信息网络安全 ›› 2024, Vol. 24 ›› Issue (9): 1386-1395.doi: 10.3969/j.issn.1671-1122.2024.09.007

• 研究论文 • 上一篇    下一篇


陈晓静1, 陶杨1, 吴柏祺2, 刁云峰2()   

  1. 1.安徽大学互联网学院,合肥 230039
    2.合肥工业大学计算机与信息学院,合肥 230009
  • 收稿日期:2023-10-30 出版日期:2024-09-10 发布日期:2024-09-27
  • 通讯作者: 刁云峰
  • 作者简介:陈晓静(1990—),女,安徽,副教授,博士,主要研究方向为计算机视觉、量子通信|陶杨(1998—),女,安徽,硕士研究生,主要研究方向为计算机视觉、人工智能安全|吴柏祺(2003—),男,安徽,主要研究方向为人工智能安全、数据安全及隐私保护|刁云峰(1993—),男,山东,讲师,博士,CCF会员,主要研究方向为人工智能安全、计算机视觉
  • 基金资助:

Optimization Gradient Perception Adversarial Attack for Skeleton-Based Action Recognition

CHEN Xiaojing1, TAO Yang1, WU Baiqi2, DIAO Yunfeng2()   

  1. 1. School of Internet, Anhui University, Hefei 230039, China
    2. School of Computer Science and Information Engineering, Hefei University of Technology, Hefei 230009, China
  • Received:2023-10-30 Online:2024-09-10 Published:2024-09-27



关键词: 骨骼动作识别, 对抗攻击, 深度学习, 迁移对抗攻击


Skeleton-based action recognition models are widely used in the fields of autonomous driving, behavior monitoring and action analysis. Some studies have shown that these models are vulnerable to adversarial attacks, raising security and privacy concerns. Although existing attack methods can achieve high attack success rates under white-box setting, these methods require the attacker to obtain the full-knowledge of the model, which is difficult to achieve in real-world scenarios, and has weak transferability under black-box attacks. In order to solve this problem, the article proposed an optimization gradient perception adversarial attack for skeleton-based action recognition named NAG-PA. This method prioritized estimating the gradient in the next iteration in each iteration of gradient calculation, and accumulated gradients at the updated position. At the same time, the current position was corrected to avoid getting stuck in local optima, thereby improving the transferability of adversarial samples. More importantly, the method proposed in the article used perceptual loss to ensure that transferable attacks were imperceptible. Results on common used datasets and state-of-the-art skeletal action recognition models show that the method proposed in the article can significantly improve the transferability against adversarial attacks.

Key words: skeleton action recognition, adversarial attack, deep learning, transferable adversarial attack
