adversarial attacks when the full-knowledge of the recognizer is accessible to the attacker. However, this white-box requirement is overly restrictive in most scenarios and the attack is not truly threatening. In this paper, we show that such threats do exist under black-box settings too. To this end, we propose the first black-box adversarial attack method BASAR. Through BASAR, we show that adversarial attack is not only truly a threat but also can be extremely deceitful, because onmanifold adversarial samples are rather common in skeletal motions, in contrast to the common belief that adversarial samples only exist off-manifold [18] . Through exhaustive evaluation and comparison, we show that BASAR can deliver successful attacks across models, data, and attack modes. Through harsh perceptual studies, we show that it achieves effective yet imperceptible attacks. By analyzing the attack on different activity recognizers, BASAR helps identify the potential causes of their vulnerability and provides insights on what classifiers are likely to be more robust against attack.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- RULER: discriminative and iterative adversarial training for deep neural network fairnessGuanhong Tao, Weisong Sun, Tingxu Han, Chunrong Fang 等FSE 2022 · 被引用 29 次
- Adversarial Bone Length Attack on Action RecognitionNariki Tanaka, Hiroshi Kera, Kazuhiko KawamotoAAAI 2022 · 被引用 18 次
- Hard No-Box Adversarial Attack on Skeleton-Based Human Action Recognition with Skeleton-Motion-Informed GradientZhengzhi Lu, He Wang, Ziyi Chang, Guoan Yang 等ICCV 2023 · 被引用 17 次
- Defending Black-Box Skeleton-Based Human Activity ClassifiersHe Wang, Yunfeng Diao, Zichang Tan, Guodong GuoAAAI 2023 · 被引用 13 次
- Physics-Based Adversarial Attack on Near-Infrared Human Detector for Nighttime Surveillance Camera SystemsMuyao Niu, Zhuoxiao Li, Yifan Zhan, Huy H. Nguyen 等ACM MM 2023 · 被引用 4 次
它引用的顶会 Paper11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- Sign-OPT: A Query-Efficient Hard-label Adversarial AttackMinhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen 等ICLR 2020 · 被引用 256 次
- Heuristic Black-Box Adversarial Attacks on Video Recognition ModelsZhipeng Wei, Jingjing Chen, Xingxing Wei, Linxi Jiang 等AAAI 2020 · 被引用 84 次
- Dynamic Future Net: Diversified Human Motion GenerationWenheng Chen, He Wang, Yi Yuan, Tianjia Shao 等ACM MM 2020 · 被引用 20 次
相关 Paper
- Understanding the Robustness of Skeleton-Based Action Recognition Under Adversarial AttackHe Wang, Feixiang He, Zhexi Peng, Tianjia Shao 等CVPR 2021
- TASAR: Transfer-based Attack on Skeletal Action RecognitionYunfeng Diao, Baiqi Wu, Ruixuan Zhang, Ajian Liu 等ICLR 2025
- Finding Achilles' Heel: Adversarial Attack on Multi-modal Action RecognitionDeepak Kumar, Chetan Kumar, Chun-Wei Seah, Siyu Xia 等ACM MM 2020 · 被引用 13 次
- Universal Targeted Adversarial Attacks Against mmWave-based Human Activity RecognitionYucheng Xie, Ruizhe Jiang, Xiaonan Guo, Yan Wang 等INFOCOM 2023 · 被引用 11 次
- Who is Real Bob? Adversarial Attacks on Speaker Recognition SystemsGuangke Chen, Sen Chen, Lingling Fan, Xiaoning Du 等S&P 2021 · 被引用 239 次
