Learning to Attack Real-World Models for Person Re-identification via Virtual-Guided Meta-Learning
Fengxiang Yang, Zhun Zhong, Hong Liu, Zheng Wang, Zhiming Luo, Shaozi Li, Nicu Sebe, Shin'ichi Satoh
Abstract
Recent advances in person re-identification (re-ID) have led to impressive retrieval accuracy. However, existing re-ID models are challenged by the adversarial examples crafted by adding quasi-imperceptible perturbations. Moreover, re-ID systems face the domain shift issue that training and testing domains are not consistent. In this study, we argue that learning powerful attackers with high universality that works well on unseen domains is an important step in promoting the robustness of re-ID systems. Therefore, we introduce a novel universal attack algorithm called ``MetaAttack'' for person re-ID. MetaAttack can mislead re-ID models on unseen domains by a universal adversarial perturbation. Specifically, to capture common patterns across different domains, we propose a meta-learning scheme to seek the universal perturbation via the gradient interaction between meta-train and meta-test formed by two datasets. We also take advantage of a virtual dataset (PersonX), instead of real ones, to conduct meta-test. This scheme not only enables us to learn with more comprehensive variation factors but also mitigates the negative effects caused by biased factors of real datasets. Experiments on three large-scale re-ID datasets demonstrate the effectiveness of our method in attacking re-ID models on unseen domains. Our final visualization results reveal some new properties of existing re-ID systems, which can guide us in designing a more robust re-ID model. Code and supplemental material are available at https://github.com/FlyingRoastDuck/MetaAttack_AAAI21.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- PUMA: Performance Unchanged Model Augmentation for Training Data RemovalGa Wu, Masoud Hashemi, Christopher SrinivasaAAAI 2022 · 96 citations
- REMOTE: Reinforced Motion Transformation Network for Semi-supervised 2D Pose Estimation in VideosXianzheng Ma, Hossein Rahmani, Zhipeng Fan, Bin Yang et al.AAAI 2022 · 10 citations
- Feature-Level Adversarial Attacks and Ranking Disruption for Visible-Infrared Person Re-identificationXi Yang, Huanling Liu, De Cheng, Nannan Wang et al.NeurIPS 2024 · 6 citations
- Prompt-Driven Transferable Adversarial Attack on Person Re-identification with Attribute-Aware Textual InversionYuan Bian, Min Liu, Yunqi Yi, Xueping Wang et al.ICCV 2025 · 3 citations
- SANER: Switchable Adapter with Non-parametric Enhanced Routing for Person De-ReidentificationYimin Liu, Nan Pu, Fengxiang Yang, Wenjing Li et al.CVPR 2026
Builds on5
- Random Erasing Data AugmentationZhun Zhong, Liang Zheng, Guoliang Kang, Shaozi Li et al.AAAI 2020 · 4,134 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
- Targeted Mismatch Adversarial Attack: Query With a Flower to Retrieve the TowerGiorgos Tolias, Filip Radenovic, Ondrej ChumICCV 2019 · 76 citations
- Transferable, Controllable, and Inconspicuous Adversarial Attacks on Person Re-identification With Deep Mis-RankingHongjun Wang, Guangrun Wang, Ya Li, Dongyu Zhang et al.CVPR 2020
- Learning Meta Face Recognition in Unseen DomainsJianzhu Guo, Xiangyu Zhu, Chenxu Zhao, Dong Cao et al.CVPR 2020
Related papers
- advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable PatternsZhibo Wang, Siyan Zheng, Mengkai Song, Qian Wang et al.ICCV 2019 · 69 citations
- Debiased Dual-Invariant Defense for Adversarially Robust Person Re-IdentificationYuhang Zhou, Yanxiang Zhao, Zhongyun Hua, Zhipu Liu et al.AAAI 2026
- Learning to Generalize Unseen Domains via Memory-based Multi-Source Meta-Learning for Person Re-IdentificationYuyang Zhao, Zhun Zhong, Fengxiang Yang, Zhiming Luo et al.CVPR 2021
- Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalLong Tang, Dengpan Ye, Yunna Lv, Chuanxi Chen et al.AAAI 2024 · 13 citations
- Meta Distribution Alignment for Generalizable Person Re-IdentificationHao Ni, Jingkuan Song, Xiaopeng Luo, Feng Zheng et al.CVPR 2022 · 77 citations
