Return
SVAttack: Spatial-Viewpoint Transfer Attack on Graph Convolutional Skeleton Action Recognition
DOI:10.1109/tifs.2026.3734764.png)
Abstract
En 中文
Skeleton-based action recognition with graph convolutional networks has achieved remarkable success and is increasingly deployed in safety-critical applications. This necessitates research on possible attack methods and their limitations. The existing adversarial attacks on skeleton-based models suffer from limited transferability across architectures and often exhibit noticeable perceptual distortion. In this work, we investigate the architectural inductive biases that fundamentally constrain transferability in skeleton-based action recognition. Based on a structural and gradient-level analysis, we propose (1) a spatial gradient damper to suppress model-specific spatial biases and (2) a viewpoint-based constraint mechanism to improve perceptual imperceptibility. Extensive experimental results on 3 benchmark datasets, 9 skeleton-based action recognition models, 7 attack methods, and 2 defense methods demonstrate that the proposed approach significantly enhances transferability while maintaining visually plausible skeleton motions. It establishes a new state of the art for transferable adversarial attacks on skeleton-based action recognition models. Our code is available at https://github.com/deep-wu/SVAttack.
Keywords:
Architectural Inductive Biases
Graph Convolution
Transfer Attack
Action Recognition
Journal
IF:
8
Papers:
5.3K
Citations:
2.3W
Organization
Cited Papers
No cited papers available

