arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.33948cs.CR

TrackFlood:将延迟攻击从无NMS检测器转移到实时跟踪器

TrackFlood: Relocating Latency Attacks from NMS-Free Detectors to Real-Time Trackers

Zonghua Gu, Julian Singh-Smith, Junlin Liao, Di Liu, Amin Saremi

首次发表
浏览论文内容

中文总结 AI 辅助

TrackFlood针对无NMS检测-跟踪流水线,通过优化扰动淹没跟踪器,实现延迟攻击,强调评估需考虑下游跟踪和端到端时序。

中文摘要 AI 辅助

我们考虑针对目标检测器的延迟攻击,在这种攻击中,攻击者的目标不是破坏预测,而是使系统无法及时响应,针对自动驾驶等实时应用。现代目标检测器通过一对一分配或集合预测消除了非极大值抑制(NMS),从而移除了先前延迟(“海绵”)攻击所利用的经典检测器侧延迟瓶颈。我们表明,无NMS并不意味着延迟鲁棒:这种架构变化并未消除攻击面,而是将其转移到下游的多目标跟踪,其数据关联成本仍然依赖于内容。我们提出了TrackFlood,一种针对无NMS检测-跟踪流水线的统一白盒过载攻击,涵盖一对一检测器(YOLOv10和YOLO26)和基于查询的检测器(RT-DETR)。TrackFlood恢复可微的置信度张量,并优化扰动,用空间分布的幻影检测淹没跟踪器,同时保持检测器推理不变。完全在NVIDIA Jetson AGX Orin(TensorRT FP16)上评估,检测器延迟基本保持不变,而跟踪器延迟显著增加。在标准的不可感知预算(L∞=8/255)下,通用扰动产生明显可测量的跟踪器过载,但端到端减速适中,对于关联主导的跟踪器没有截止时间错过;一个单独的高预算压力测试导致严重的端到端减速和持续的截止时间错过。我们进一步评估了一个轻量级、架构无关的有界接纳层,该层限制跟踪器工作负载,并基本恢复端到端延迟,但以接纳的干净检测为不小的代价。我们的结果表明,评估无NMS感知系统需要考虑下游跟踪和端到端时序,而不仅仅是检测器推理。

英文摘要

We consider latency attacks on object detectors, where the attacker's goal is not to corrupt a prediction but to make the system fail to respond in time, targeting real-time applications such as autonomous driving. Modern object detectors eliminate Non-Maximum Suppression (NMS) through one-to-one assignment or set prediction, removing the classical detector-side latency bottleneck exploited by prior latency (``sponge'') attacks. We show that NMS-free does not mean latency-robust: this architectural change does not eliminate the attack surface but relocates it downstream to multi-object tracking, whose data-association cost remains content dependent. We present \emph{TrackFlood}, a unified white-box overload attack against NMS-free detect-then-track pipelines spanning both one-to-one detectors (YOLOv10 and YOLO26) and query-based detectors (RT-DETR). TrackFlood recovers differentiable confidence tensors and optimizes perturbations that flood the tracker with spatially distributed phantom detections while leaving detector inference unchanged. Evaluated entirely on an NVIDIA Jetson AGX Orin (TensorRT FP16), detector latency remains essentially constant, whereas tracker latency increases substantially. At a standard imperceptible budget ($L_\infty{=}8/255$), a universal perturbation produces clearly measurable tracker overload but only modest end-to-end slowdown, without deadline misses for the association-dominated trackers; a separate higher-budget stress test drives severe end-to-end slowdowns and sustained deadline misses. We further evaluate a lightweight, architecture-agnostic bounded-admission layer that caps the tracker workload and largely restores end-to-end latency, at a non-trivial cost in admitted clean detections. Our results demonstrate that evaluating NMS-free perception systems requires considering downstream tracking and end-to-end timing, not detector inference alone.

发表机构

  • Hofstra University(霍夫斯特拉大学)
  • Norwegian University of Science and Technology(挪威科技大学)
  • Umeå University(于默奥大学)

机构由 AI 辅助整理,请以论文原文为准。

↑