Cube-Evo: A Query-Efficient Black-Box Attack on Video Classification System

被引:2
作者
Zhan, Yu [1 ]
Fu, Ying [2 ]
Huang, Liang [1 ]
Guo, Jianmin [3 ]
Shi, Heyuan [1 ]
Song, Houbing [4 ]
Hu, Chao [1 ]
机构
[1] Cent South Univ, Changsha 410017, Peoples R China
[2] Natl Univ Def Technol, Changsha 410073, Peoples R China
[3] Tsinghua Univ, Beijing 100190, Peoples R China
[4] Univ Maryland Baltimore Cty, Baltimore, MD 21250 USA
基金
国家重点研发计划; 中国国家自然科学基金; 湖南省自然科学基金;
关键词
Perturbation methods; Pipelines; Closed box; Costs; Sociology; Estimation; Security; Adversarial examples; black-box attack; deep learning; system testing; video classification;
D O I
10.1109/TR.2023.3261986
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The current progressive research in the domain of black-box adversarial attack enhances the reliability of deep neural network (DNN)-based video systems. Recent works mainly carry out black-box adversarial attacks on video systems by query-based parameter dimension reduction. However, the additional temporal dimension of video data leads to massive query consumption and low attack success rate. In this article, we embark on our efforts to design an effective adversarial attack on popular video classification systems. We deeply root the observations that the DNN-based systems are sensitive to adversarial perturbations with high frequency and reconstructed shape. Specifically, we propose a systematic attack pipeline Cube-Evo, aiming to reduce the search space dimension and obtain the effective adversarial perturbation via the optimal parameter group updating. We evaluate the proposed attack pipeline on two popular datasets: UCF101 and JESTER. Our attack pipeline reduces query consumption and achieves a high success rate on various DNN-based video classification systems. Compared with the state-of-the-art method Geo-Trap-Att, our pipeline averagely reduces 1.6x query consumption in untargeted attacks and 2.9x in targeted attacks. Besides, Cube-Evo improves 13% attack success rate on average, achieving new state-of-the-art results over diverse video classification systems.
引用
收藏
页码:1160 / 1171
页数:12
相关论文
共 50 条
  • [11] Sparse and Imperceivable Adversarial Attacks
    Croce, Francesco
    Hein, Matthias
    [J]. 2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 4723 - 4731
  • [12] Spatio-temporal Channel Correlation Networks for Action Classification
    Diba, Ali
    Fayyaz, Mohsen
    Sharma, Vivek
    Arzani, M. Mahdi
    Yousefzadeh, Rahman
    Gall, Juergen
    Van Gool, Luc
    [J]. COMPUTER VISION - ECCV 2018, PT IV, 2018, 11208 : 299 - 315
  • [13] Learning Spatiotemporal Features with 3D Convolutional Networks
    Du Tran
    Bourdev, Lubomir
    Fergus, Rob
    Torresani, Lorenzo
    Paluri, Manohar
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2015, : 4489 - 4497
  • [14] SlowFast Networks for Video Recognition
    Feichtenhofer, Christoph
    Fan, Haoqi
    Malik, Jitendra
    He, Kaiming
    [J]. 2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 6201 - 6210
  • [15] Guo JJ, 2020, IEEE T WIREL COMMUN, V19, P2827, DOI [10.1109/TWC.2020.2968430, 10.1109/TNSE.2020.2997359]
  • [16] RNN-Test: Towards Adversarial Testing for Recurrent Neural Network Systems
    Guo, Jianmin
    Zhang, Quan
    Zhao, Yue
    Shi, Heyuan
    Jiang, Yu
    Sun, Jiaguang
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (10) : 4167 - 4180
  • [17] DLFuzz: Differential Fuzzing Testing of Deep Learning Systems
    Guo, Jianmin
    Jiang, Yu
    Zhao, Yue
    Chen, Quan
    Sun, Jiaguang
    [J]. ESEC/FSE'18: PROCEEDINGS OF THE 2018 26TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, 2018, : 739 - 743
  • [18] Hou X, 2007, 2007 IEEE C COMP VIS, P1, DOI DOI 10.1109/CVPR.2007.383267
  • [19] Hu Zhang, 2020, Computer Vision - ECCV 2020. 16th European Conference. Proceedings. Lecture Notes in Computer Science (LNCS 12365), P240, DOI 10.1007/978-3-030-58565-5_15
  • [20] Ilyas A., 2019, ICLR", P1