StyleFool: Fooling Video Classification Systems via Style Transfer

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cao, Yuxin, Xiao, Xi, Sun, Ruoxi, Wang, Derui, Xue, Minhui, Wen, Sheng
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929296655777792
author Cao, Yuxin
Xiao, Xi
Sun, Ruoxi
Wang, Derui
Xue, Minhui
Wen, Sheng
author_facet Cao, Yuxin
Xiao, Xi
Sun, Ruoxi
Wang, Derui
Xue, Minhui
Wen, Sheng
contents Video classification systems are vulnerable to adversarial attacks, which can create severe security problems in video verification. Current black-box attacks need a large number of queries to succeed, resulting in high computational overhead in the process of attack. On the other hand, attacks with restricted perturbations are ineffective against defenses such as denoising or adversarial training. In this paper, we focus on unrestricted perturbations and propose StyleFool, a black-box video adversarial attack via style transfer to fool the video classification system. StyleFool first utilizes color theme proximity to select the best style image, which helps avoid unnatural details in the stylized videos. Meanwhile, the target class confidence is additionally considered in targeted attacks to influence the output distribution of the classifier by moving the stylized video closer to or even across the decision boundary. A gradient-free method is then employed to further optimize the adversarial perturbations. We carry out extensive experiments to evaluate StyleFool on two standard datasets, UCF-101 and HMDB-51. The experimental results demonstrate that StyleFool outperforms the state-of-the-art adversarial attacks in terms of both the number of queries and the robustness against existing defenses. Moreover, 50% of the stylized videos in untargeted attacks do not need any query since they can already fool the video classification model. Furthermore, we evaluate the indistinguishability through a user study to show that the adversarial samples of StyleFool look imperceptible to human eyes, despite unrestricted perturbations.
format Preprint
id arxiv_https___arxiv_org_abs_2203_16000
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle StyleFool: Fooling Video Classification Systems via Style Transfer
Cao, Yuxin
Xiao, Xi
Sun, Ruoxi
Wang, Derui
Xue, Minhui
Wen, Sheng
Computer Vision and Pattern Recognition
Cryptography and Security
Video classification systems are vulnerable to adversarial attacks, which can create severe security problems in video verification. Current black-box attacks need a large number of queries to succeed, resulting in high computational overhead in the process of attack. On the other hand, attacks with restricted perturbations are ineffective against defenses such as denoising or adversarial training. In this paper, we focus on unrestricted perturbations and propose StyleFool, a black-box video adversarial attack via style transfer to fool the video classification system. StyleFool first utilizes color theme proximity to select the best style image, which helps avoid unnatural details in the stylized videos. Meanwhile, the target class confidence is additionally considered in targeted attacks to influence the output distribution of the classifier by moving the stylized video closer to or even across the decision boundary. A gradient-free method is then employed to further optimize the adversarial perturbations. We carry out extensive experiments to evaluate StyleFool on two standard datasets, UCF-101 and HMDB-51. The experimental results demonstrate that StyleFool outperforms the state-of-the-art adversarial attacks in terms of both the number of queries and the robustness against existing defenses. Moreover, 50% of the stylized videos in untargeted attacks do not need any query since they can already fool the video classification model. Furthermore, we evaluate the indistinguishability through a user study to show that the adversarial samples of StyleFool look imperceptible to human eyes, despite unrestricted perturbations.
title StyleFool: Fooling Video Classification Systems via Style Transfer
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2203.16000