RoVISQ: Reduction of Video Service Quality via Adversarial Attacks on Deep Learning-based Video Compression
arXiv:2203.10183 · doi:10.14722/ndss.2023.23165
Abstract
Video compression plays a crucial role in video streaming and classification systems by maximizing the end-user quality of experience (QoE) at a given bandwidth budget. In this paper, we conduct the first systematic study for adversarial attacks on deep learning-based video compression and downstream classification systems. Our attack framework, dubbed RoVISQ, manipulates the Rate-Distortion (-) relationship of a video compression model to achieve one or both of the following goals: (1) increasing the network bandwidth, (2) degrading the video quality for end-users. We further devise new objectives for targeted and untargeted attacks to a downstream video classification service. Finally, we design an input-invariant perturbation that universally disrupts video compression and classification systems in real time. Unlike previously proposed attacks on video classification, our adversarial perturbations are the first to withstand compression. We empirically show the resilience of RoVISQ attacks against various defenses, i.e., adversarial training, video denoising, and JPEG compression. Our extensive experimental results on various video datasets show RoVISQ attacks deteriorate peak signal-to-noise ratio by up to 5.6dB and the bit-rate by up to 2.4 while achieving over 90 attack success rate on a downstream classifier. Our user study further demonstrates the effect of RoVISQ attacks on users' QoE.
Accepted at NDSS 2023
References in corpus (10)
- Explaining and Harnessing Adversarial Examples
- UCF101: A Dataset of 101 Human Actions Classes From Videos in The Wild
- A Unified End-to-End Framework for Efficient Deep Image Compression
- Temporal Pyramid Network for Action Recognition
- AdvDrop: Adversarial Attack to DNNs by Dropping Information
- FVC: A New Framework towards Deep Video Compression in Feature Space
- WaveGuard: Understanding and Mitigating Audio Adversarial Examples
- Adversarial Attacks on Black Box Video Classifiers: Leveraging the Power of Geometric Transformations
- Over-the-Air Adversarial Flickering Attacks against Video Recognition Networks
- Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition Systems