arXiv:2512.01934cs.CV2025-12中稿 · Annual Computer Se…被引 5

用对抗轨迹在真实场景中劫持目标跟踪ID,让系统认错人。

Physical ID-Transfer Attacks against Multi-Object Tracking via Adversarial Trajectory

  • 通过生成对抗性运动轨迹,远程篡改跟踪系统的身份分配。
  • 在CARLA模拟中对SORT算法攻击成功率100%,跨模型迁移率最高达93%。
  • 提出人类可执行的通用对抗动作,适合关注安全的自动驾驶研究者。

多目标跟踪(MOT)是计算机视觉中的关键任务,广泛应用于监控系统与自动驾驶。然而,针对MOT算法的威胁尚未被充分研究。错误的目标关联可能导致严重后果,如轨迹预测错误。此前的攻击多针对单个目标或通过数字域攻击集成的目标检测(OD)模块,具有模型依赖性、鲁棒性差且仅适用于离线数据集。本文提出首个在线物理级的ID操控攻击——AdvTraj,攻击者利用对抗性轨迹将自身ID转移至目标对象,无需攻击检测模块。仿真结果表明,在CARLA环境中,AdvTraj对白盒攻击下的SORT算法实现100%成功欺骗,且对主流SOTA MOT算法具备高达93%的攻击迁移率,源于其共通的设计原则。我们分析了对抗轨迹模式,提出两种人类可执行的通用对抗行为。本工作揭示了当前SOTA MOT系统在目标关联阶段的未受重视缺陷,并为提升系统鲁棒性提供重要启示。

原文摘要 · Abstract (English)

Multi-Object Tracking (MOT) is a critical task in computer vision, with applications ranging from surveillance systems to autonomous driving. However, threats to MOT algorithms have yet been widely studied. In particular, incorrect association between the tracked objects and their assigned IDs can lead to severe consequences, such as wrong trajectory predictions. Previous attacks against MOT either focused on hijacking the trackers of individual objects, or manipulating the tracker IDs in MOT by attacking the integrated object detection (OD) module in the digital domain, which are model-specific, non-robust, and only able to affect specific samples in offline datasets. In this paper, we present AdvTraj, the first online and physical ID-manipulation attack against tracking-by-detection MOT, in which an attacker uses adversarial trajectories to transfer its ID to a targeted object to confuse the tracking system, without attacking OD. Our simulation results in CARLA show that AdvTraj can fool ID assignments with 100% success rate in various scenarios for white-box attacks against SORT, which also have high attack transferability (up to 93% attack success rate) against state-of-the-art (SOTA) MOT algorithms due to their common design principles. We characterize the patterns of trajectories generated by AdvTraj and propose two universal adversarial maneuvers that can be performed by a human walker/driver in daily scenarios. Our work reveals under-explored weaknesses in the object association phase of SOTA MOT systems, and provides insights into enhancing the robustness of such systems.

多目标跟踪对抗攻击自动驾驶安全物理攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。