Efficient Decision-based Black-box Patch Attacks on Video Recognition
Fuzhou University Efficient Decision-based Black-box Patch Attacks on Video Recognition :IEEE International Conference on Computer Vision(ICCV) :2023 8 :Kaixun Jiang, Zhaoyu Chen,Hao Huang,Jiafeng Wang Dingkang Yang, Bo Li, Yan Wang, Wenqiang Zhang :Academy for Engineering and Technology, Fudan University 2025-12-11
1.摘要
1. (DNN) ( 访 ) 使 (STDE) STDE
2.相关工作
2. 访 100%
3.符号定义
3. x∈R T × H × W × C y∈Y={1 2 ··· K} T H W C K F(·) F(·) F(·) y ˜ ∈Y F(x)=y ˜ δ∈R T × H × W × C M∈{0 1} T × H × W δ M x adv
3.符号定义
3. xadv F(·) F(X adv )≠y F(X adv )=y adv y adv y 使 l0 ( )
4.模型-概述
4. - STDE N v P Fk vi vj vBest vnew 使 vnew
4.稀疏空间与时间
4. x M x tar P FK FK P v ( P((p0,p1),(p2,p3)) FK)
4.进化算法-初始
4. - N ( , ) 0.4 0.6 0.7 N 15
4.进化算法-进化
4. - a.  
4.进化算法-进化
4. - b. A B Best = Best + * (A - B ),γ = 1 = Best (A B )
4.进化算法-进化
4. - c. ±1 α α =1 α =2 d. 访 访 10000 50000 退
5.实验-数据集
5. - UCF-101 Kinetics-400 UCF-101 101 13,320 Kinetics-400 400 24 2 C3D NL TPN UCF-101 C3D NL TPN 86.3% 74.4% 84.1% Kinetics-400 54.3% 74.8% 77.3% 1) (FR) (%) 2) (AOA) 3) (AOA*) (%) 4) (AQN)
5.实验-对比方法
5. - TPA (Texture-based Patch Attack) 使 RL Agent 使 Patch-RS (Patch Random Search) 使
5.实验-对比方法
5. - AdvW (Adversarial Watermark) Bash Hopping Evolution 使 BSCA (Bullet-Screen Comments Attack) 使 使 BSCA BSCA*
5.实验-结果对比
5. -
5.实验-消融实验
5. - 使 l0 l2 使 5
6.结论
6. -- (STDE) STDE
谢谢!
Fuzhou University