Multi-Expert Adversarial Attack Detection in Person Re-identification Using Context Inconsistency
Xueping Wang, Shasha Li, Min Liu, Yaonan Wang, Amit K. Roy-Chowdhury
Abstract
The success of deep neural networks (DNNs) has promoted the widespread applications of person re-identification (ReID). However, ReID systems inherit the vulnerability of DNNs to malicious attacks of visually in-conspicuous adversarial perturbations. Detection of adversarial attacks is, therefore, a fundamental requirement for robust ReID systems. In this work, we propose a Multi-Expert Adversarial Attack Detection (MEAAD) approach to achieve this goal by checking context inconsistency, which is suitable for any DNN-based ReID systems. Specifically, three kinds of context inconsistencies caused by adversarial attacks are employed to learn a detector for distinguishing the perturbed examples, i.e., a) the embedding distances between a perturbed query person image and its top-K retrievals are generally larger than those between a benign query image and its top-K retrievals, b) the embedding distances among the top-K retrievals of a perturbed query image are larger than those of a benign query image, c) the top-K retrievals of a benign query image obtained with multiple expert ReID models tend to be consistent, which is not preserved when attacks are present. Extensive experiments on the Market1501 and DukeMTMC-ReID datasets show that, as the first adversarial attack detection approach for ReID, MEAAD effectively detects various adversarial attacks and achieves high ROC-AUC (over 97.5%).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 58593bd6-e476-4a76-a9b8-9a4e091eab51Cited by top-tier papers5
- Adversarial Attacks on Black Box Video Classifiers: Leveraging the Power of Geometric TransformationsShasha Li, Abhishek Aich, Shitong Zhu, M. Salman Asif et al.NeurIPS 2021 · 50 citations
- VisionGuard: Secure and Robust Visual Perception of Autonomous Vehicles in PracticeXingshuo Han, Haozhao Wang, Kangqiao Zhao, Gelei Deng et al.CCS 2024 · 3 citations
- HAMoBE: Hierarchical and Adaptive Mixture of Biometric Experts for Video-Based Person ReIDYiyang Su, Yunping Shi, Feng Liu, Xiaoming LiuICCV 2025 · 1 citation
- That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal ConsistencyYanmao Man, Raymond Muller, Ming Li, Z. Berkay Celik et al.USENIX Security 2023
- Event-Guided Person Re-Identification via Sparse-Dense Complementary LearningChengzhi Cao, Xueyang Fu, Hongjian Liu, Yukun Huang et al.CVPR 2023
Builds on7
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Seeing isn't Believing: Towards More Robust Adversarial Attack Against Real World Object DetectorsYue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen et al.CCS 2019 · 239 citations
- Targeted Mismatch Adversarial Attack: Query With a Flower to Retrieve the TowerGiorgos Tolias, Filip Radenovic, Ondrej ChumICCV 2019 · 76 citations
- Exploiting Multi-Object Relationships for Detecting Adversarial Attacks in Complex ScenesMingjun Yin, Shasha Li, Zikui Cai, Chengyu Song et al.ICCV 2021 · 25 citations
- DeepTrack: Grouping RFID Tags Based on Spatio-temporal Proximity in Retail SpacesShasha Li, Mustafa Y. Arslan, Amir Khojastepour, Srikanth V. Krishnamurthy et al.INFOCOM 2020 · 4 citations
Related papers
- Transferable, Controllable, and Inconspicuous Adversarial Attacks on Person Re-identification With Deep Mis-RankingHongjun Wang, Guangrun Wang, Ya Li, Dongyu Zhang et al.CVPR 2020
- advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable PatternsZhibo Wang, Siyan Zheng, Mengkai Song, Qian Wang et al.ICCV 2019 · 69 citations
- Detecting Adversarial Examples from Sensitivity Inconsistency of Spatial-Transform DomainJinyu Tian, Jiantao Zhou, Yuanman Li, Jia DuanAAAI 2021 · 72 citations
- Learning to Attack Real-World Models for Person Re-identification via Virtual-Guided Meta-LearningFengxiang Yang, Zhun Zhong, Hong Liu, Zheng Wang et al.AAAI 2021 · 23 citations
- NIC: Detecting Adversarial Samples with Neural Network Invariant CheckingShiqing Ma, Yingqi Liu, Guanhong Tao, Wen-Chuan Lee et al.NDSS 2019 · 283 citations
