Abstract
Multi‐object tracking (MOT) models have achieved great success in wide ranging applications, such as video surveillance and autonomous driving, especially for those deep neural networks (DNNs) based MOT, which obtained the state‐of‐the‐art detection performance. Unfortunately, existing research has unveiled that DNNs are vulnerable to carefully crafted adversarial perturbations, leading to catastrophic consequences. In order to explore the adversarial vulnerability of MOT, we propose PhantomVeil, a novel physical camouflage for DNN based MOT. PhantomVeil significantly differs from previous work in four aspects: (1) effectiveness—by undermining the data association between the detection and tracking stages of MOT models, our method reliably ensures a high probability of attack success; (2) generality—by targeting the common core mechanisms of MOT models, we design an efficient loss optimization strategy that enables generalized attacks across different models; (3) transferability—Gaussian smoothing and color gamut constraints are introduced, it reduces the adversarial attenuation when transferring from the digital domain to the physical domain and improves the effectiveness of target transfer in the physical domain by restricting drastic pixel value fluctuations and ensuring printable color values; (4) practicability —extensive experiments conducted on two public datasets and one self‐built dataset demonstrate that PhantomVeil outperforms four baseline methods on three multi‐object trackers (with digital‐domain attack performance reaching 1.02 6.07 that of the baselines and physical‐domain attack performance reaching 6.07 that of the baselines), verifying its advantages in practicality, effectiveness, and generalization.