paper-with-me

홈 › Papers

Hard No-Box Adversarial Attack on Skeleton-Based Human Action Recognition with Skeleton-Motion-Informed Gradient

2023-08-10 · ICCV 2023 1 · Zhengzhi Lu, He Wang, Ziyi Chang, Guoan Yang, Hubert P. H. Shum

Recently, methods for skeleton-based human activity recognition have been shown to be vulnerable to adversarial attacks. However, these attack methods require either the full knowledge of the victim (i.e. white-box attacks), access to training data (i.e. transfer-based attacks) or frequent model queries (i.e. black-box attacks). All their requirements are highly restrictive, raising the question of how detrimental the vulnerability is. In this paper, we show that the vulnerability indeed exists. To this end, we consider a new attack task: the attacker has no access to the victim model or the training data or labels, where we coin the term hard no-box attack. Specifically, we first learn a motion manifold where we define an adversarial loss to compute a new gradient for the attack, named skeleton-motion-informed (SMI) gradient. Our gradient contains information of the motion dynamics, which is different from existing gradient-based attack methods that compute the loss gradient assuming each dimension in the data is independent. The SMI gradient can augment many gradient-based attack methods, leading to a new family of no-box attack methods. Extensive evaluation and comparison show that our method imposes a real threat to existing classifiers. They also show that the SMI gradient improves the transferability and imperceptibility of adversarial samples in both no-box and transfer-based black-box settings.

📄 PDF Abstract BibTeX arXiv:2308.05681

Code (1)

luyg45/hardnoboxattack 공식 구현 pytorch

Tasks

Action RecognitionActivity RecognitionAdversarial AttackHuman Activity RecognitionTemporal Action Localization

Similar Papers 제목 키워드 기반

Adversarial Attack on Skeleton-based Human Action Recognition

2019-09-14 · Jian Liu, Naveed Akhtar, Ajmal Mian

Deep learning models achieve impressive performance for skeleton-based human action recognition. However, the robustness of these models to adversarial attacks remains largely unexplored due to their complex spatio-tempo…

Action RecognitionAdversarial AttackSkeleton Based Action RecognitionTemporal Action Localization

SkeletonVis: Interactive Visualization for Understanding Adversarial Attacks on Human Action Recognition Models

2021-01-26 · Haekyu Park, Zijie J. Wang, Nilaksh Das, Anindya S. Paul 외

Skeleton-based human action recognition technologies are increasingly used in video based applications, such as home robotics, healthcare on aging population, and surveillance. However, such models are vulnerable to adve…

Action RecognitionTemporal Action Localization

Adversarial Interaction Attack: Fooling AI to Misinterpret Human Intentions

2021-01-17 · Nodens Koren, Qiuhong Ke, Yisen Wang, James Bailey 외

Understanding the actions of both humans and artificial intelligence (AI) agents is important before modern AI systems can be fully integrated into our daily life. In this paper, we show that, despite their current huge …

Adversarial Attack

Adversarial Bone Length Attack on Action Recognition

2021-09-13 · Nariki Tanaka, Hiroshi Kera, Kazuhiko Kawamoto

Skeleton-based action recognition models have recently been shown to be vulnerable to adversarial attacks. Compared to adversarial attacks on images, perturbations to skeletons are typically bounded to a lower dimension …

Action RecognitionAdversarial RobustnessData AugmentationSkeleton Based Action Recognition

Adversarial Interaction Attacks: Fooling AI to Misinterpret Human Intentions

2021-06-18 · ICML Workshop AML 2021 7 · Nodens Koren, Xingjun Ma, Qiuhong Ke, Yisen Wang 외

Understanding the actions of both humans and artificial intelligence (AI) agents is important before modern AI systems can be fully integrated into our daily life. In this paper, we show that, despite their current huge …

Adversarial Attack