Recently, methods for skeleton-based human activity recognition have been shown to be vulnerable to adversarial attacks. However, these attack methods require either the full knowledge of the victim (i.e. white-box attacks), access to training data (i.e. transfer-based attacks) or frequent model queries (i.e. black-box attacks). All their requirements are highly restrictive, raising the question of how detrimental the vulnerability is. In this paper, we show that the vulnerability indeed exists. To this end, we consider a new attack task: the attacker has no access to the victim model or the training data or labels, where we coin the term hard no-box attack. Specifically, we first learn a motion manifold where we define an adversarial loss to compute a new gradient for the attack, named skeleton-motion-informed (SMI) gradient. Our gradient contains information of the motion dynamics, which is different from existing gradient-based attack methods that compute the loss gradient assuming each dimension in the data is independent. The SMI gradient can augment many gradient-based attack methods, leading to a new family of no-box attack methods. Extensive evaluation and comparison show that our method imposes a real threat to existing classifiers. They also show that the SMI gradient improves the transferability and imperceptibility of adversarial samples in both no-box and transfer-based black-box settings.
翻译:最近,基于骨骼的人体动作识别方法已被证明容易受到对抗攻击。然而,这些攻击方法要么需要完全了解受害者模型(即白盒攻击),要么需要访问训练数据(即基于迁移的攻击),要么需要频繁查询模型(即黑盒攻击)。它们的所有要求都具有高度限制性,这引发了一个问题:这种脆弱性的危害程度究竟有多大。在本文中,我们证明这种脆弱性确实存在。为此,我们考虑一种新的攻击任务:攻击者无法访问受害者模型、训练数据或标签,我们将其称为硬无盒攻击。具体而言,我们首先学习一个运动流形,并在其上定义对抗损失以计算一种新的攻击梯度,称为骨骼运动信息(SMI)梯度。我们的梯度包含运动动态信息,这与现有基于梯度的攻击方法不同——后者计算损失梯度时假设数据每个维度相互独立。SMI梯度可以增强许多基于梯度的攻击方法,从而形成一族新的无盒攻击方法。大量评估和比较表明,我们的方法对现有分类器构成了真实威胁。同时,结果还显示SMI梯度在无盒和基于迁移的黑盒设置中均提升了对抗样本的可迁移性和不可感知性。