Physical ID-Transfer Attacks against Multi-Object Tracking via Adversarial Trajectory
Multi-object tracking (MOT) exhibits security vulnerabilities during the data association stage, where attackers can exploit physically realizable adversarial trajectories (AdvTraj) to evade detection modules and illegitimately transfer their identity to target objects, causing ID confusion. This work proposes the first online, physically implementable ID manipulation attack that requires no modification to the detector; instead, it designs universal adversarial motion patterns to perturb mainstream association algorithms. Evaluated on the CARLA simulation platform, the attack achieves 100% success rate against SORT under both white-box and black-box settings, and attains up to 93% cross-model transferability against state-of-the-art MOT methods. Our findings expose a common vulnerability inherent in MOT association mechanisms, offering a novel perspective for robustness evaluation and establishing a benchmark adversarial paradigm for tracking systems.