• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

对抗性度量攻击与防御在行人再识别中的应用

Adversarial Metric Attack and Defense for Person Re-Identification.

出版信息

IEEE Trans Pattern Anal Mach Intell. 2021 Jun;43(6):2119-2126. doi: 10.1109/TPAMI.2020.3031625. Epub 2021 May 11.

DOI:10.1109/TPAMI.2020.3031625
PMID:33064650
Abstract

Person re-identification (re-ID) has attracted much attention recently due to its great importance in video surveillance. In general, distance metrics used to identify two person images are expected to be robust under various appearance changes. However, our work observes the extreme vulnerability of existing distance metrics to adversarial examples, generated by simply adding human-imperceptible perturbations to person images. Hence, the security danger is dramatically increased when deploying commercial re-ID systems in video surveillance. Although adversarial examples have been extensively applied for classification analysis, it is rarely studied in metric analysis like person re-identification. The most likely reason is the natural gap between the training and testing of re-ID networks, that is, the predictions of a re-ID network cannot be directly used during testing without an effective metric. In this work, we bridge the gap by proposing Adversarial Metric Attack, a parallel methodology to adversarial classification attacks. Comprehensive experiments clearly reveal the adversarial effects in re-ID systems. Meanwhile, we also present an early attempt of training a metric-preserving network, thereby defending the metric against adversarial attacks. At last, by benchmarking various adversarial settings, we expect that our work can facilitate the development of adversarial attack and defense in metric-based applications.

摘要

由于在视频监控中的重要性,人体重识别(re-ID)最近引起了广泛关注。通常,用于识别两个人体图像的距离度量应能在各种外观变化下稳健。然而,我们的工作观察到,现有距离度量在对抗样本下非常脆弱,这些对抗样本是通过简单地向人体图像添加人眼不可察觉的扰动而生成的。因此,当在视频监控中部署商业 re-ID 系统时,安全风险大大增加。尽管对抗样本已被广泛应用于分类分析,但在像人体重识别这样的度量分析中却很少被研究。最可能的原因是 re-ID 网络的训练和测试之间存在天然的差距,即如果没有有效的度量,re-ID 网络的预测在测试期间不能直接使用。在这项工作中,我们通过提出对抗度量攻击来弥合这一差距,这是一种与对抗分类攻击并行的方法。全面的实验清楚地揭示了 re-ID 系统中的对抗效应。同时,我们还首次尝试训练一种保持度量的网络,从而防御度量免受对抗攻击。最后,通过对各种对抗设置进行基准测试,我们希望我们的工作能够促进基于度量的应用中的对抗攻击和防御的发展。

相似文献

1
Adversarial Metric Attack and Defense for Person Re-Identification.对抗性度量攻击与防御在行人再识别中的应用
IEEE Trans Pattern Anal Mach Intell. 2021 Jun;43(6):2119-2126. doi: 10.1109/TPAMI.2020.3031625. Epub 2021 May 11.
2
Towards Robust Person Re-Identification by Defending Against Universal Attackers.通过抵御通用攻击者实现鲁棒的行人重识别
IEEE Trans Pattern Anal Mach Intell. 2023 Apr;45(4):5218-5235. doi: 10.1109/TPAMI.2022.3199013. Epub 2023 Mar 7.
3
Defending Person Detection Against Adversarial Patch Attack by Using Universal Defensive Frame.利用通用防御框架防御对抗性补丁攻击的人像检测。
IEEE Trans Image Process. 2022;31:6976-6990. doi: 10.1109/TIP.2022.3217375. Epub 2022 Nov 14.
4
Enhancing robustness in video recognition models: Sparse adversarial attacks and beyond.增强视频识别模型的鲁棒性:稀疏对抗攻击及其他。
Neural Netw. 2024 Mar;171:127-143. doi: 10.1016/j.neunet.2023.11.056. Epub 2023 Nov 25.
5
Privacy Preserving Defense For Black Box Classifiers Against On-Line Adversarial Attacks.隐私保护的黑盒分类器对抗在线对抗攻击。
IEEE Trans Pattern Anal Mach Intell. 2022 Dec;44(12):9503-9520. doi: 10.1109/TPAMI.2021.3125931. Epub 2022 Nov 7.
6
Adversarial attack vulnerability of medical image analysis systems: Unexplored factors.对抗攻击对医学影像分析系统的漏洞:未知因素。
Med Image Anal. 2021 Oct;73:102141. doi: 10.1016/j.media.2021.102141. Epub 2021 Jun 18.
7
Adversarial Examples: Attacks and Defenses for Deep Learning.对抗样本:深度学习的攻击与防御。
IEEE Trans Neural Netw Learn Syst. 2019 Sep;30(9):2805-2824. doi: 10.1109/TNNLS.2018.2886017. Epub 2019 Jan 14.
8
Image-Level Adaptive Adversarial Ranking for Person Re-Identification.用于行人重识别的图像级自适应对抗排序
IEEE Trans Image Process. 2024;33:5172-5182. doi: 10.1109/TIP.2024.3456000. Epub 2024 Sep 19.
9
Approaching Adversarial Example Classification with Chaos Theory.用混沌理论处理对抗性示例分类问题。
Entropy (Basel). 2020 Oct 24;22(11):1201. doi: 10.3390/e22111201.
10
DualFlow: Generating imperceptible adversarial examples by flow field and normalize flow-based model.双流:通过流场和基于归一化流的模型生成不可察觉的对抗样本。
Front Neurorobot. 2023 Feb 9;17:1129720. doi: 10.3389/fnbot.2023.1129720. eCollection 2023.