Publication | Closed Access
Appending Adversarial Frames for Universal Video Attack
26
Citations
31
References
2021
Year
Unknown Venue
Artificial IntelligenceEngineeringMachine LearningInformation SecurityModified VideoInformation ForensicsVideo RetrievalVideo AdaptationVideo InterpretationImage AnalysisData SciencePattern RecognitionAdversarial Machine LearningVideo ClassificationAdversarial ExamplesMachine VisionComputer ScienceVideo UnderstandingDeep LearningComputer VisionUniversal Video AttackVideo Hallucination
This paper investigates the problem of generating adversarial examples for video classification. We project all videos onto a semantic space and a perception space, and point out that adversarial attack is to find a counterpart which is close to the target in the perception space but far from the target in the semantic space. Based on this formulation, we notice that conventional attacking methods mostly used Euclidean distance to measure the perception space, but we propose to make full use of the property of videos and assume a modified video with a few consecutive frames replaced by dummy contents (e.g., a black frame with texts of `thank you for watching' on it) to be close to the original video in the perception space though they have a large Euclidean gap. This leads to a new attack approach which only adds perturbations on the newly-added frames. We show its high success rates in attacking six state-of-the-art video classification networks, as well as its universality, i.e., transferring well across videos and models.
| Year | Citations | |
|---|---|---|
Page 1
Page 1