Learning to Attack Real-World Models for Person Re-identification via Virtual-Guided Meta-Learning

Learning to Attack Real-World Models for Person Re-identification via Virtual-Guided Meta-Learning
复制标题

DOI:
10.1609/aaai.v35i4.16422
复制
发表时间:
2021-05
期刊:
--
影响因子:
--
通讯作者:
Fengxiang Yang;Zhun Zhong;Hong Liu;Z. Wang;Zhiming Luo;Shaozi Li;N. Sebe;S. Satoh
Fengxiang Yang;Zhun Zhong;Hong Liu;Z. Wang;Zhiming Luo;Shaozi Li;N. Sebe;S. Satoh
中科院分区:
其他
文献类型:
--
作者:
Fengxiang Yang;Zhun Zhong;Hong Liu;Z. Wang;Zhiming Luo;Shaozi Li;N. Sebe;S. Satoh

文献摘要

相似文献

最近在人员重新识别(Re-ID)方面的进展导致了令人印象深刻的检索准确率。然而,现有的Re-ID模型受到了通过添加准不可察觉扰动而形成的对抗性例子的挑战。此外,Re-ID系统还面临着训练领域和测试领域不一致的领域转移问题。在这项研究中,我们认为学习在看不见的域上工作得很好的具有高度普适性的强大攻击者是提高re-ID系统健壮性的重要一步。为此,我们提出了一种新的针对Person Re-ID的通用攻击算法“MetaAttack”。MetaAttack可以通过普遍的对抗性扰动在看不见的域上误导re-ID模型。具体地说,为了捕捉不同领域的公共模式,我们提出了一种元学习方案,通过两个数据集形成的元训练和元测试之间的梯度交互来寻求普遍的扰动。我们还利用虚拟数据集(PersonX)而不是真实数据集来进行元测试。该方案不仅使我们能够以更全面的变异因素进行学习,而且还可以减轻真实数据集的偏差因素所带来的负面影响。在三个大规模Re-ID数据集上的实验表明,该方法在攻击不可见区域上的Re-ID模型方面是有效的。我们最终的可视化结果揭示了现有Re-ID系统的一些新的性质,这可以指导我们设计更健壮的Re-ID模型。有关代码和补充材料,请访问\url{https://github.com/FlyingRoastDuck/MetaAttack_AAAI21}.
Recent advances in person re-identification (re-ID) have led to impressive retrieval accuracy. However, existing re-ID models are challenged by the adversarial examples crafted by adding quasi-imperceptible perturbations. Moreover, re-ID systems face the domain shift issue that training and testing domains are not consistent. In this study, we argue that learning powerful attackers with high universality that works well on unseen domains is an important step in promoting the robustness of re-ID systems. Therefore, we introduce a novel universal attack algorithm called ``MetaAttack'' for person re-ID. MetaAttack can mislead re-ID models on unseen domains by a universal adversarial perturbation. Specifically, to capture common patterns across different domains, we propose a meta-learning scheme to seek the universal perturbation via the gradient interaction between meta-train and meta-test formed by two datasets. We also take advantage of a virtual dataset (PersonX), instead of real ones, to conduct meta-test. This scheme not only enables us to learn with more comprehensive variation factors but also mitigates the negative effects caused by biased factors of real datasets. Experiments on three large-scale re-ID datasets demonstrate the effectiveness of our method in attacking re-ID models on unseen domains. Our final visualization results reveal some new properties of existing re-ID systems, which can guide us in designing a more robust re-ID model. Code and supplemental material are available at \url{https://github.com/FlyingRoastDuck/MetaAttack_AAAI21}.