Investigating vulnerabilities of gait recognition model using latent-based perturbations
Zeeshan Ali1, Maryam Bukhari2, Mubashir Javaid3
1Department of Software Development and Automation, National University of Computer and Emerging Sciences, Islamabad, Pakistan.
Scientific Reports
|November 10, 2025
Summary
This study introduces a novel black-box attack for gait recognition systems, enhancing security surveillance. The BLG attack achieves a 94.33% success rate, offering a realistic method to test model vulnerabilities.
Area of Science:
- Computer Science
- Artificial Intelligence
- Security Systems
Background:
- Video surveillance is crucial for security, with gait recognition offering unique identification capabilities.
- Deep learning models for gait recognition are vulnerable to adversarial attacks, posing a significant security challenge.
- Existing attacks often require extensive model access or lack real-world applicability.
Purpose of the Study:
- To propose a novel, practical, and transferable black-box attack against gait recognition systems.
- To develop an attack method that is effective and perceptually realistic in limited-access scenarios.
- To evaluate the vulnerability of gait recognition models to sophisticated adversarial attacks.
Main Methods:
- Introduced the Black-box-Latent-GEI (BLG) attack, a novel black-box adversarial technique.
- Developed AdvHelper, a surrogate model to simulate the target gait recognition system.
- Implemented PerturbGen using an encoder-decoder framework with reconstruction and perceptual losses for realistic perturbations.
Main Results:
- The BLG attack achieved a high success rate of 94.33% on the CASIA-gait dataset.
- Adversarial samples generated were both effective and perceptually realistic.
- Demonstrated the feasibility of black-box attacks in realistic surveillance contexts.
Conclusions:
- The proposed BLG attack presents a significant advancement in understanding adversarial vulnerabilities in gait recognition.
- The method offers a practical and transferable approach for evaluating model robustness.
- Highlights the need for developing more resilient gait recognition systems against sophisticated adversarial threats.
Related Concept Videos
Stereotype Content Model
13.1K
The Stereotype Content Model (SCM) was first proposed by Susan Fiske and her colleagues (Fiske, Cuddy, Glick & Xu, 2002; see also Fiske, 2012 and Fiske, 2017). The SCM specifies that when someone encounters a new group, they will stereotype them based on two metrics: warmth—or that group’s perceived intent, and how likely they are to provide help or inflict harm—and competence—or their ability to carry out that objective. Depending on the warmth-competence...
13.1K
Leaky Scanning
4.5K
During most eukaryotic translation processes, the small 40S ribosome subunit scans an mRNA from its 5' end until it encounters the first start AUG codon. The large 60S ribosomal subunit then joins the smaller one to initiate protein synthesis. The location of the translation initiation is largely determined by the nucleotides near the start codon as there may be multiple translation initiation sites present on the mRNA. Marilyn Kozak discovered that the sequence RCCAUGG (where R...
4.5K
Detection of Black Holes
1.7K
Although black holes were theoretically postulated in the 1920s, they remained outside the domain of observational astronomy until the 1970s.
Their closest cousins are neutron stars, which are composed almost entirely of neutrons packed against each other, making them extremely dense. A neutron star has the same mass as the Sun but its diameter is only a few kilometers. Therefore, the escape velocity from their surface is close to the speed of light.
Not until the 1960s, when the first neutron...
Their closest cousins are neutron stars, which are composed almost entirely of neutrons packed against each other, making them extremely dense. A neutron star has the same mass as the Sun but its diameter is only a few kilometers. Therefore, the escape velocity from their surface is close to the speed of light.
Not until the 1960s, when the first neutron...
1.7K
Types of Errors: Detection and Minimization
8.7K
Error is the deviation of the obtained result from the true, expected value or the estimated central value. Errors are expressed in absolute or relative terms.
Absolute error in a measurement is the numerical difference from the true or central value. Relative error is the ratio between absolute error and the true or central value, expressed as a percentage.
Errors can be classified by source, magnitude, and sign. There are three types of errors: systematic, random, and gross.
Systematic or...
Absolute error in a measurement is the numerical difference from the true or central value. Relative error is the ratio between absolute error and the true or central value, expressed as a percentage.
Errors can be classified by source, magnitude, and sign. There are three types of errors: systematic, random, and gross.
Systematic or...
8.7K
Detection of Gross Error: The Q Test
7.1K
When one or more data points appear far from the rest of the data, there is a need to determine whether they are outliers and whether they should be eliminated from the data set to ensure an accurate representation of the measured value. In many cases, outliers arise from gross errors (or human errors) and do not accurately reflect the underlying phenomenon. In some cases, however, these apparent outliers reflect true phenomenological differences. In these cases, we can use statistical methods...
7.1K


