Stealth Is a Relation, Not a Property: How Event Representations Create Blind Spots for Timing Attacks in Event-Based Perception

📅 2026-09-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the temporal attack blind spots in event cameras caused by discrepancies in time representation. It introduces the concept of "observer-relative stealthiness," revealing that the imperceptibility of adversarial perturbations depends on the observer's temporal granularity rather than the perturbation itself. Methodologically, by exploiting the precise blind space of accumulation windows, the authors design a null-gradient-guided timestamp retiming attack alongside a C-PGD constrained optimization algorithm, and propose the SC-ASR_A metric to quantify cross-temporal-view attack visibility and success rates. Evaluated on the DVS Gesture and DailyDVS-200 datasets, the proposed approach achieves attack success rates ranging from 81% to 99%, significantly outperforming existing methods and validating the relational nature of stealthiness in event-based adversarial attacks.
📝 Abstract
An event camera produces an asynchronous stream, but what is visible in that stream depends on how a downstream consumer, such as a model or detector, processes time. The same timestamp change may leave a coarse temporal representation unchanged while changing the response of a model that preserves finer timing. We characterize this dependence as observer-relative stealth. For recorded event streams, retiming an event within its protected accumulation window leaves the accumulated integer tensor exactly unchanged. We use this exact blind space to construct Null, a gradient-guided timestamp-retiming attack, and define SC-ASR_A(tau) to measure attack success while bounding the change visible to observer A. On DVS Gesture at a 10% event budget, Null reaches 81.56 +/- 5.81% ASR on ConvSNN and 98.67 +/- 0.45% on a GRU while preserving the protected tensor exactly. On DailyDVS-200, a protocol-scale Multi-View Fusion Network variant reaches 99.28 +/- 0.11% exact-null ASR, compared with 9.70 +/- 1.06% for its matched control. In a five-attack comparison, Null is the only method with nonzero attack success at exact observer equality, reaching 81.4% on DVS Gesture and 87.35% on DailyDVS-200. We also search the same exact blind space with an independently implemented constrained projected-gradient optimizer, C-PGD. At matched victim-gradient evaluations, C-PGD reaches 84.50 +/- 2.89% ASR on DVS Gesture and 89.55 +/- 4.39% on DailyDVS-200, again with exact protected equality. Perturbations that are exactly hidden from the protected observer become visible under shifted, finer, overlapping, and randomized temporal views. Adding observer constraints reduces the real-valued blind-space fraction from 87.5% to 75.0% to 62.5%, while DVS ConvSNN ASR falls from 74.9% to 61.9% to 37.2%. These results show that stealth is not a property of the perturbation alone.
Problem

Research questions and friction points this paper is trying to address.

event-based perception
timing attacks
observer-relative stealth
adversarial robustness
event cameras
Innovation

Methods, ideas, or system contributions that make the work stand out.

Observer-relative Stealth
Timestamp Retiming Attack
Exact Blind Space
Event-based Perception
Adversarial Attack
🔎 Similar Papers
No similar papers found.