Skip to main navigation Skip to search Skip to main content

Consistent Valid Physically-Realizable Adversarial Attack Against Crowd-Flow Prediction Models

  • Hassan Ali
  • , Muhammad Atif Butt
  • , Fethi Filali
  • , Ala Al-Fuqaha
  • , Junaid Qadir*
  • *Corresponding author for this work
  • Information Technology University
  • Qatar University
  • Computer Science and Engineering Department

Research output: Contribution to journalArticlepeer-review

Abstract

Recent works have shown that deep learning (DL) models can effectively learn city-wide crowd-flow patterns, which can be used for more effective urban planning and smart city management. However, DL models have been known to perform poorly on inconspicuous adversarial perturbations. Although many works have studied these adversarial perturbations in general, the adversarial vulnerabilities of deep CFP models in particular have remained largely unexplored. In this paper, we perform a rigorous analysis of the adversarial vulnerabilities of DL-based CFP models under multiple threat settings, making three-fold contributions; 1) we propose by formally identifying two novel properties-Consistency and Validity-of the CFP inputs that enable the detection of standard adversarial inputs with 0% false acceptance rate (FAR); 2) we leverage universal adversarial perturbations and an adaptive adversarial loss to present adaptive adversarial attacks to evade defense; 3) we propose, a Consistent, Valid and Physically-realizable adversarial attack, that explicitly inducts the consistency and validity priors in the perturbation generation mechanism. We find out that although the crowd-flow models are vulnerable to adversarial perturbations, it is extremely challenging to simulate these perturbations in physical settings, notably when is in place. We also show that attack considerably outperforms the adaptively modified standard attacks in FAR and adversarial loss metrics. We conclude with useful insights emerging from our work and highlight promising future research directions.
Original languageEnglish
Pages (from-to)5567-5582
Number of pages16
JournalIEEE Transactions on Intelligent Transportation Systems
Volume25
Issue number6
DOIs
Publication statusPublished - 1 Jun 2024

Keywords

  • Adaptation models
  • Analytical models
  • Cfp
  • Computer architecture
  • Data models
  • Deep neural networks
  • History
  • Perturbation methods
  • Standards
  • adversarial ML

Fingerprint

Dive into the research topics of 'Consistent Valid Physically-Realizable Adversarial Attack Against Crowd-Flow Prediction Models'. Together they form a unique fingerprint.

Cite this