提出无损动作质量的隐蔽对抗攻击,提升攻击成功率与自然度
Quality-Preserving Imperceptible Adversarial Attack on Skeleton-based Human Action Recognition

- 基于分布的对抗攻击,不引入噪声型扰动
- 在两个数据集上实现更高攻击成功率与更优动作质量
- 新评测指标贴合人类对自然动作的感知
针对骨架动作识别的对抗攻击近年受到广泛关注。然而,现有方法通常引入类似噪声的扰动,导致攻击后动作质量下降,因而可被当前S-HAR系统察觉。我们发现,这一问题源于优化过程中经验风险与真实风险之间的差距。为此,提出一种不损害动作质量的对抗攻击方法:通过分布建模避免噪声扰动,从而缩小风险差距并保持动作自然性。为准确评估动作质量,设计了一种符合人类感知的新型自然度评价指标。在两种主流S-HAR方法和两个数据集上的实验表明,该方法在攻击成功率与攻击后动作质量方面均显著优于现有方法。本研究揭示了动作识别系统在质量保持下的脆弱性,凸显其鲁棒性亟待加强。
原文摘要 · Abstract (English)
Adversarial attacks on skeletal human action recognition have received significant attention. However, existing methods typically introduce noise-like perturbations that degrade motion quality post-attack, and thereby are inherently perceptible with recent advancements in S-HAR systems. We discover that this degradation stems from the gap between empirical and true risks during the optimization process of previous adversarial attacks. To address this issue, we propose an attack where adversarial motions are obtained without compromising their motion quality. To minimize the risk gap and preserve motion quality, we propose a distribution-based adversarial attack method without introducing noise-like perturbations. To faithfully evaluate the motion quality, we propose a new metric that aligns with human perception on real-world naturalness. Experiments have been conducted on the state-of-the-art S-HAR methods across two datasets, demonstrating the superiority of our method in both the attack success rate and the post-attack motion quality through qualitative and quantitative analyses. The success of our quality-preserving attack application and distribution-based method raises serious concerns about the robustness of action recognizers, highlighting the need for further enhancements in this domain.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。