{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T00:19:51Z","timestamp":1760228391679,"version":"build-2065373602"},"reference-count":33,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2022,5,12]],"date-time":"2022-05-12T00:00:00Z","timestamp":1652313600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Adversarial examples have aroused great attention during the past years owing to their threat to the deep neural networks (DNNs). Recently, they have been successfully extended to video models. Compared with image cases, the sparse adversarial perturbations in the videos can not only reduce the computation complexity, but also guarantee the crypticity of adversarial examples. In this paper, we propose an efficient attack to generate adversarial video perturbations with large sparsity in both the temporal (inter-frames) and spatial (intra-frames) domains. Specifically, we select the key frames and key pixels according to the gradient feedback of the target models by computing the forward derivative, and then add the perturbations on them. To overcome the problem of dimensional explosion in the video, we introduce super-pixels to decrease the number of pixels that need to compute gradients. The proposed method is finally verified under both the white-box and black-box settings. We estimate the gradients using natural evolution strategy (NES) in the black-box attacks. The experiments are conducted on two widely used datasets: UCF101 and HMDB51 versus two mainstream models: C3D and LRCN. Results show that compared with the state-of-the-art method, our method can achieve the similar attacking performance, but it pollutes only &lt;1% pixels and costs less time to finish the attacks.<\/jats:p>","DOI":"10.3390\/s22103686","type":"journal-article","created":{"date-parts":[[2022,5,12]],"date-time":"2022-05-12T23:08:36Z","timestamp":1652396916000},"page":"3686","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Sparse Adversarial Video Attacks via Superpixel-Based Jacobian Computation"],"prefix":"10.3390","volume":"22","author":[{"given":"Zhenyu","family":"Du","sequence":"first","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fangzheng","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuehu","family":"Yan","sequence":"additional","affiliation":[{"name":"College of Electronic Engineering, National University of Defense Technology, Hefei 230037, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,5,12]]},"reference":[{"key":"ref_1","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015, January 7\u20139). Explaining and harnessing adversarial examples. Proceedings of the ICLR 2015, San Diego, CA, USA."},{"key":"ref_2","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D. (2022, May 05). Robust Physical-World Attacks on Deep Learning Models, Available online: http:\/\/xxx.lanl.gov\/abs\/1707.08945."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M.K. (2016, January 24\u201328). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. Proceedings of the ACM Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978392"},{"key":"ref_4","unstructured":"Komkov, S., and Petiushko, A. (2019). AdvHat: Real-world adversarial attack on ArcFace Face ID system. arXiv."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Xu, K., Zhang, G., Liu, S., Fan, Q., Sun, M., Chen, H., Chen, P.Y., Wang, Y., and Lin, X. (2020, January 23\u201328). Adversarial T-shirt! Evading Person Detectors in A Physical World. Proceedings of the European Conference on Computer Vision, Glasgow, UK.","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"481","DOI":"10.1007\/s10994-017-5663-3","article-title":"Analysis of classifiers\u2019 robustness to adversarial perturbations","volume":"107","author":"Fawzi","year":"2018","journal-title":"Mach. Learn."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., and Frossard, P. (2016, January 27\u201330). DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. Proceedings of the CVPR, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Romeo, L., Marani, R., Petitti, A., Milella, A., D\u2019Orazio, T., and Cicirelli, G. (2020, January 19\u201321). Image-Based Mobility Assessment in Elderly People from Low-Cost Systems of Cameras: A Skeletal Dataset for Experimental Evaluations. Proceedings of the Ad-Hoc, Mobile, and Wireless Networks, Bari, Italy.","DOI":"10.1007\/978-3-030-61746-2_10"},{"key":"ref_9","unstructured":"Wei, X., Zhu, J., Yuan, S., and Su, H. (February, January 27). Sparse Adversarial Perturbations for Videos. Proceedings of the AAAI Conference on Artificial Intelligence."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Li, S., Neupane, A., Paul, S., Song, C., Krishnamurthy, S.V., Chowdhury, A.K.R., and Swami, A. (2018). Adversarial Perturbations Against Real-Time Video Classification Systems. arXiv.","DOI":"10.14722\/ndss.2019.23202"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Jiang, L., Ma, X., Chen, S., Bailey, J., and Jiang, Y.G. (2019, January 21\u201325). Black-box adversarial attacks on video recognition models. Proceedings of the ACMMM, Nice, France.","DOI":"10.1145\/3343031.3351088"},{"key":"ref_12","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2016). Adversarial examples in the physical world. arXiv."