IP Library › Granted Patent US 10,783,401
Granted Patent B1
US 10,783,401 · App. 16/798,393 · Granted Sep 22, 2020

Black-box adversarial attacks on videos

Inventors: Yugang Jiang (Shanghai, CN); Linxi Jiang (Shanghai, CN); Xingjun Ma (Shanghai, CN)
Assignee: FUDAN UNIVERSITY
G06K9/6257G06F16/73G06F21/577G06K9/00765G06K9/628G06K9/6262G06N7/005G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,783,401
App. No.
16/798,393
Granted
Sep 22, 2020
Kind
B1
Abstract

A method for generating black-box adversarial attacks on video recognition models is provided, comprising a) passing input video frames into a public image model, to obtain pixel-wise tentative perturbations; b) partitioning the tentative perturbations into tentative perturbation patches; c) estimating the rectification weight required for each patch, via querying the target video model; d) applying the patch-wise rectification weight on the patches, to obtain the rectified pixel-wise perturbations; e) applying one step projected gradient descent (PGD) perturbation on the input video, according to the rectified pixel-wise perturbations; and f) iteratively performing steps a)-e) until an attack succeeds or a query limit is reached. Systems and networks therefor are also provided.

Claims (33)

1. A method for providing black-box video attacks on video recognition models, comprising:

a) passing input video frames into a public image model, to obtain pixel-wise tentative perturbations;

b) partitioning the tentative perturbations into tentative perturbation patches;

c) estimating the rectification weight required for each patch, via querying the target video model;

d) applying the patch-wise rectification weight on the patches, to obtain the rectified pixel-wise perturbations;

e) applying one step projected gradient descent (PGD) perturbation on the input video, according to the rectified pixel-wise perturbations; and

f) iteratively performing steps a)-e) until an attack succeeds or a query limit is reached.

2. The method of claim 1 , wherein the tentative perturbation is defined as the sign values of the perturbation.

3. The method of claim 1 , wherein the tentative perturbation is a random perturbation, wherein the perturbation for each input dimension is generated randomly with 50% probability of being either 1 or −1.

4. The method of claim 1 , wherein the tentative perturbation is a static perturbation, wherein the perturbation for each input dimension is fixed to 1.

5. The method of claim 1 , wherein the tentative perturbation is a transferred perturbation, wherein the perturbation can alternatively be transferred from existing pre-trained image models.

6. The method of claim 1 , wherein each tentative perturbation patch is adjusted by multiplying all its dimensions by a rectification factor found by a gradient estimator.

7. The method of claim 6 , wherein the gradient estimator is FD or NES.

8. The method of claim 1 , wherein the partitioning step includes dividing input dimensions randomly into a certain number of partitions.

9. The method of claim 1 , wherein the partitioning step includes splitting a frame uniformly into some patches.

10. The method of claim 1 , wherein the partitioning step includes partitioning the video input according to its semantic content.

11. The method of claim 1 , wherein a successful attack comprises the situation that an untargeted adversarial example has been found or a targeted adversarial example.

12. The method of claim 1 , wherein the query limit is preset.

13. The method of claim 11 , wherein the untargeted adversarial example is an example that can be misclassified in an arbitrary class other than the correct one.

14. The method of claim 11 , wherein the targeted adversarial example is an example that can be misclassified in a targeted adversarial class.

15. The method of claim 1 , wherein the public image model is pre-trained ImageNet.

16. A system for providing black-box video attacks on a video recognition model, comprising:

a) a perturbation creator for creating pixel-wise tentative perturbations by passing input video frames into a public image model;

b) a partitioner for dividing the tentative perturbations into tentative perturbation patches;

c) a black-box gradient estimator for estimating the rectification weight required for each patch, via querying the target video model;

d) a patch-based rectifier for applying the patch-wise rectification weight on the patches, to obtain the rectified pixel-wise perturbations;

e) a frame modifier for applying one step projected gradient descent (PGD) perturbation on the input video, according to the rectified pixel-wise perturbations;

f) a counter for counting query numbers; and

g) a receiver for receiving the recognition result from the video recognition model;

wherein the perturbation creator, the partitioner, the black-box gradient estimator, the patch-based rectifier and the frame modifier work iteratively, until the query numbers reach a query limit in the counter, or a result including an untargeted adversarial example or a target adversarial example is received by the receiver.

17. The system of claim 16 , wherein the partitioner divides the tentative perturbations into tentative perturbation patches randomly.

18. The system of claim 16 , wherein the partitioner divides the tentative perturbations into tentative perturbation patches uniformly.

19. The system of claim 16 , wherein the partitioner divides the tentative perturbations into tentative perturbation patches according to the semantic content of the tentative perturbations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2020
From: JIANG, YUGANG; JIANG, LINXI; MA, XINGJUN
To: FUDAN UNIVERSITY
Reel/Frame 051909/0594 →
Cited By (7)
US 12,488,242 US 12,511,545 US 12,524,574 US 12,536,838 US 12,596,941 US 12,597,246 US 12,738,028