Vulnerability of Person Re-Identification Models to Metric Adversarial Attacks

被引:9
|
作者
Bouniot, Quentin [1 ]
Audigier, Romaric [1 ]
Loesch, Angelique [1 ]
机构
[1] CEA, LIST, Vis & Learning Lab Scene Anal, PC 184, F-91191 Gif Sur Yvette, France
来源
2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2020) | 2020年
关键词
D O I
10.1109/CVPRW50498.2020.00405
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Person re-identification (re-ID) is a key problem in smart supervision of camera networks. Over the past years, models using deep learning have become state of the art. However, it has been shown that deep neural networks are flawed with adversarial examples, i.e. human-imperceptible perturbations. Extensively studied for the task of image closed-set classification, this problem can also appear in the case of open-set retrieval tasks. Indeed, recent work has shown that we can also generate adversarial examples for metric learning systems such as re-ID ones. These models remain vulnerable: when faced with adversarial examples, they fail to correctly recognize a person, which represents a security breach. These attacks are all the more dangerous as they are impossible to detect for a human operator. Attacking a metric consists in altering the distances between the feature of an attacked image and those of reference images, i.e. guides. In this article, we investigate different possible attacks depending on the number and type of guides available. From this metric attack family, two particularly effective attacks stand out. The first one, called Self Metric Attack, is a strong attack that does not need any image apart from the attacked image. The second one, called Furthest-Negative Attack, makes full use of a set of images. Attacks are evaluated on commonly used datasets: Market1501 and DukeMTMC. Finally, we propose an efficient extension of adversarial training protocol adapted to metric learning as a defense that increases the robustness of re-ID models.(1)
引用
收藏
页码:3450 / 3459
页数:10
相关论文
共 50 条
  • [21] Multilevel metric rank match for person re-identification
    Wang, Chao
    Pan, ZhengGao
    Li, XueZhu
    COGNITIVE SYSTEMS RESEARCH, 2021, 65 : 98 - 106
  • [22] Deep features for person re-identification on metric learning
    Wu, Wanyin
    Tao, Dapeng
    Li, Hao
    Yang, Zhao
    Cheng, Jun
    PATTERN RECOGNITION, 2021, 110
  • [23] Regularized Bayesian Metric Learning for Person Re-identification
    Liong, Venice Erin
    Lu, Jiwen
    Ge, Yongxin
    COMPUTER VISION - ECCV 2014 WORKSHOPS, PT III, 2015, 8927 : 209 - 224
  • [24] Learning to rank in person re-identification with metric ensembles
    Paisitkriangkrai, Sakrapee
    Shen, Chunhua
    van den Hengel, Anton
    2015 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2015, : 1846 - 1855
  • [25] Deep Cosine Metric Learning for Person Re-Identification
    Wojke, Nicolai
    Bewley, Alex
    2018 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2018), 2018, : 748 - 756
  • [26] Relaxed Pairwise Learned Metric for Person Re-identification
    Hirzer, Martin
    Roth, Peter M.
    Koestinger, Martin
    Bischof, Horst
    COMPUTER VISION - ECCV 2012, PT VI, 2012, 7577 : 780 - 793
  • [27] Discriminative Regularized Metric Learning for Person Re-Identification
    Liong, Venice Erin
    Ge, Yongxin
    Lu, Jiwen
    2015 INTERNATIONAL CONFERENCE ON BIOMETRICS (ICB), 2015, : 52 - 57
  • [28] Weighted Local Metric Learning for Person Re-identification
    Gu, Xinqian
    Ge, Yongxin
    BIOMETRIC RECOGNITION, 2016, 9967 : 686 - 694
  • [29] Visual-textual adversarial learning for person re-identification
    Yin, Pengqi
    MULTIMEDIA SYSTEMS, 2025, 31 (01)
  • [30] Adversarial View Confusion Feature Learning for Person Re-Identification
    Zhang, Lei
    Liu, Fangyi
    Zhang, David
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2021, 31 (04) : 1490 - 1502