Adversarial Attack Detection for Video Surveillance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Video surveillance systems employing Deep Neural Network (DNN) models for image segmentation are vulnerable to attacks that create small perturbations in input images, delayed inference attacks, and mimicking attacks that exploit publicly available pre-trained models.
Innovation Solution
A method for detecting attacks on video surveillance systems involves dynamic monitoring of image segmentation model outputs, intelligent analysis of predictions, and the use of an adversarial image generator to train a discriminator that distinguishes genuine from malicious images, even with an imperfect discriminator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If image segmentation DNN models are used for video surveillance, then the system can perform automated object classification and tracking, but the system becomes vulnerable to adversarial attacks that create small perturbations in input images to fool the segmentation model
Solution Approach 1:
The patent introduces an intermediary detection system that sits between the adversarial attack and the image segmentation model. This intermediary component analyzes the relationship between consecutive video frames and detects adversarial perturbations before they reach the segmentation model, thereby protecting the automated classification system while maintaining its automation benefits
Solution Approach 2:
The system implements feedback by continuously monitoring the output of the image segmentation model and comparing it with the original video frames. When adversarial attacks are detected through frame comparison and perturbation analysis, the system provides feedback to alert operators or trigger corrective measures, creating a closed-loop protection mechanism
2Reliability
If the system monitors and analyzes predictions continuously to detect attacks, then the reliability against adversarial attacks improves, but the computational complexity and processing time increase
Solution Approach 1:
The patent applies preliminary action by performing frame comparison and perturbation detection on consecutive video frames before the adversarial attack can fully compromise the segmentation model. By detecting attacks in advance through simple frame differencing and perturbation analysis, the system reduces the need for complex real-time analysis during critical moments
Solution Approach 2:
The detection system is segmented into multiple independent components: frame comparison module, perturbation detection module, and alert generation module. This segmentation allows each component to perform its specific function with optimized complexity, reducing the overall system complexity while maintaining comprehensive attack detection capability
3Productivity
If publicly available pre-trained models are used through transfer learning, then the system can be deployed faster with less training data, but the system becomes more vulnerable to mimicking attacks that exploit these public models
Solution Approach 1:
The patent introduces an intermediary protection layer that detects mimicking attacks targeting publicly available pre-trained models. This intermediary system monitors for characteristic patterns of mimicking attacks and provides protection without requiring modification of the underlying pre-trained model, thus maintaining deployment speed while adding security
Solution Approach 2:
The system applies preliminary anti-action by proactively detecting and alerting on mimicking attacks before they can successfully compromise the surveillance system. By using frame comparison and perturbation analysis, the system creates a preliminary defense mechanism that counteracts the vulnerability introduced by using publicly available pre-trained models
Data Source
AI summary
One example method includes dynamically monitoring a stream of image portions that have been classified by a segmentation model of a video surveillance system, evaluating the image portions, based on the evaluating, determining that an attack on the video surveillance system is occurring, or has occurred, and implementing, or causing the implementation of, a remedial action with regard to the attack. The image portions may be image portions that have been classified by a segmentation model.


