We introduce a technique known as “Spatio-Temporal Focus with Active Learning” for sparse black-box adversarial attacks on video recognition models. This approach is designed to minimize temporal and spatial redundancies in adversarial video examples by applying perturbations of varying intensities to key frames and key regions. Our methodology is bifurcated into two modules: an inter-frame dynamic frame selection module that employs active learning, and an intra-frame focus area concentration module that harnesses reinforcement learning. Extensive experiments have been conducted on six state-of-the-art action recognition models using three widely-used action recognition datasets. The empirical results demonstrate that our method outperforms existing techniques in success rate, query efficiency, and time efficiency, thereby establishing new benchmarks within the field.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Spatio-Temporal Focus with Active Learning in Sparse Black-Box Adversarial Attacks for Video Recognition

  • Jiefu Chen,
  • Tong Chen,
  • Zheng Wang

摘要

We introduce a technique known as “Spatio-Temporal Focus with Active Learning” for sparse black-box adversarial attacks on video recognition models. This approach is designed to minimize temporal and spatial redundancies in adversarial video examples by applying perturbations of varying intensities to key frames and key regions. Our methodology is bifurcated into two modules: an inter-frame dynamic frame selection module that employs active learning, and an intra-frame focus area concentration module that harnesses reinforcement learning. Extensive experiments have been conducted on six state-of-the-art action recognition models using three widely-used action recognition datasets. The empirical results demonstrate that our method outperforms existing techniques in success rate, query efficiency, and time efficiency, thereby establishing new benchmarks within the field.