Adversarial Machine Learning Attacks Against Video Anomaly Detection Systems

Adversarial Machine Learning Attacks Against Video Anomaly Detection Systems
复制标题

DOI:
10.1109/cvprw56347.2022.00034
复制
发表时间:
2022-04
期刊:
2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW)
影响因子:
--
通讯作者:
Furkan Mumcu;Keval Doshi;Yasin Yılmaz
Furkan Mumcu;Keval Doshi;Yasin Yılmaz
中科院分区:
其他
文献类型:
--
作者:
Furkan Mumcu;Keval Doshi;Yasin Yılmaz

文献摘要

相似文献

视频中的异常检测是包括自动视频监控在内的各种应用中的一个重要计算机视觉问题。虽然对图像理解模型的对抗性攻击已经进行了大量的研究,但针对视频理解模型的对抗性机器学习的工作并不多,并且以前没有专注于视频异常检测的工作。为此,我们研究了针对视频异常检测系统的对抗性机器学习攻击,该攻击可以通过易于执行的网络攻击来实现。由于监控摄像机通常通过无线网络连接到运行异常检测模型的服务器,因此它们容易受到针对无线连接的网络攻击。我们演示了如何Wi-Fi去认证攻击,一个众所周知的易于执行和有效的拒绝服务(DoS)攻击,可以用来生成视频异常检测系统的对抗数据。具体来说,我们将Wi-Fi取消认证攻击对视频质量造成的几种影响(例如,慢下来,冻结,快进,低分辨率)到流行的基准数据集的视频异常检测。我们的实验与几个国家的最先进的异常检测模型表明,攻击者可以显着破坏视频异常检测系统的可靠性,造成频繁的误报和隐藏的物理异常从监控系统。
Anomaly detection in videos is an important computer vision problem with various applications including auto-mated video surveillance. Although adversarial attacks on image understanding models have been heavily investigated, there is not much work on adversarial machine learning targeting video understanding models and no previous work which focuses on video anomaly detection. To this end, we investigate an adversarial machine learning attack against video anomaly detection systems, that can be implemented via an easy-to-perform cyber-attack. Since surveillance cameras are usually connected to the server running the anomaly detection model through a wireless network, they are prone to cyber-attacks targeting the wireless connection. We demonstrate how Wi-Fi deauthentication attack, a notoriously easy-to-perform and effective denial-of-service (DoS) attack, can be utilized to generate adversarial data for video anomaly detection systems. Specifically, we apply several effects caused by the Wi-Fi deauthentication attack on video quality (e.g., slow down, freeze, fast forward, low resolution) to the popular bench-mark datasets for video anomaly detection. Our experiments with several state-of-the-art anomaly detection models show that the attackers can significantly undermine the reliability of video anomaly detection systems by causing frequent false alarms and hiding physical anomalies from the surveillance system.