arXiv:2604.00452cs.CV2026-04中稿 · CVPR被引 1

攻击多目标追踪的查询传播机制,让跟踪器误判或丢失目标。

Out of Sight, Out of Track: Adversarial Attacks on Propagation-based Multi-Object Trackers via Query State Manipulation

  • 通过制造虚假查询耗尽追踪器预算,强制中断真实轨迹。
  • 破坏查询更新的记忆关联,使已匹配目标身份失效。
  • 可模拟物理世界攻击,对先进追踪器效果显著。

基于查询传播(TBP)的多目标追踪方法通过端到端架构实现长时序建模,但其依赖查询传播的特性引入了新型安全漏洞。本文提出FADE攻击框架,针对TBP核心机制设计两种策略:(i) 时间查询泛滥——生成具时间一致性的虚假查询,耗尽追踪器有限的查询预算,迫使有效轨迹终止;(ii) 时间记忆污染——通过状态去相关与特征身份擦除,直接攻击查询更新器的记忆结构,切断时间关联。此外,我们构建可微分流水线,结合先进感知传感器欺骗仿真,优化攻击在真实场景中的可实现性。在MOT17与MOT20基准上的实验表明,FADE对当前主流TBP追踪器具有极强破坏力,导致大量身份切换与轨迹中断。

原文摘要 · Abstract (English)

Recent Tracking-by-Query-Propagation (TBP) methods have advanced Multi-Object Tracking (MOT) by enabling end-to-end (E2E) pipelines with long-range temporal modeling. However, this reliance on query propagation introduces unexplored architectural vulnerabilities to adversarial attacks. We present FADE, a novel attack framework designed to exploit these specific vulnerabilities. FADE employs two attack strategies targeting core TBP mechanisms: (i) Temporal Query Flooding: Generates spurious temporally consistent track queries to exhaust the tracker's limited query budget, forcing it to terminate valid tracks. (ii) Temporal Memory Corruption: Directly attacks the query updater's memory by severing temporal links via state de-correlation and erasing the learned feature identity of matched tracks. Furthermore, we introduce a differentiable pipeline to optimize these attacks for physical-world realizability by leveraging simulations of advanced perception sensor spoofing. Experiments on MOT17 and MOT20 benchmarks demonstrate that FADE is highly effective against state-of-the-art TBP trackers, causing significant identity switches and track terminations.

目标追踪对抗攻击查询传播安全漏洞

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。