Cube-Evo: A Query-Efficient Black-Box Attack on Video Classification System
dc.contributor.author | Zhan, Yu | |
dc.contributor.author | Fu, Ying | |
dc.contributor.author | Huang, Liang | |
dc.contributor.author | Guo, Jianmin | |
dc.contributor.author | Shi, Heyuan | |
dc.contributor.author | Song, Houbing | |
dc.contributor.author | Hu, Chao | |
dc.date.accessioned | 2023-05-15T20:02:40Z | |
dc.date.available | 2023-05-15T20:02:40Z | |
dc.date.issued | 2023-04-13 | |
dc.description.abstract | The current progressive research in the domain of black-box adversarial attack enhances the reliability of deep neural network (DNN)-based video systems. Recent works mainly carry out black-box adversarial attacks on video systems by query-based parameter dimension reduction. However, the additional temporal dimension of video data leads to massive query consumption and low attack success rate. In this article, we embark on our efforts to design an effective adversarial attack on popular video classification systems. We deeply root the observations that the DNN-based systems are sensitive to adversarial perturbations with high frequency and reconstructed shape. Specifically, we propose a systematic attack pipeline Cube-Evo, aiming to reduce the search space dimension and obtain the effective adversarial perturbation via the optimal parameter group updating. We evaluate the proposed attack pipeline on two popular datasets: UCF101 and JESTER. Our attack pipeline reduces query consumption and achieves a high success rate on various DNN-based video classification systems. Compared with the state-of-the-art method Geo-Trap-Att, our pipeline averagely reduces 1.6× query consumption in untargeted attacks and 2.9× in targeted attacks. Besides, Cube-Evo improves 13% attack success rate on average, achieving new state-of-the-art results over diverse video classification systems. | en_US |
dc.description.sponsorship | This work was supported in part by the National Natural Science Foundation of China under Grant 62177046, Grant 61977062, and Grant 62202500, in part by the Hunan Natural Science Foundation of China under Grant 2021JJ30866, and in part by the National Key R&D Program of China under Grant 2022YFB3104003. | en_US |
dc.description.uri | https://ieeexplore.ieee.org/abstract/document/10102317 | en_US |
dc.format.extent | 12 pages | en_US |
dc.genre | journal articles | en_US |
dc.genre | postprints | en_US |
dc.identifier | doi:10.13016/m23ozn-ofvu | |
dc.identifier.citation | Y. Zhan et al., "Cube-Evo: A Query-Efficient Black-Box Attack on Video Classification System," in IEEE Transactions on Reliability, doi: 10.1109/TR.2023.3261986. | en_US |
dc.identifier.uri | https://doi.org/10.1109/TR.2023.3261986 | |
dc.identifier.uri | http://hdl.handle.net/11603/27919 | |
dc.language.iso | en_US | en_US |
dc.publisher | IEEE | en_US |
dc.relation.isAvailableAt | The University of Maryland, Baltimore County (UMBC) | |
dc.relation.ispartof | UMBC Information Systems Department Collection | |
dc.relation.ispartof | UMBC Faculty Collection | |
dc.rights | © 2023 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. | en_US |
dc.title | Cube-Evo: A Query-Efficient Black-Box Attack on Video Classification System | en_US |
dc.type | Text | en_US |
dcterms.creator | https://orcid.org/0000-0003-2631-9223 | en_US |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Cube-Evo_A_Query-Efficient_Black-Box_Attack_on_Video_Classification_System.pdf
- Size:
- 3.29 MB
- Format:
- Adobe Portable Document Format
- Description:
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 2.56 KB
- Format:
- Item-specific license agreed upon to submission
- Description: