advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable Patterns
Zhibo Wang, Siyan Zheng, Mengkai Song, Qian Wang, Alireza Rahimpour, Hairong Qi
Abstract
Person re-identification (re-ID) is the task of matching person images across camera views, which plays an important role in surveillance and security applications. Inspired by great progress of deep learning, deep re-ID models began to be popular and gained state-of-the-art performance. However, recent works found that deep neural networks (DNNs) are vulnerable to adversarial examples, posing potential threats to DNNs based applications. This phenomenon throws a serious question about whether deep re-ID based systems are vulnerable to adversarial attacks. In this paper, we take the first attempt to implement robust physical-world attacks against deep re-ID. We propose a novel attack algorithm, called advPattern, for generating adversarial patterns on clothes, which learns the variations of image pairs across cameras to pull closer the image features from the same camera, while pushing features from different cameras farther. By wearing our crafted “invisible cloak”, an adversary can evade person search, or impersonate a target person to fool deep re-ID models in physical world. We evaluate the effectiveness of our transformable patterns on adversaries’ clothes with Market1501 and our established PRCS dataset. The experimental results show that the rank-1 accuracy of re-ID models for matching the adversary decreases from 87.9% to 27.1% under Evading Attack. Furthermore, the adversary can impersonate a target person with 47.1% rank-1 accuracy and 67.9% mAP under Impersonation Attack. The results demonstrate that deep re-ID systems are vulnerable to our physical attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 553af021-cb0a-411f-bd8d-5ebf22edafc1Cited by top-tier papers3
- Enhancing Adversarial Robustness for Deep Metric LearningMo Zhou, Vishal M. PatelCVPR 2022 · 17 citations
- Full-Distance Evasion of Pedestrian Detectors in the Physical WorldZhi Cheng, Zhanhao Hu, Yuqiu Liu, Jianmin Li et al.NeurIPS 2024 · 6 citations
- Debiased Dual-Invariant Defense for Adversarially Robust Person Re-IdentificationYuhang Zhou, Yanxiang Zhao, Zhongyun Hua, Zhipu Liu et al.AAAI 2026
Builds on2
Related papers
- Learning to Attack Real-World Models for Person Re-identification via Virtual-Guided Meta-LearningFengxiang Yang, Zhun Zhong, Hong Liu, Zheng Wang et al.AAAI 2021 · 23 citations
- Adversarial Camouflage: Hiding Physical-World Attacks With Natural StylesRanjie Duan, Xingjun Ma, Yisen Wang, James Bailey et al.CVPR 2020
- Disentangling Identity Features from Interference Factors for Cloth-Changing Person Re-identificationYubo Li, De Cheng, Chaowei Fang, Changzhe Jiao et al.ACM MM 2024 · 7 citations
- Transferable, Controllable, and Inconspicuous Adversarial Attacks on Person Re-identification With Deep Mis-RankingHongjun Wang, Guangrun Wang, Ya Li, Dongyu Zhang et al.CVPR 2020
- Adversarial Texture for Fooling Person Detectors in the Physical WorldZhanhao Hu, Siyuan Huang, Xiaopei Zhu, Fuchun Sun et al.CVPR 2022 · 125 citations
