Cube-Evo: A Query-Efficient Black-Box Attack on Video Classification System

dc.contributor.authorZhan, Yu
dc.contributor.authorFu, Ying
dc.contributor.authorHuang, Liang
dc.contributor.authorGuo, Jianmin
dc.contributor.authorShi, Heyuan
dc.contributor.authorSong, Houbing
dc.contributor.authorHu, Chao
dc.date.accessioned2023-05-15T20:02:40Z
dc.date.available2023-05-15T20:02:40Z
dc.date.issued2023-04-13
dc.description.abstractThe current progressive research in the domain of black-box adversarial attack enhances the reliability of deep neural network (DNN)-based video systems. Recent works mainly carry out black-box adversarial attacks on video systems by query-based parameter dimension reduction. However, the additional temporal dimension of video data leads to massive query consumption and low attack success rate. In this article, we embark on our efforts to design an effective adversarial attack on popular video classification systems. We deeply root the observations that the DNN-based systems are sensitive to adversarial perturbations with high frequency and reconstructed shape. Specifically, we propose a systematic attack pipeline Cube-Evo, aiming to reduce the search space dimension and obtain the effective adversarial perturbation via the optimal parameter group updating. We evaluate the proposed attack pipeline on two popular datasets: UCF101 and JESTER. Our attack pipeline reduces query consumption and achieves a high success rate on various DNN-based video classification systems. Compared with the state-of-the-art method Geo-Trap-Att, our pipeline averagely reduces 1.6× query consumption in untargeted attacks and 2.9× in targeted attacks. Besides, Cube-Evo improves 13% attack success rate on average, achieving new state-of-the-art results over diverse video classification systems.en_US
dc.description.sponsorshipThis work was supported in part by the National Natural Science Foundation of China under Grant 62177046, Grant 61977062, and Grant 62202500, in part by the Hunan Natural Science Foundation of China under Grant 2021JJ30866, and in part by the National Key R&D Program of China under Grant 2022YFB3104003.en_US
dc.description.urihttps://ieeexplore.ieee.org/abstract/document/10102317en_US
dc.format.extent12 pagesen_US
dc.genrejournal articlesen_US
dc.genrepostprintsen_US
dc.identifierdoi:10.13016/m23ozn-ofvu
dc.identifier.citationY. Zhan et al., "Cube-Evo: A Query-Efficient Black-Box Attack on Video Classification System," in IEEE Transactions on Reliability, doi: 10.1109/TR.2023.3261986.en_US
dc.identifier.urihttps://doi.org/10.1109/TR.2023.3261986
dc.identifier.urihttp://hdl.handle.net/11603/27919
dc.language.isoen_USen_US
dc.publisherIEEEen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.rights© 2023 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.en_US
dc.titleCube-Evo: A Query-Efficient Black-Box Attack on Video Classification Systemen_US
dc.typeTexten_US
dcterms.creatorhttps://orcid.org/0000-0003-2631-9223en_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Cube-Evo_A_Query-Efficient_Black-Box_Attack_on_Video_Classification_System.pdf
Size:
3.29 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: