Towards Robust Person Re-identification by Defending Against Universal Attackers

Towards Robust Person Re-identification by Defending Against Universal Attackers
复制标题

通过防御通用攻击者实现稳健的人员重新识别

DOI:
10.1109/tpami.2022.3199013
复制
发表时间:
2023
影响因子:
23.6
通讯作者:
Nicu Sebe
Nicu Sebe
中科院分区:
计算机科学1区
文献类型:
--
作者:
Fengxiang Yang;Juanjuan Weng;Zhun Zhong;Hong Liu;Zheng Wang;Zhiming Luo;Donglin Cao;Shaozi Li;Shin'ichi Satoh;Nicu Sebe

文献摘要

相似文献

最近的研究表明,深度人重新识别(re-ID)模型容易受到对抗性样本的攻击,因此提高re-ID模型对攻击的鲁棒性至关重要。为了实现这一目标,我们探索了现有re-ID模型的优点和缺点,即,设计基于学习的攻击,并通过防御学习的攻击来训练鲁棒模型。本文的贡献是三方面的:首先,我们建立了一个整体的攻击-防御框架,研究攻击和防御之间的关系的人re-ID。其次,我们介绍了一种组合对抗攻击,是自适应的看不见的领域和看不见的模型类型。它包括像素和颜色空间中的失真(即,模仿照相机移位)。第三,我们提出了一种新的虚拟引导元学习算法,我们的攻击防御系统。我们利用虚拟数据集在我们的元学习框架下进行实验,可以探索跨域约束,以增强攻击的泛化能力和re-ID模型的鲁棒性。在三个大规模re-ID基准测试上的综合实验表明:1)我们的组合攻击是有效的,并且在跨模型和跨数据集的场景中具有高度的通用性; 2)我们的元学习算法可以很容易地应用于不同的攻击和防御方法,可以达到一致的改进; 3)在学习到学习框架上训练的防御模型对最近的SOTA攻击具有鲁棒性,这些攻击甚至在训练期间都没有使用。
Recent studies show that deep person re-identification (re-ID) models are vulnerable to adversarial examples, so it is critical to improving the robustness of re-ID models against attacks. To achieve this goal, we explore the strengths and weaknesses of existing re-ID models, i.e., designing learning-based attacks and training robust models by defending against the learned attacks. The contributions of this paper are three-fold: First, we build a holistic attack-defense framework to study the relationship between the attack and defense for person re-ID. Second, we introduce a combinatorial adversarial attack that is adaptive to unseen domains and unseen model types. It consists of distortions in pixel and color space (i.e., mimicking camera shifts). Third, we propose a novel virtual-guided meta-learning algorithm for our attack-defense system. We leverage a virtual dataset to conduct experiments under our meta-learning framework, which can explore the cross-domain constraints for enhancing the generalization of the attack and the robustness of the re-ID model. Comprehensive experiments on three large-scale re-ID benchmarks demonstrate that: 1) Our combinatorial attack is effective and highly universal in cross-model and cross-dataset scenarios; 2) Our meta-learning algorithm can be readily applied to different attack and defense approaches, which can reach consistent improvement; 3) The defense model trained on the learning-to-learn framework is robust to recent SOTA attacks that are not even used during training.