Physics-constrained Attack against Convolution-based Human Motion Prediction

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Duan, Chengxu, Zhang, Zhicheng, Liu, Xiaoli, Dang, Yonghao, Yin, Jianqin
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913284098097152
author Duan, Chengxu
Zhang, Zhicheng
Liu, Xiaoli
Dang, Yonghao
Yin, Jianqin
author_facet Duan, Chengxu
Zhang, Zhicheng
Liu, Xiaoli
Dang, Yonghao
Yin, Jianqin
contents Human motion prediction has achieved a brilliant performance with the help of convolution-based neural networks. However, currently, there is no work evaluating the potential risk in human motion prediction when facing adversarial attacks. The adversarial attack will encounter problems against human motion prediction in naturalness and data scale. To solve the problems above, we propose a new adversarial attack method that generates the worst-case perturbation by maximizing the human motion predictor's prediction error with physical constraints. Specifically, we introduce a novel adaptable scheme that facilitates the attack to suit the scale of the target pose and two physical constraints to enhance the naturalness of the adversarial example. The evaluating experiments on three datasets show that the prediction errors of all target models are enlarged significantly, which means current convolution-based human motion prediction models are vulnerable to the proposed attack. Based on the experimental results, we provide insights on how to enhance the adversarial robustness of the human motion predictor and how to improve the adversarial attack against human motion prediction.
format Preprint
id arxiv_https___arxiv_org_abs_2306_11990
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Physics-constrained Attack against Convolution-based Human Motion Prediction
Duan, Chengxu
Zhang, Zhicheng
Liu, Xiaoli
Dang, Yonghao
Yin, Jianqin
Computer Vision and Pattern Recognition
Human motion prediction has achieved a brilliant performance with the help of convolution-based neural networks. However, currently, there is no work evaluating the potential risk in human motion prediction when facing adversarial attacks. The adversarial attack will encounter problems against human motion prediction in naturalness and data scale. To solve the problems above, we propose a new adversarial attack method that generates the worst-case perturbation by maximizing the human motion predictor's prediction error with physical constraints. Specifically, we introduce a novel adaptable scheme that facilitates the attack to suit the scale of the target pose and two physical constraints to enhance the naturalness of the adversarial example. The evaluating experiments on three datasets show that the prediction errors of all target models are enlarged significantly, which means current convolution-based human motion prediction models are vulnerable to the proposed attack. Based on the experimental results, we provide insights on how to enhance the adversarial robustness of the human motion predictor and how to improve the adversarial attack against human motion prediction.
title Physics-constrained Attack against Convolution-based Human Motion Prediction
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2306.11990