• Home
  • Search
  • Towards Patch-Based Noise Compression for Adversarial Attack Against Transformer-Based Visual Tracking
  • https://doi.org/10.1109/tifs.2025.3648551Copy DOI Icon

Towards Patch-Based Noise Compression for Adversarial Attack Against Transformer-Based Visual Tracking

  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

In recent years, with the widespread application of Vision Transformer (ViT) in visual trackers, their robustness has received increasing attention. However, by focusing on global interactions between image patches, ViT reduces sensitivity to local noise, posing new challenges for adversarial attacks. Meanwhile, existing decision-based adversarial attack methods often overlook the differences in noise sensitivity between different patches, further limiting the compression efficiency of adversarial noise, especially in ViT. In visual tracking, existing adversarial attack methods primarily target Siamese network-based trackers, and research on adversarial attacks against Transformer-based trackers, particularly decision-based black-box attacks, is still relatively limited. To implement effective black-box attacks on Transformer-based trackers, this paper innovatively proposes patch-based adversarial noise compression (PANC), a decision-based adversarial attack method. This method effectively compresses adversarial noise patch by patch, significantly improving compression efficiency and attack concealment. PANC also introduces a noise sensitivity matrix that dynamically adds and reduces adversarial noise, optimizing the spatial distribution of noise while decreasing the number of queries. We validated the effectiveness of the proposed PANC attack method on several Transformer-based trackers, including OSTrack, STARK, TransT, and MixformerV2, and three public large-scale benchmark datasets: GOT-10k, TrackingNet, and LaSOT. Experimental results show that compared to the existing state-of-the-art adversarial attack method, the IoU attack, PANC compresses the noise level to 10%, improving the attack effectiveness by 162% with the number of queries of only 45.7%. Furthermore, PANC can serve as an initialization or post-processing optimization strategy for other adversarial attack methods, providing a more flexible and efficient mechanism for adversarial example generation. Our work reveals the vulnerabilities of existing Transformer-based visual trackers and offers new ideas for further improving the efficiency and concealment of adversarial attacks.

Similar Papers
  • Research Article
  • Citations3

Adversarial attack method against image classification based on haze perturbation

  • Feb 01, 2023
  • SCIENTIA SINICA Informationis
  • 伟 冯 +3
  • Research Article
  • Citations2

General Sparse Adversarial Attack Method for SAR Images Based on Keypoints

  • Oct 01, 2025
  • IEEE Transactions on Aerospace and Electronic Systems
  • Fei Gao +5
  • Research Article
  • Citations12

A Word-Level Adversarial Attack Method Based on Sememes and an Improved Quantum-Behaved Particle Swarm Optimization.

  • Nov 01, 2024
  • IEEE Transactions on Neural Networks and Learning Systems
  • Qidong Chen +2
  • Research Article
  • Citations7

Multiloss Adversarial Attacks for Multimodal Remote Sensing Image Classification

  • Jan 01, 2024
  • IEEE Transactions on Geoscience and Remote Sensing
  • Qi Hu +3
  • Research Article
  • Citations112

Adversarial examples: A survey of attacks and defenses in deep learning-enabled cybersecurity systems

  • Oct 20, 2023
  • Expert Systems with Applications
  • Mayra Macas +2
  • Research Article
  • Citations6

Evaluating Impact of Image Transformations on Adversarial Examples

  • Jan 01, 2024
  • IEEE Access
  • Pu Tian +5
  • Conference Article
  • Citations45

Universal Adversarial Attack Via Enhanced Projected Gradient Descent

  • Oct 01, 2020
  • Yingpeng Deng +1
  • Research Article
  • Citations19

EnsembleFool: A method to generate adversarial examples based on model fusion strategy

  • May 07, 2021
  • Computers & Security
  • Wenyu Peng +6
  • Research Article
  • Citations23

FAWA: Fast Adversarial Watermark Attack

  • Mar 12, 2021
  • IEEE Transactions on Computers
  • Hao Jiang +6
  • Research Article
  • Citations3

Explanation-Guided Adversarial Example Attacks

  • Mar 26, 2024
  • Big Data Research
  • Anli Yan +4
  • Conference Article

AS-ES: Sparse Black-box Adversarial Attack by Active Subspace Evolution Strategy

  • Jan 01, 2025
  • Duan Jinling
  • Research Article
  • Citations22

Adversarial Sample Attack and Defense Method for Encrypted Traffic Data

  • Oct 01, 2022
  • IEEE Transactions on Intelligent Transportation Systems
  • Yi Ding +5
  • PDF
  • Research Article
  • Citations26

On the Effectiveness of Adversarial Training in Defending against Adversarial Example Attacks for Image Classification

  • Nov 14, 2020
  • Applied Sciences
  • Sanglee Park +1
  • Research Article
  • Citations1

DiffProtect: Generative adversarial examples using diffusion models for facial privacy protection

  • May 01, 2026
  • Pattern Recognition
  • Jiang Liu +5
  • PDF
  • Research Article
  • Citations8

A CMA-ES-Based Adversarial Attack on Black-Box Deep Neural Networks

  • Jan 01, 2019
  • IEEE Access
  • Xiaohui Kuang +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.