• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

对视频检索系统的隐秘且高效的对抗样本攻击。

Stealthy and efficient adversarial example attack on video retrieval systems.

作者信息

Yao Xin, Li Enlang, Chen Yimin, Guo Jiawei, Huang Kecheng, Tang Fengxiao, Zhao Ming

机构信息

School of Computer Science and Engineering, Central South University, Changsha, 410083, Hunan, China.

School of Computer Science and Engineering, Central South University, Changsha, 410083, Hunan, China.

出版信息

Neural Netw. 2025 Nov;191:107829. doi: 10.1016/j.neunet.2025.107829. Epub 2025 Jul 3.

DOI:10.1016/j.neunet.2025.107829
PMID:40639149
Abstract

Massive videos are released every day particularly through video-focused social media apps like TikTok. This trend has fostered the quick emergence of video retrieval systems, which provide video retrieval services using machine learning techniques. Adversarial example (AE) attacks have been shown to be effective on such systems by perturbing an unaltered video subtly to induce false retrieval results. Such AE attacks can be easily detected because the adversarial perturbations are all over pixels and frames. In this paper, we propose DUO, a stealthy targeted black-box AE attack which uses DUal search Over frame-pixel to generate sparse perturbations and improve stealthiness and query efficiency. DUO is driven by three observations: only "key video frames" decide the model predictions, and different pixels and frames contribute far differently to AEs, and pixels in a frame exhibit locality. Subsequently we propose two AE attacks: DUO featuring pixel sparsity and DUO featuring group sparsity. Our sequential attack pipeline consists of two components, i.e., SparseTransfer and SparseQuery. In effect, DUO utilizes SparseTransfer to generate initial perturbations and then SparseQuery to further rectify them. Meanwhile, DUO focuses on individual pixels, whereas DUO targets groups of pixels. Extensive evaluations on two popular datasets confirm the improved stealthiness and efficacy of DUO over existing AE attacks on video retrieval systems. Particularly, DUO can achieve higher precision while significantly reducing adversarial perturbations by more than ×100 than state-of-the-art, and DUO is with more than ×10 fewer queries.

摘要

每天都会发布大量视频,尤其是通过TikTok等专注于视频的社交媒体应用程序。这种趋势推动了视频检索系统的迅速出现,这些系统使用机器学习技术提供视频检索服务。对抗样本(AE)攻击已被证明对此类系统有效,通过巧妙地扰动未改变的视频来诱导错误的检索结果。这种AE攻击很容易被检测到,因为对抗性扰动遍布像素和帧。在本文中,我们提出了DUO,一种隐秘的有针对性的黑盒AE攻击,它使用帧像素双重搜索来生成稀疏扰动,并提高隐秘性和查询效率。DUO基于三个观察结果:只有“关键视频帧”决定模型预测,不同的像素和帧对AE的贡献差异很大,并且帧中的像素具有局部性。随后,我们提出了两种AE攻击:具有像素稀疏性的DUO和具有组稀疏性的DUO。我们的顺序攻击管道由两个组件组成,即SparseTransfer和SparseQuery。实际上,DUO利用SparseTransfer生成初始扰动,然后利用SparseQuery进一步修正它们。同时,DUO关注单个像素,而DUO针对像素组。对两个流行数据集的广泛评估证实了DUO相对于视频检索系统上现有AE攻击的隐秘性和有效性有所提高。特别是,DUO可以实现更高的精度,同时将对抗性扰动显著减少超过100倍,比现有技术水平少10倍以上的查询次数。

相似文献

1
Stealthy and efficient adversarial example attack on video retrieval systems.对视频检索系统的隐秘且高效的对抗样本攻击。
Neural Netw. 2025 Nov;191:107829. doi: 10.1016/j.neunet.2025.107829. Epub 2025 Jul 3.
2
Prescription of Controlled Substances: Benefits and Risks管制药品的处方:益处与风险
3
Short-Term Memory Impairment短期记忆障碍
4
Identifying significant features in adversarial attack detection framework using federated learning empowered medical IoT network security.利用联邦学习赋能的医疗物联网网络安全在对抗攻击检测框架中识别显著特征。
Sci Rep. 2025 Aug 26;15(1):31485. doi: 10.1038/s41598-025-14913-0.
5
Anterior Approach Total Ankle Arthroplasty with Patient-Specific Cut Guides.使用患者特异性截骨导向器的前路全踝关节置换术。
JBJS Essent Surg Tech. 2025 Aug 15;15(3). doi: 10.2106/JBJS.ST.23.00027. eCollection 2025 Jul-Sep.
6
AdvFaceGAN: a face dual-identity impersonation attack method based on generative adversarial networks.AdvFaceGAN:一种基于生成对抗网络的面部双重身份伪装攻击方法。
PeerJ Comput Sci. 2025 Jun 11;11:e2904. doi: 10.7717/peerj-cs.2904. eCollection 2025.
7
Healthcare workers' informal uses of mobile phones and other mobile devices to support their work: a qualitative evidence synthesis.医护人员非正规使用手机和其他移动设备来支持工作:定性证据综合评价。
Cochrane Database Syst Rev. 2024 Aug 27;8(8):CD015705. doi: 10.1002/14651858.CD015705.pub2.
8
The Black Book of Psychotropic Dosing and Monitoring.《精神药物剂量与监测黑皮书》
Psychopharmacol Bull. 2024 Jul 8;54(3):8-59.
9
DeePosit, an AI-based tool for detecting mouse urine and fecal depositions from thermal video clips of behavioral experiments.DeePosit是一种基于人工智能的工具,用于从行为实验的热视频片段中检测小鼠尿液和粪便沉积。
Elife. 2025 Aug 28;13:RP100739. doi: 10.7554/eLife.100739.
10
Comparison of Two Modern Survival Prediction Tools, SORG-MLA and METSSS, in Patients With Symptomatic Long-bone Metastases Who Underwent Local Treatment With Surgery Followed by Radiotherapy and With Radiotherapy Alone.两种现代生存预测工具 SORG-MLA 和 METSSS 在接受手术联合放疗和单纯放疗治疗有症状长骨转移患者中的比较。
Clin Orthop Relat Res. 2024 Dec 1;482(12):2193-2208. doi: 10.1097/CORR.0000000000003185. Epub 2024 Jul 23.