Attacking the Tracker with a Universal and Attractive Patch as Fake Target

Ze Zhou,Yinghui Sun,Quansen Sun,Chaobo Li,Zhenwen Ren
DOI: https://doi.org/10.1016/j.ins.2023.119677
IF: 8.1
2023-09-13
Information Sciences
Abstract:Adversarial attacks in visual object tracking aim to drop tracking performance through injecting imperceptible perturbations to the input of the tracker. Current methods usually superimpose perturbation maps on the input images, and advocate blinding the tracker via occluding the real targets to achieve attack effect. From the perspective of attraction, we alternatively propose a novel idea of attacking the tracker, which advocates using perturbation patches to act as fake targets to attract the tracker's attention. For this purpose, we establish a multi-conditional objective function to generate our ideal patch in an offline iterative manner. For invisibility, we integrate the constraint of patch value into the function for unified optimization. For universality, in addition to adopting large-scale and high-diversity training samples, we also incorporate the video-agnostic condition into this function. To make the patch attractive like a fake target, we elaborately design the non-overlapping area to determine the patch position, and generate matched fake labels to mislead the tracker to track the patch. In online attacking, it only needs to paste the optimized patch onto the video frames, the tracker will be successfully attracted by our patch, achieving attack effect. Extensive experimental results on 8 popular tracking datasets demonstrate that our method can obtain exceptional attack performance in both non-targeted and targeted attack. Additionally, the experiments on transferability illustrate our optimized patches can be directly applied to other trackers with different architectures.
computer science, information systems
What problem does this paper attempt to address?