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J. (2018, January 18\u201323). Boosting Adversarial Attacks with Momentum. Proceedings of the 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"2274","DOI":"10.1109\/TPAMI.2012.120","article-title":"SLIC superpixels compared to state-of-the-art superpixel methods","volume":"34","author":"Achanta","year":"2012","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_15","first-page":"949","article-title":"Natural evolution strategies","volume":"15","author":"Wierstra","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref_16","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2022, May 05). Intriguing Properties of Neural Networks, Available online: http:\/\/xxx.lanl.gov\/abs\/1312.6199."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Swami, A., and Harang, R. (2016, January 1\u20133). Crafting adversarial input sequences for recurrent neural networks. Proceedings of the IEEE Military Communications Conference, Baltimore, MD, USA.","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201324). Towards Evaluating the Robustness of Neural Networks. Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Fawzi, O., and Frossard, P. (2017, January 21\u201326). Universal adversarial perturbations. Proceedings of the CVPR, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Chen, P.Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.J. (2017, January 3). ZOO: Zeroth order optimization based black-box atacks to deep neural networks without training substitute models. Proceedings of the AISec, Dallas, TX, USA.","DOI":"10.1145\/3128572.3140448"},{"key":"ref_21","unstructured":"Tu, C., Ting, P., Chen, P., Liu, S., Zhang, H., Yi, J., Hsieh, C., and Cheng, S. (February, January 27). AutoZOOM: Autoencoder-based Zeroth Order Optimization Method for Attacking Black-box Neural Networks. Proceedings of the AAAI Conference on Artificial Intelligence."},{"key":"ref_22","unstructured":"Brendel, W., Rauber, J., and Bethge, M. (May, January 30). Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. Proceedings of the ICLR, Vancouver, BC, Canada."},{"key":"ref_23","unstructured":"Cheng, M., Zhang, H., Hsieh, C.J., Le, T., Chen, P.Y., and Yi, J. (2019, January 6\u20139). Query-efficient hard-label black-box attack: An optimization-based approach. Proceedings of the ICLR, New Orleans, LA, USA."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Bacco, M., Cassar\u00e0, P., Gotta, A., and Puddu, M. (2020, January 19\u201321). A Simulation Framework for QoE-Aware Real-Time Video Streaming in Multipath Scenarios. Proceedings of the Ad-Hoc, Mobile, and Wireless Networks, Bari, Italy.","DOI":"10.1007\/978-3-030-61746-2_9"},{"key":"ref_25","unstructured":"Wei, Z., Chen, J., Wei, X., Jiang, L., Chua, T.S., Zhou, F., and Jiang, Y.G. (2019, January 10\u201316). Heuristic Black-box Adversarial Attacks on Video Recognition Models. Proceedings of the IJCAI, Macao, China."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Papernot, N., Mcdaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A. (2016, January 21\u201324). The limitations of deep learning in adversarial settings. Proceedings of the 2016 IEEE European Symposium on Security and Privacy, EURO S and P 2016, Saarbruecken, Germany.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref_27","unstructured":"Eyas, A., Engstrom, L., Athalye, A., and Lin, J. (2018, January 10\u201315). Black-box adversarial attacks with limited queries and information. Proceedings of the ICML, Stockholm, Sweden."},{"key":"ref_28","unstructured":"Soomro, K., Zamir, A.R., and Shah, M. (2012, January 19). UCF101: A Dataset of 101 Human Actions Classes From Videos in The Wild. Proceedings of the CoRR, Bertinoro, Italy."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kuehne, H., Jhuang, H., Garrote, E., Poggio, T., and Serre, T. (2011, January 17\u201321). HMDB: A Large Video Database for Human Motion Recognition H. Proceedings of the HLRS, Hamburg, Germany.","DOI":"10.1109\/ICCV.2011.6126543"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Tran, D., Bourdev, L., Fergus, R., Torresani, L., and Paluri, M. (2015, January 7\u201313). Learning spatiotemporal features with 3D convolutional networks. Proceedings of the ICCV, Santiago, Chile.","DOI":"10.1109\/ICCV.2015.510"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Hara, K., Kataoka, H., and Satoh, Y. (2018, January 18\u201322). Can Spatiotemporal 3D CNNs Retrace the History of 2D CNNs and ImageNet?. Proceedings of the CVPR, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00685"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z. (2016, January 27\u201330). Rethinking the Inception Architecture for Computer Vision. Proceedings of the CVPR, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref_33","first-page":"125","article-title":"Adversarial Examples Are Not Bugs, They Are Features","volume":"32","author":"Engstrom","year":"2019","journal-title":"Distill"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/10\/3686\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:09:43Z","timestamp":1760137783000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/10\/3686"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,12]]},"references-count":33,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2022,5]]}},"alternative-id":["s22103686"],"URL":"https:\/\/doi.org\/10.3390\/s22103686","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2022,5,12]]}}}