基于时空交并比约束的目标跟踪对抗防御方法
Spatio-Temporal IoU Constraints Based Adversarial Defense Method for Object Tracking
盛晶晶 1张大伟 2蔡听依 2肖昕 3郑忠龙 2蒋云良2
作者信息
- 1. 浙江师范大学 计算机科学与技术学院 金华 321004
- 2. 浙江师范大学 计算机科学与技术学院 金华 321004;浙江师范大学 浙江省智能教育技术与应用重点实验室 金华 321004
- 3. 浙江师范大学 浙江省智能教育技术与应用重点实验室 金华 321004
- 折叠
摘要
随着深度学习在视觉跟踪领域的广泛应用,对抗攻击逐渐成为影响方法性能的关键因素之一,然而针对对抗攻击的防御方法研究还处于初始阶段.因此,文中提出基于时空交并比约束的目标跟踪对抗防御方法.首先,在对抗样本上随机添加高斯噪声约束.然后,根据噪声等高线的切线方向,选择噪声等级相同且时空交并比分数最高的切线约束.通过其法线约束使防御目标向原始图像的方向更新,并将法线约束和切线约束进行正交组合优化.最后,经过不断迭代,选择具有最高时空交并比分数且噪声等级最低的组合向量作为最佳约束,添至对抗样本图像中,同时传递给下一帧图像,从而实现时序防御.在VOT2018、OTB100、GOT-10k、LaSOT跟踪数据集上的实验验证文中方法的有效性.
Abstract
With the wide application of deep learning in the field of visual tracking,adversarial attack is one of key factors affecting the model performance.However,the research on defense methods for adversarial attack is still in the initial stage.Therefore,a spatio-temporal intersection over union(IoU)constraints based adversarial defense method for object tracking is proposed.In this method,Gaussian noise constraints are firstly added to the adversarial examples.Then,according to the tangent direction of the noise contour,the tangential constraint with the same noise level and the highest spatio-temporal IoU score is selected.The normal constraint is utilized to update the defense target towards the direction of the original image,and the normal and tangential constraints are orthogonally combined and optimized.Finally,the combined vector with the highest spatio-temporal IoU score and the lowest noise level is selected as the best constraint,and it is added to the adversarial example image and transferred to the next frame image,thereby realizing temporal defense.Experiments on VOT2018,OTB100,GOT-10k and LaSOT tracking datasets verify the validity of the proposed method.
关键词
目标跟踪/对抗防御/对抗攻击/时空交并比Key words
Object Tracking/Adversarial Defense/Adversarial Attack/Spatio-Temporal Intersection over Union引用本文复制引用
基金项目
国家自然科学基金项目(62272419)
浙江省自然科学基金项目(LQ23F020010)
浙江省自然科学基金项目(LZ22F020010)
金华市科技计划项目(2023-4-016)
出版年
2024