Meta-Attack Perturbation Generation for Generalized Target Tracker Deception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Adversarial attacks pose a significant threat to autonomous driving systems by deceiving visual tracking systems, leading to incorrect recognition and tracking results, and existing attack methods lack sufficient generalization capability and balance between effectiveness and speed, affecting the performance and safety of these systems.

Innovation Solution

An adaptive meta-attack system and method for target trackers, comprising an initialization module, meta-training iteration module, meta-testing module, and inference module, which includes a perturbation generator trained through diverse network structures to generate adversarial examples that effectively deceive target trackers across various models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional adversarial attack methods are used, then attack effectiveness is improved, but generalization capability deteriorates

Engineering Contradiction:
Improveattack effectivenessVSAvoidgeneralization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a tracker model pool containing multiple diverse tracker models (Siamese network, Transformer-based trackers) that can be dynamically selected and combined. This universal approach allows the adversarial attack system to generalize across different tracker architectures, solving the problem of poor generalization while maintaining high attack effectiveness through ensemble strategies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs meta-learning techniques that dynamically adjust attack parameters and perturbation strategies based on the target tracker's characteristics. By changing parameters adaptively rather than using fixed attack configurations, the system achieves both high attack effectiveness and broad generalization capability across different tracker models.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If complex attack algorithms are used, then attack strength is improved, but computational speed deteriorates

Engineering Contradiction:
Improveattack strengthVSAvoidcomputational speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent pre-trains the tracker model pool and establishes attack strategies in advance through meta-learning. This preliminary action allows the system to quickly deploy pre-computed adversarial perturbations during actual attacks, reducing real-time computational overhead while maintaining strong attack effectiveness through pre-optimized attack configurations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent divides the attack process into distinct modules: perturbation generation, tracker model selection, and adversarial example construction. This segmentation allows each module to be optimized independently, with the perturbation generator focusing on attack strength and the model selection module managing computational efficiency through intelligent routing and ensemble strategies.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12625953B2Adaptive meta-attack system and method for target tracker under autonomous driving scenarios
Publication Date: 2026.05.12 HANGZHOU DIANZI UNIV
  • US12625953B2 patent drawing

AI summary

An adaptive meta-attack system for target trackers under autonomous driving scenarios including an initialization module, a meta-training iteration module, a meta-testing module, a perturbation generator, and an inference module. The initialization module includes a model initialization sub-module and a parameter initialization sub-module. The meta-training iteration module includes a video input sub-module, a training-validation model division sub-module, and a meta-training sub-module. The meta-testing module includes a performance validation and evaluation sub-module and a parameter output sub-module. An adaptive meta-attack method for a target tracker under autonomous driving scenarios applied in the adaptive meta-attack system is further provided.