Investigating vulnerabilities of gait recognition model using latent-based perturbations
摘要
Video surveillance systems are very beneficial in strengthening security and tracking events and activities in a variety of contexts, including public venues. In this regard, gait recognition-based surveillance has emerged as an evolving technology because of its unique characteristics. However, adversarial Gait Recognition has arisen as a major challenge in video surveillance systems, as deep learning-based gait recognition algorithms become more sensitive to adversarial attacks. Most known attack approaches rely significantly on white-box access or repetitive querying of the target model, making them not feasible in real-world surveillance contexts with limited system access. Additionally, these attacks often lack transferability and perceptual realism, limiting their effectiveness. Motivated by the need for more practical and transferable black-box attacks, another novel attack named the BLG attack, a.k.a Black-box-Latent-GEI attack, is proposed in this study. Our technique includes two major components: AdvHelper, a surrogate model that simulates the target, and PerturbGen, a latent-space perturbation generator implemented in an encoder-decoder framework. This design guarantees that adversarial samples are both effective and perceptually realistic by utilizing reconstruction and perceptual losses. Experimental results on the benchmark CASIA-gait dataset show that the proposed method achieves a high attack success rate of 94.33%. The study focuses on a realistic and adaptable attack technique, which contributes to a better understanding of model vulnerabilities in adversarial gait recognition.