Efficient Decision-based Black-box Patch Attacks on Video Recognition
Kaixun Jiang, Zhaoyu Chen, Hao Huang, Jiafeng Wang, Dingkang Yang, Bo Li, Yan Wang, Wenqiang Zhang
摘要
Although Deep Neural Networks (DNNs) have demonstrated excellent performance, they are vulnerable to adversarial patches that introduce perceptible and localized perturbations to the input. Generating adversarial patches on images has received much attention, while adversarial patches on videos have not been well investigated. Further, decision-based attacks, where attackers only access the predicted hard labels by querying threat models, have not been well explored on video models either, even if they are practical in real-world video recognition scenes. The absence of such studies leads to a huge gap in the robustness assessment for video models. To bridge this gap, this work first explores decision-based patch attacks on video models. We analyze that the huge parameter space brought by videos and the minimal information returned by decision-based models both greatly increase the attack difficulty and query burden. To achieve a query-efficient attack, we propose a spatial-temporal differential evolution (STDE) framework. First, STDE introduces target videos as patch textures and only adds patches on keyframes that are adaptively selected by temporal difference. Second, STDE takes minimizing the patch area as the optimization objective and adopts spatialtemporal mutation and crossover to search for the global optimum without falling into the local optimum. Experiments show STDE has demonstrated state-of-the-art performance in terms of threat, efficiency and imperceptibility. Hence, STDE has the potential to be a powerful tool for evaluating the robustness of video recognition models. * indicates equal contributions. † indicates corresponding authors.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- AIDE: A Vision-Driven Multi-View, Multi-Modal, Multi-Tasking Dataset for Assistive Driving PerceptionDingkang Yang, Shuai Huang, Zhi Xu, Zhenpeng Li 等ICCV 2023 · 被引用 72 次
- CamoPatch: An Evolutionary Strategy for Generating Camoflauged Adversarial PatchesPhoenix Neale Williams, Ke LiNeurIPS 2023 · 被引用 22 次
- ERMVP: Communication-Efficient and Collaboration-Robust Multi-Vehicle Perception in Challenging EnvironmentsJingyu Zhang, Kun Yang, Yilei Wang, Hanqi Wang 等CVPR 2024 · 被引用 21 次
- DSRC: Learning Density-Insensitive and Semantic-Aware Collaborative Representation Against CorruptionsJingyu Zhang, Yilei Wang, Lang Qian, Peng Sun 等AAAI 2025 · 被引用 13 次
- LogoStyleFool: Vitiating Video Recognition Systems via Logo Style TransferYuxin Cao, Ziyu Zhao, Xi Xiao, Derui Wang 等AAAI 2024 · 被引用 7 次
它引用的顶会 Paper16
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Sparse-RS: A Versatile Framework for Query-Efficient Sparse Black-Box Adversarial AttacksFrancesco Croce, Maksym Andriushchenko, Naman D. Singh, Nicolas Flammarion 等AAAI 2022 · 被引用 135 次
- Content-based Unrestricted Adversarial AttackZhaoyu Chen, Bo Li, Shuang Wu, Kaixun Jiang 等NeurIPS 2023 · 被引用 132 次
- CMUA-Watermark: A Cross-Model Universal Adversarial Watermark for Combating DeepfakesHao Huang, Yongtao Wang, Zhaoyu Chen, Yuze Zhang 等AAAI 2022 · 被引用 131 次
- Heuristic Black-Box Adversarial Attacks on Video Recognition ModelsZhipeng Wei, Jingjing Chen, Xingxing Wei, Linxi Jiang 等AAAI 2020 · 被引用 84 次
相关 Paper
- Towards Decision-based Sparse Attacks on Video RecognitionKaixun Jiang, Zhaoyu Chen, Xinyu Zhou, Jingyu Zhang 等ACM MM 2023 · 被引用 8 次
- Attacking Video Recognition Models with Bullet-Screen CommentsKai Chen, Zhipeng Wei, Jingjing Chen, Zuxuan Wu 等AAAI 2022 · 被引用 27 次
- BRP: Query-Efficient Block Revert Patch for Decision-Based Black-Box Adversarial AttackZenghui Yang, Xingquan Zuo, Gang Chen, Hai Huang 等KDD 2026
- Boosting the Transferability of Video Adversarial Examples via Temporal TranslationZhipeng Wei, Jingjing Chen, Zuxuan Wu, Yu-Gang JiangAAAI 2022 · 被引用 48 次
- Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition SystemsShangyu Xie, Han Wang, Yu Kong, Yuan HongS&P 2022 · 被引用 32 次
