通过时间敏感点编辑生成手写攻击,更隐蔽且易迁移。
Adversarial Attacks on Online Handwriting using Salience-based Temporal Editing

- 基于时序显著性选择关键时间点插入删除笔画
- 在两个数据集上黑盒攻击成功率超传统方法
- 适合研究手写识别安全或对抗样本迁移的读者
在线手写识别的深度学习模型虽有效,但易受对抗攻击。现有方法多针对图像输入,依赖加性空间扰动,应用于时序笔迹时会产生高频抖动和不自然痕迹。本文提出一种基于显著性引导的时间编辑攻击框架:不加噪声,而是根据梯度激活图估计的时序显著性,在关键时间步插入或删除点,保持原笔迹形状与平滑性。在Unipen和CASIA-OLHWDB数据集上,白盒攻击下传统方法表现强,但跨模型迁移能力差;而本方法在单次黑盒攻击中转移成功率更高,同时保留书写视觉结构。结果表明,时间编辑是在线手写识别的重要威胁,尤其在单次黑盒场景中。
原文摘要 · Abstract (English)
Deep learning models for online handwriting recognition have been shown effective and are increasingly deployed in practical applications. However, their vulnerability to adversarial attacks is still a challenge. Existing adversarial methods are predominantly designed for image-based inputs and typically rely on additive spatial perturbations. When applied to online handwriting, which is inherently represented as a time series of pen trajectories, such perturbations often introduce high-frequency jitter and visibly unnatural stroke artifacts. In this work, we propose a novel adversarial attack framework for online handwriting recognition based on salience-guided temporal editing. Instead of adding noise, the proposed method generates adversarial examples by inserting and deleting points at time steps selected according to temporal salience, preserving the shape and smoothness of the original handwriting. Temporal salience is estimated using gradient-based activation mapping, which guides edits toward time steps that strongly support the original class prediction. We evaluate the proposed approach on the Unipen and CASIA-OLHWDB datasets under both white-box and one-shot black-box attack settings. Experimental results demonstrate that while conventional image-based attacks achieve strong white-box performance, they exhibit poor transferability across models. In contrast, the proposed temporal editing attack achieves stronger one-shot black-box transferability while preserving the visual structure of the handwriting. These results indicate that temporal editing is a relevant threat model for online handwriting recognition, particularly in one-shot black-box transfer settings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。