LogoStyleFool: Vitiating Video Recognition Systems via Logo Style Transfer

被引:0
|
作者
Cao, Yuxin [1 ]
Zhao, Ziyu [2 ]
Xiao, Xi [1 ]
Wang, Derui [3 ]
Xue, Minhui [3 ]
Lu, Jin [4 ]
机构
[1] Tsinghua Univ, Shenzhen Int Grad Sch, Shenzhen, Peoples R China
[2] Beijing Univ Technol, Fan Gongxiu Honors Coll, Beijing, Peoples R China
[3] CSIROs Data61, Eveleigh, NSW, Australia
[4] Ping Technol Shenzhen Co Ltd, Shenzhen, Peoples R China
来源
THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 2 | 2024年
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Video recognition systems are vulnerable to adversarial examples. Recent studies show that style transfer-based and patch-based unrestricted perturbations can effectively improve attack efficiency. These attacks, however, face two main challenges: 1) Adding large stylized perturbations to all pixels reduces the naturalness of the video and such perturbations can be easily detected. 2) Patch-based video attacks are not extensible to targeted attacks due to the limited search space of reinforcement learning that has been widely used in video attacks recently. In this paper, we focus on the video blackbox setting and propose a novel attack framework named LogoStyleFool by adding a stylized logo to the clean video. We separate the attack into three stages: style reference selection, reinforcement-learning-based logo style transfer, and perturbation optimization. We solve the first challenge by scaling down the perturbation range to a regional logo, while the second challenge is addressed by complementing an optimization stage after reinforcement learning. Experimental results substantiate the overall superiority of LogoStyleFool over three state-of-the-art patch-based attacks in terms of attack performance and semantic preservation. Meanwhile, LogoStyleFool still maintains its performance against two existing patch-based defense methods. We believe that our research is beneficial in increasing the attention of the security community to such subregional style transfer attacks.
引用
收藏
页码:945 / 953
页数:9
相关论文
共 50 条
  • [1] StyleFool: Fooling Video Classification Systems via Style Transfer
    Cao, Yuxin
    Xiao, Xi
    Sun, Ruoxi
    Wang, Derui
    Xue, Minhui
    Wen, Sheng
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 1631 - 1648
  • [2] Video cloning for paintings via artistic style transfer
    Liu, Damon Shing-Min
    Tu, Ning
    SIGNAL IMAGE AND VIDEO PROCESSING, 2021, 15 (01) : 111 - 119
  • [3] Consistent Video Style Transfer via Compound Regularization
    Wang, Wenjing
    Xu, Jizheng
    Zhang, Li
    Wang, Yue
    Liu, Jiaying
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 12233 - 12240
  • [4] Consistent Video Style Transfer via Relaxation and Regularization
    Wang, Wenjing
    Yang, Shuai
    Xu, Jizheng
    Liu, Jiaying
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2020, 29 (29) : 9125 - 9139
  • [5] Video cloning for paintings via artistic style transfer
    Damon Shing-Min Liu
    Ning Tu
    Signal, Image and Video Processing, 2021, 15 : 111 - 119
  • [6] Towards Evaluating the Robustness of Automatic Speech Recognition Systems via Audio Style Transfer
    Jin, Weifei
    Cao, Yuxin
    Su, Junjie
    Shen, Qi
    Ye, Kai
    Wang, Derui
    Hao, Jie
    Liu, Ziyao
    PROCEEDINGS OF THE 2ND ACM WORKSHOP ON SECURE AND TRUSTWORTHY DEEP LEARNING SYSTEMS, SECTL 2024, 2024, : 47 - 55
  • [7] Logo recognition in video stills by string matching
    den Hollander, RJM
    Hanjalic, A
    2003 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOL 3, PROCEEDINGS, 2003, : 517 - 520
  • [8] Logo recognition in video by line profile classification
    den Hollander, RJM
    Hanjalic, A
    STORAGE AND RETRIEVAL METHODS AND APPLICATIONS FOR MULTIMEDIA 2004, 2004, 5307 : 300 - 306
  • [9] Contained Neural Style Transfer for Decorated Logo Generation
    Atarsaikhan, Gantugs
    Iwana, Brian Kenji
    Uchida, Seiichi
    2018 13TH IAPR INTERNATIONAL WORKSHOP ON DOCUMENT ANALYSIS SYSTEMS (DAS), 2018, : 317 - 322
  • [10] Research on the Transfer Learning of the Vehicle Logo Recognition
    Zhao, Wei
    GREEN ENERGY AND SUSTAINABLE DEVELOPMENT I, 2017, 1864