Physical Adversarial Attacks on AI Surveillance Systems:Detection, Tracking, and Visible--Infrared Evasion

📅 2026-04-08
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses a critical limitation in existing physical adversarial attack research, which predominantly relies on single-frame image evaluations and fails to capture the robustness of real-world surveillance systems under temporal continuity, multi-sensor fusion, and practical deployment constraints. To bridge this gap, the authors propose a four-dimensional evaluation framework tailored for surveillance systems, encompassing temporal identity consistency, visible-infrared dual-modality evasion, controllable wearable carrier feasibility, and system-level target alignment. By integrating multi-object tracking, dual-modality adversarial sample generation, and real-world deployment tests, the study exposes the inadequacy of single-frame assessments and underscores the necessity of system-level robustness validation across time, modalities, and realistic operational conditions. It further highlights key challenges such as distance-dependent robustness and discrepancies in camera processing pipelines.

Technology Category

Application Category

📝 Abstract
Physical adversarial attacks are increasingly studied in settings that resemble deployed surveillance systems rather than isolated image benchmarks. In these settings, person detection, multi-object tracking, visible--infrared sensing, and the practical form of the attack carrier all matter at once. This changes how the literature should be read. A perturbation that suppresses a detector in one frame may have limited practical effect if identity is recovered over time; an RGB-only result may say little about night-time systems that rely on visible and thermal inputs together; and a conspicuous patch can imply a different threat model from a wearable or selectively activated carrier. This paper reviews physical attacks from that surveillance-oriented viewpoint. Rather than attempting a complete catalogue of all physical attacks in computer vision, we focus on the technical questions that become central in surveillance: temporal persistence, sensing modality, carrier realism, and system-level objective. We organize prior work through a four-part taxonomy and discuss how recent results on multi-object tracking, dual-modal visible--infrared evasion, and controllable clothing reflect a broader change in the field. We also summarize evaluation practices and unresolved gaps, including distance robustness, camera-pipeline variation, identity-level metrics, and activation-aware testing. The resulting picture is that surveillance robustness cannot be judged reliably from isolated per-frame benchmarks alone; it has to be examined as a system problem unfolding over time, across sensors, and under realistic physical deployment constraints.
Problem

Research questions and friction points this paper is trying to address.

physical adversarial attacks
surveillance systems
multi-object tracking
visible-infrared sensing
system-level robustness
Innovation

Methods, ideas, or system contributions that make the work stand out.

physical adversarial attacks
multi-object tracking
visible-infrared evasion
system-level robustness
controllable clothing
M
Miguel A. DelaCruz
Department of Computer Science, University of the Philippines Diliman, Quezon City, Philippines
P
Patricia Mae Santos
Department of Information Systems and Computer Science, Ateneo de Manila University, Quezon City, Philippines
R
Rafael T. Navarro
College of Computer Studies, De La Salle University, Manila, Philippines