• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

通过抵御通用攻击者实现鲁棒的行人重识别

Towards Robust Person Re-Identification by Defending Against Universal Attackers.

作者信息

Yang Fengxiang, Weng Juanjuan, Zhong Zhun, Liu Hong, Wang Zheng, Luo Zhiming, Cao Donglin, Li Shaozi, Satoh Shin'ichi, Sebe Nicu

出版信息

IEEE Trans Pattern Anal Mach Intell. 2023 Apr;45(4):5218-5235. doi: 10.1109/TPAMI.2022.3199013. Epub 2023 Mar 7.

DOI:10.1109/TPAMI.2022.3199013
PMID:35969571
Abstract

Recent studies show that deep person re-identification (re-ID) models are vulnerable to adversarial examples, so it is critical to improving the robustness of re-ID models against attacks. To achieve this goal, we explore the strengths and weaknesses of existing re-ID models, i.e., designing learning-based attacks and training robust models by defending against the learned attacks. The contributions of this paper are three-fold: First, we build a holistic attack-defense framework to study the relationship between the attack and defense for person re-ID. Second, we introduce a combinatorial adversarial attack that is adaptive to unseen domains and unseen model types. It consists of distortions in pixel and color space (i.e., mimicking camera shifts). Third, we propose a novel virtual-guided meta-learning algorithm for our attack-defense system. We leverage a virtual dataset to conduct experiments under our meta-learning framework, which can explore the cross-domain constraints for enhancing the generalization of the attack and the robustness of the re-ID model. Comprehensive experiments on three large-scale re-ID benchmarks demonstrate that: 1) Our combinatorial attack is effective and highly universal in cross-model and cross-dataset scenarios; 2) Our meta-learning algorithm can be readily applied to different attack and defense approaches, which can reach consistent improvement; 3) The defense model trained on the learning-to-learn framework is robust to recent SOTA attacks that are not even used during training.

摘要

最近的研究表明,深度行人重识别(re-ID)模型容易受到对抗样本的影响,因此提高re-ID模型对攻击的鲁棒性至关重要。为了实现这一目标,我们探究了现有re-ID模型的优缺点,即设计基于学习的攻击,并通过抵御学习到的攻击来训练鲁棒模型。本文的贡献主要有三点:第一,我们构建了一个整体的攻防框架来研究行人re-ID攻击与防御之间的关系。第二,我们引入了一种组合对抗攻击,它适用于未见领域和未见模型类型。它由像素和颜色空间中的失真组成(即模拟相机移动)。第三,我们为我们的攻防系统提出了一种新颖的虚拟引导元学习算法。我们利用一个虚拟数据集在我们的元学习框架下进行实验,该框架可以探索跨域约束,以增强攻击的泛化能力和re-ID模型的鲁棒性。在三个大规模re-ID基准上的综合实验表明:1)我们的组合攻击在跨模型和跨数据集场景中是有效且高度通用的;2)我们的元学习算法可以很容易地应用于不同的攻防方法,并且可以实现一致的改进;3)在学习学习框架上训练的防御模型对最近在训练期间甚至未使用的最先进攻击具有鲁棒性。

相似文献

1
Towards Robust Person Re-Identification by Defending Against Universal Attackers.通过抵御通用攻击者实现鲁棒的行人重识别
IEEE Trans Pattern Anal Mach Intell. 2023 Apr;45(4):5218-5235. doi: 10.1109/TPAMI.2022.3199013. Epub 2023 Mar 7.
2
Adversarial Metric Attack and Defense for Person Re-Identification.对抗性度量攻击与防御在行人再识别中的应用
IEEE Trans Pattern Anal Mach Intell. 2021 Jun;43(6):2119-2126. doi: 10.1109/TPAMI.2020.3031625. Epub 2021 May 11.
3
Multi-Domain Adversarial Feature Generalization for Person Re-Identification.多领域对抗特征泛化的行人再识别
IEEE Trans Image Process. 2021;30:1596-1607. doi: 10.1109/TIP.2020.3046864. Epub 2021 Jan 11.
4
Meta Invariance Defense Towards Generalizable Robustness to Unknown Adversarial Attacks.针对未知对抗攻击的泛化鲁棒性的元不变性防御
IEEE Trans Pattern Anal Mach Intell. 2024 Oct;46(10):6669-6687. doi: 10.1109/TPAMI.2024.3385745. Epub 2024 Sep 5.
5
Style Uncertainty Based Self-Paced Meta Learning for Generalizable Person Re-Identification.基于风格不确定性的自定步元学习在通用人像再识别中的应用
IEEE Trans Image Process. 2023;32:2107-2119. doi: 10.1109/TIP.2023.3263112.
6
Person Re-Identification by Camera Correlation Aware Feature Augmentation.基于相机关联感知特征增强的行人再识别。
IEEE Trans Pattern Anal Mach Intell. 2018 Feb;40(2):392-408. doi: 10.1109/TPAMI.2017.2666805. Epub 2017 Feb 9.
7
Defending Person Detection Against Adversarial Patch Attack by Using Universal Defensive Frame.利用通用防御框架防御对抗性补丁攻击的人像检测。
IEEE Trans Image Process. 2022;31:6976-6990. doi: 10.1109/TIP.2022.3217375. Epub 2022 Nov 14.
8
Improving Adversarial Robustness via Attention and Adversarial Logit Pairing.通过注意力机制和对抗性逻辑对配对提高对抗鲁棒性
Front Artif Intell. 2022 Jan 27;4:752831. doi: 10.3389/frai.2021.752831. eCollection 2021.
9
Interactive attack-defense for generalized person re-identification.交互式攻击防御的广义人像再识别。
Neural Netw. 2024 Aug;176:106349. doi: 10.1016/j.neunet.2024.106349. Epub 2024 May 3.
10
Adversarial Robustness of Deep Reinforcement Learning Based Dynamic Recommender Systems.基于深度强化学习的动态推荐系统的对抗鲁棒性
Front Big Data. 2022 May 3;5:822783. doi: 10.3389/fdata.2022.822783. eCollection 2022.