Dual-Dimensional Adversarial Attacks: A Novel Spatial and Temporal Attack Strategy for Multi-Object Tracking
Weilong Zhang, Fang Ou Yang, Zhao Guan · 2024
Deep learning-based Multi-Object Tracking (MOT) systems are vulnerable to adversarial attacks, which pose significant security and privacy risks to the system. Therefore, researching adversarial attacks in MOT is crucial for developing more secure tracking technologies. Currently, research on adversarial attacks in MOT is capable of conducting attacks on both object detectors and feature extraction components but encounters limitations in applicability. Moreover, these methods overlook the relationship between spatial and temporal dimensions in MOT, thus constraining their effectiveness. To solve the aforementioned issues, we propose a novel method of attack, termed the Dual-Dimensional Adversarial Attack (DDAA), implying that DDAA takes account of adversarial attacks from both spatial and temporal perspectives. DDAA is actualized via two pivotal loss functions: the drift loss function, which is used to reduce the area of the tracking box and move it to the image edge, thereby interrupting the tracker’s precise tracking of the target in the spatial dimension; and the feature loss function, which destroys the similarity between object features in consecutive frames, effectively hindering the tracker from accurately tracking based on temporal information. The experimental results show that DDAA can significantly reduce the tracking performance of mainstream MOT models and is clearly superior to existing attack strategies. Overall, our experimental results demonstrate that DDAA is an effective attack strategy, offering new perspectives and implications for the design and security evaluation of MOT systems in the future.