Attack is the Best Defense: Towards Preemptive-Protection Person Re-Identification
Lin Wang, Wanqian Zhang, Dayan Wu, Fei Zhu, Bo Li
Abstract
Person Re-IDentification (ReID) aims at retrieving images of the same person across multiple camera views. Despite its popularity in surveillance and public safety, the leakage of identity information is still at risk. For example, once obtaining the illegal access to ReID systems, malicious user can accurately retrieve the target person, leading to the exposure of private information. Recently, some pioneering works protect private images with adversarial examples by adding imperceptible perturbations to target images. However, in this paper, we argue that directly applying adversary-based methods to protect the ReID system is sub-optimal due to the 'overlap identity' issue. Specifically, merely pushing the adversarial image away from its original label would probably make it move into the vicinity of other identities. This leads to the potential risk of being retrieved when querying with all the other identities exhaustively. We thus propose a novel preemptive-Protection person Re-IDentification (PRIDE) method. By explicitly constraining the adversarial image to an isolated location, the target person is far away from neither the original identity nor any other identities, which protects him from being retrieved by illegal queries. Moreover, we further propose two crucial attack scenarios (Random Attack and Order Attack) and a novel Success Protection Rate (SPR) metric to quantify the protection ability. Experiments show consistent outperformance of our method over other baselines across different ReID models, datasets and attack scenarios.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bfd6faa4-b213-4096-8236-714ad7ecd3afCited by top-tier papers2
- A Pedestrian is Worth One Prompt: Towards Language Guidance Person Re- IdentificationZexian Yang, Dayan Wu, Chenming Wu, Zheng Lin et al.CVPR 2024 · 26 citations
- Person De-reidentification: A Variation-guided Identity Shift ModelingYi-Xing Peng, Yu-Ming Tang, Kun-Yu Lin, Qize Yang et al.CVPR 2025
Related papers
- advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable PatternsZhibo Wang, Siyan Zheng, Mengkai Song, Qian Wang et al.ICCV 2019 · 69 citations
- Transferable, Controllable, and Inconspicuous Adversarial Attacks on Person Re-identification With Deep Mis-RankingHongjun Wang, Guangrun Wang, Ya Li, Dongyu Zhang et al.CVPR 2020
- PixelFade: Privacy-preserving Person Re-identification with Noise-guided Progressive ReplacementDelong Zhang, Yi-Xing Peng, Xiao-Ming Wu, Ancong Wu et al.ACM MM 2024 · 4 citations
- Multi-Expert Adversarial Attack Detection in Person Re-identification Using Context InconsistencyXueping Wang, Shasha Li, Min Liu, Yaonan Wang et al.ICCV 2021 · 34 citations
- Disentangling Identity Features from Interference Factors for Cloth-Changing Person Re-identificationYubo Li, De Cheng, Chaowei Fang, Changzhe Jiao et al.ACM MM 2024 · 7 citations
