Understanding the Vulnerability of Skeleton-based Human Activity Recognition via Black-box Attack

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Diao, Yunfeng, Wang, He, Shao, Tianjia, Yang, Yong-Liang, Zhou, Kun, Hogg, David, Wang, Meng
Formato: Preprint
Publicado: 2022
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909189953028096
author Diao, Yunfeng
Wang, He
Shao, Tianjia
Yang, Yong-Liang
Zhou, Kun
Hogg, David
Wang, Meng
author_facet Diao, Yunfeng
Wang, He
Shao, Tianjia
Yang, Yong-Liang
Zhou, Kun
Hogg, David
Wang, Meng
contents Human Activity Recognition (HAR) has been employed in a wide range of applications, e.g. self-driving cars, where safety and lives are at stake. Recently, the robustness of skeleton-based HAR methods have been questioned due to their vulnerability to adversarial attacks. However, the proposed attacks require the full-knowledge of the attacked classifier, which is overly restrictive. In this paper, we show such threats indeed exist, even when the attacker only has access to the input/output of the model. To this end, we propose the very first black-box adversarial attack approach in skeleton-based HAR called BASAR. BASAR explores the interplay between the classification boundary and the natural motion manifold. To our best knowledge, this is the first time data manifold is introduced in adversarial attacks on time series. Via BASAR, we find on-manifold adversarial samples are extremely deceitful and rather common in skeletal motions, in contrast to the common belief that adversarial samples only exist off-manifold. Through exhaustive evaluation, we show that BASAR can deliver successful attacks across classifiers, datasets, and attack modes. By attack, BASAR helps identify the potential causes of the model vulnerability and provides insights on possible improvements. Finally, to mitigate the newly identified threat, we propose a new adversarial training approach by leveraging the sophisticated distributions of on/off-manifold adversarial samples, called mixed manifold-based adversarial training (MMAT). MMAT can successfully help defend against adversarial attacks without compromising classification accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2211_11312
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Understanding the Vulnerability of Skeleton-based Human Activity Recognition via Black-box Attack
Diao, Yunfeng
Wang, He
Shao, Tianjia
Yang, Yong-Liang
Zhou, Kun
Hogg, David
Wang, Meng
Computer Vision and Pattern Recognition
Human Activity Recognition (HAR) has been employed in a wide range of applications, e.g. self-driving cars, where safety and lives are at stake. Recently, the robustness of skeleton-based HAR methods have been questioned due to their vulnerability to adversarial attacks. However, the proposed attacks require the full-knowledge of the attacked classifier, which is overly restrictive. In this paper, we show such threats indeed exist, even when the attacker only has access to the input/output of the model. To this end, we propose the very first black-box adversarial attack approach in skeleton-based HAR called BASAR. BASAR explores the interplay between the classification boundary and the natural motion manifold. To our best knowledge, this is the first time data manifold is introduced in adversarial attacks on time series. Via BASAR, we find on-manifold adversarial samples are extremely deceitful and rather common in skeletal motions, in contrast to the common belief that adversarial samples only exist off-manifold. Through exhaustive evaluation, we show that BASAR can deliver successful attacks across classifiers, datasets, and attack modes. By attack, BASAR helps identify the potential causes of the model vulnerability and provides insights on possible improvements. Finally, to mitigate the newly identified threat, we propose a new adversarial training approach by leveraging the sophisticated distributions of on/off-manifold adversarial samples, called mixed manifold-based adversarial training (MMAT). MMAT can successfully help defend against adversarial attacks without compromising classification accuracy.
title Understanding the Vulnerability of Skeleton-based Human Activity Recognition via Black-box Attack
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2211.11312