DIMBA: Discretely Masked Black-Box Attack in Single Object Tracking

Published in Machine Learning (Springer) 2024, 2024

We develop a method to generate adversarial perturbations for single object tracking under black-box settings, where perturbations are added only on initialized frames rather than throughout entire videos. Our approach uses reinforcement learning to identify critical frame patches while minimizing computational overhead. We evaluate DIMBA on both long-term and short-term datasets—OTB100, VOT2018, UAV123, and LaSOT—and demonstrate effectiveness across three tracker types: discrimination-based, Siamese-based, and reinforcement learning-based models. We release DIMBA as an open-source tool to facilitate further research into neural network vulnerability and robustness in object tracking.