arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.03902cs.AI

当效率成为脆弱性:利用自适应无人机跟踪中的动态路由漏洞

When Efficiency Becomes Fragility: Exploiting Dynamic Routing Vulnerabilities in Adaptive UAV Tracking

Shaofeng Liang, Runwei Guan, Wenshuo Chen, Jiemin Wu, Bowen Tian, Haozhe Jia, Kaishen Yuan, Songning Lai, Daizong Liu, Yutao Yue

首次发表
浏览论文内容

中文总结 AI 辅助

该研究发现自适应无人机跟踪器的动态路由架构存在 Lipschitz 奇异性漏洞,提出 API 框架操纵门控决策破坏模型,为动态跟踪网络安全分析开辟新维度。

中文摘要 AI 辅助

无人机平台的资源限制推动了空中跟踪的范式转变,从追求性能转向平衡精度与效率。利用依赖输入的动态路由架构的自适应 Transformer 跟踪器已成为应对这一挑战的代表性解决方案。然而,我们揭示这种按需计算的灵活性背后隐藏着一个关键结构缺陷:计算路径决策的 Lipschitz 奇异性,其在离散跳层决策边界处具有无界的局部 Lipschitz 常数。这种数学不连续性使自适应跟踪网络本质上不稳定:微小的输入扰动会在门控模块处被放大,导致推理拓扑发生剧烈变化。我们在自适应跟踪架构的背景下正式表征了这种奇异性,并首次将其确定为可直接利用的新型攻击面。这一发现揭示了一个此前被忽视且高度脆弱的拓扑路径空间攻击面。基于此,我们提出了对抗性路径反转(Adversarial Path-Inversion, API)框架。API 生成不可感知的扰动以精确操纵门控决策,迫使推理进入改变后的计算路径。原始路径与反转路径之间的严重不一致会破坏模型的表示能力。在最先进的自适应跟踪器上进行的大量实验表明,API 具有卓越的扰动隐蔽性、更有效的攻击效果和更快的推理速度。这项工作为动态跟踪网络的安全分析开辟了新维度,并为未来构建鲁棒的自适应跟踪架构提供了理论警示。

英文摘要

Resource constraints on UAV platforms have driven a paradigm shift in aerial tracking, from pursuing performance toward balancing accuracy with efficiency. Adaptive Transformer Trackers, which leverage an input-dependent dynamic routing architecture, have emerged as a representative solution to this challenge. However, we reveal that behind this computation-on-demand flexibility hides a critical structural flaw: the Lipschitz singularity of computational path decisions, which has an unbounded local Lipschitz constant at discrete layer-skipping decision boundaries. This mathematical discontinuity renders adaptive tracking networks inherently unstable: tiny input perturbations can be amplified at the gating modules, causing dramatic changes in the inference topology. We formally characterize this singularity in the context of adaptive tracking architectures and, for the first time, identify it as a directly exploitable new attack surface. This insight reveals a previously overlooked and highly vulnerable topological path space attack surface. Based on this, we propose the Adversarial Path-Inversion (API) framework. API generates imperceptible perturbations to precisely manipulate the gating decisions, forcing the inference onto altered computational paths. The severe inconsistency between the original and the inverted paths dismantles the representation capability of the model. Extensive experiments on state-of-the-art adaptive trackers demonstrate that API achieves superior perturbation stealthiness, more effective attack, and faster inference speeds. This work opens a new dimension for the security analysis of dynamic tracking networks and provides a theoretical warning for constructing robust adaptive tracking architectures in the future.

↑