Feature-Level Adversarial Attacks and Ranking Disruption for Visible-Infrared Person Re-identification
Xi Yang, Huanling Liu, De Cheng, Nannan Wang, Xinbo Gao
Abstract
Visible-infrared person re-identification (VIReID) is widely used in fields such as video surveillance and intelligent transportation, imposing higher demands on model security. In practice, the adversarial attacks based on VIReID aim to disrupt output ranking and quantify the security risks of models. Although numerous studies have been emerged on adversarial attacks and defenses in fields such as face recognition, person re-identification, and pedestrian detection, there is currently a lack of research on the security of VIReID systems. To this end, we propose to explore the vulnerabilities of VIReID systems and prevent potential serious losses due to insecurity. Compared to research on single-modality ReID, adversarial feature alignment and modality differences need to be particularly emphasized. Thus, we advocate for feature-level adversarial attacks to disrupt the output rankings of VIReID systems. To obtain adversarial features, we introduce Universal Adversarial Perturbations (UAP) to simulate common disturbances in real-world environments. Additionally, we employ a Frequency-Spatial Attention Module (FSAM), integrating frequency information extraction and spatial focusing mechanisms, and further emphasize important regional features from different domains on the shared features. This ensures that adversarial features maintain consistency within the feature space. Finally, we employ an Auxiliary Quadruple Adversarial Loss to amplify the differences between modalities, thereby improving the distinction and recognition of features between visible and infrared images, which cause the system to output incorrect rankings. Extensive experiments on two VIReID benchmarks (i.e., SYSU-MM01, RegDB) and different systems validate the effectiveness of our method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 72e8a594-ce67-416e-828f-bc58d0478e67Builds on17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Channel Augmented Joint Learning for Visible-Infrared RecognitionMang Ye, Weijian Ruan, Bo Du, Mike Zheng ShouICCV 2021 · 310 citations
- Towards a Unified Middle Modality Learning for Visible-Infrared Person Re-IdentificationYukang Zhang, Yan Yan, Yang Lu, Hanzi WangACM MM 2021 · 219 citations
- CM-NAS: Cross-Modality Neural Architecture Search for Visible-Infrared Person Re-IdentificationChaoyou Fu, Yibo Hu, Xiang Wu, Hailin Shi et al.ICCV 2021 · 150 citations
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong et al.ICCV 2019 · 115 citations
Related papers
- Cross-Modality Perturbation Synergy Attack for Person Re-identificationYunpeng Gong, Zhun Zhong, Yansong Qu, Zhiming Luo et al.NeurIPS 2024 · 67 citations
- Video-based Visible-Infrared Person Re-Identification via Style Disturbance Defense and Dual InteractionChuhao Zhou, Jinxing Li, Huafeng Li, Guangming Lu et al.ACM MM 2023 · 23 citations
- FA3T: Feature-Aware Adversarial Attacks for Multi-modal TrackingJiahao Wang, Fang Liu, Licheng Jiao, Hao Wang et al.ACM MM 2025
- Co-Attentive Lifting for Infrared-Visible Person Re-IdentificationXing Wei, Diangang Li, Xiaopeng Hong, Wei Ke et al.ACM MM 2020 · 61 citations
- Keypoint-Guided Modality-Invariant Discriminative Learning for Visible-Infrared Person Re-identificationTengfei Liang, Yi Jin, Wu Liu, Songhe Feng et al.ACM MM 2022 · 19 citations
