FrameShield: Adversarially Robust Video Anomaly Detection

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Nafez, Mojtaba, Poulaei, Mobina, Vasei, Nikan, Moakhar, Bardia Soltani, Sabokrou, Mohammad, Rohban, MohammadHossein
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866912668970909696
author Nafez, Mojtaba
Poulaei, Mobina
Vasei, Nikan
Moakhar, Bardia Soltani
Sabokrou, Mohammad
Rohban, MohammadHossein
author_facet Nafez, Mojtaba
Poulaei, Mobina
Vasei, Nikan
Moakhar, Bardia Soltani
Sabokrou, Mohammad
Rohban, MohammadHossein
contents Weakly Supervised Video Anomaly Detection (WSVAD) has achieved notable advancements, yet existing models remain vulnerable to adversarial attacks, limiting their reliability. Due to the inherent constraints of weak supervision, where only video-level labels are provided despite the need for frame-level predictions, traditional adversarial defense mechanisms, such as adversarial training, are not effective since video-level adversarial perturbations are typically weak and inadequate. To address this limitation, pseudo-labels generated directly from the model can enable frame-level adversarial training; however, these pseudo-labels are inherently noisy, significantly degrading performance. We therefore introduce a novel Pseudo-Anomaly Generation method called Spatiotemporal Region Distortion (SRD), which creates synthetic anomalies by applying severe augmentations to localized regions in normal videos while preserving temporal consistency. Integrating these precisely annotated synthetic anomalies with the noisy pseudo-labels substantially reduces label noise, enabling effective adversarial training. Extensive experiments demonstrate that our method significantly enhances the robustness of WSVAD models against adversarial attacks, outperforming state-of-the-art methods by an average of 71.0\% in overall AUROC performance across multiple benchmarks. The implementation and code are publicly available at https://github.com/rohban-lab/FrameShield.
format Preprint
id arxiv_https___arxiv_org_abs_2510_21532
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle FrameShield: Adversarially Robust Video Anomaly Detection
Nafez, Mojtaba
Poulaei, Mobina
Vasei, Nikan
Moakhar, Bardia Soltani
Sabokrou, Mohammad
Rohban, MohammadHossein
Machine Learning
Weakly Supervised Video Anomaly Detection (WSVAD) has achieved notable advancements, yet existing models remain vulnerable to adversarial attacks, limiting their reliability. Due to the inherent constraints of weak supervision, where only video-level labels are provided despite the need for frame-level predictions, traditional adversarial defense mechanisms, such as adversarial training, are not effective since video-level adversarial perturbations are typically weak and inadequate. To address this limitation, pseudo-labels generated directly from the model can enable frame-level adversarial training; however, these pseudo-labels are inherently noisy, significantly degrading performance. We therefore introduce a novel Pseudo-Anomaly Generation method called Spatiotemporal Region Distortion (SRD), which creates synthetic anomalies by applying severe augmentations to localized regions in normal videos while preserving temporal consistency. Integrating these precisely annotated synthetic anomalies with the noisy pseudo-labels substantially reduces label noise, enabling effective adversarial training. Extensive experiments demonstrate that our method significantly enhances the robustness of WSVAD models against adversarial attacks, outperforming state-of-the-art methods by an average of 71.0\% in overall AUROC performance across multiple benchmarks. The implementation and code are publicly available at https://github.com/rohban-lab/FrameShield.
title FrameShield: Adversarially Robust Video Anomaly Detection
topic Machine Learning
url https://arxiv.org/abs/2510.21532