{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-perturbations-against-real-time","title":"Adversarial Perturbations Against Real-Time Video Classification Systems","arxiv_id":"1807.00458","date":"2018-07-02","proceeding":null,"authors":["Shasha Li","Ajaya Neupane","Sujoy Paul","Chengyu Song","Srikanth V. Krishnamurthy","Amit K. Roy Chowdhury","Ananthram Swami"],"abstract":"Recent research has demonstrated the brittleness of machine learning systems\nto adversarial perturbations. However, the studies have been mostly limited to\nperturbations on images and more generally, classification that does not deal\nwith temporally varying inputs. In this paper we ask \"Are adversarial\nperturbations possible in real-time video classification systems and if so,\nwhat properties must they satisfy?\" Such systems find application in\nsurveillance applications, smart vehicles, and smart elderly care and thus,\nmisclassification could be particularly harmful (e.g., a mishap at an elderly\ncare facility may be missed). We show that accounting for temporal structure is\nkey to generating adversarial examples in such systems. We exploit recent\nadvances in generative adversarial network (GAN) architectures to account for\ntemporal correlations and generate adversarial samples that can cause\nmisclassification rates of over 80% for targeted activities. More importantly,\nthe samples also leave other activities largely unaffected making them\nextremely stealthy. Finally, we also surprisingly find that in many scenarios,\nthe same perturbation can be applied to every frame in a video clip that makes\nthe adversary's ability to achieve misclassification relatively easy.","url_abs":"http://arxiv.org/abs/1807.00458v1","url_pdf":"http://arxiv.org/pdf/1807.00458v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-perturbations-against-real-time","repo_url":"https://github.com/sli057/Video-Perturbation","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}}],"tasks":[{"task_slug":"classification-1","task_name":"Classification"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":null,"task_name":"Generative Adversarial Network"},{"task_slug":"video-classification","task_name":"Video Classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=1807.00458","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}