Authors
Xuesong Chen, Canmiao Fu, Feng Zheng, Yong Zhao, Hongsheng Li, Ping Luo, Guo-Jun Qi
Publication date
2021/5/18
Journal
Proceedings of the AAAI Conference on Artificial Intelligence
Volume
35
Issue
2
Pages
1097-1104
Description
Existing methods of adversarial attacks successfully generate adversarial examples to confuse Deep Neural Networks (DNNs) of image classification and object detection, resulting in wrong predictions. However, these methods are difficult to attack models of video object tracking, because the tracking algorithms could handle sequential information across video frames and the categories of targets tracked are normally unknown in advance. In this paper, we propose a Unified and Effective Network, named UEN, to attack visual object tracking models. There are several appealing characteristics of UEN:(1) UEN could produce various invisible adversarial perturbations according to different attack settings by using only one simple end-to-end network with three ingenious loss function;(2) UEN could generate general visible adversarial patch patterns to attack the advanced trackers in the real-world;(3) Extensive experiments show that UEN is able to attack many state-of-the-art trackers effectively (eg SiamRPN-based networks and DiMP) on popular tracking datasets including OTB100, UAV123, and GOT10K, making online real-time attacks possible. The attack results outperform the introduced baseline in terms of attacking ability and attacking efficiency.
Total citations
202220232024483
Scholar articles
X Chen, C Fu, F Zheng, Y Zhao, H Li, P Luo, GJ Qi - Proceedings of the AAAI Conference on Artificial …, 2021