A Patch Can Disrupt Live Video Streaming: Physical Adversarial Attacks on Deep Learning Compression

Yuqing Yang, Anh Nguyen, Zhisheng Yan · ACM Transactions on Multimedia Computing Communications and Applications · 2025

Deep learning (DL)-based compression has achieved outstanding performance compared to traditional compression. However, due to the vulnerability of adversarial attacks on DL models, understanding the security of DL-based compression is crucial. Previous attacks have demonstrated the feasibility of failing DL-based compression models in the digital domain. However, these attacks rely on perfect digital modification of the whole image and internal access to camera/server files, preventing their usage in the physical world where such assumptions do not hold. In this article, we unveil the first physical adversarial attack targeting DL-based compression in the context of live video streaming. The proposed attack, namely CamHack , places a small-sized physical patch in the visual scene covered by the live camera to manipulate the bitrate of compressed content and disrupt live streaming. The patch is crafted to address color and geometric transformations in diverse streaming scenes while remaining inconspicuous. Extensive experiments in various streaming scenes and network conditions show that CamHack increases bit consumption by 276.58%, 384.74%, and 942.28% over the clean scene without a patch on three representative victim models. CamHack is also robust under various practical impacts such as patch location, lighting conditions, and patch size.

Read the paper · More papers on PaperTik