Feature-Level Adversarial Attacks and Ranking Disruption for Visible-Infrared Person Re-identification
Xi Yang, Huanling Liu, De Cheng, Nannan Wang, Xinbo Gao
摘要
Visible-infrared person re-identification (VIReID) is widely used in fields such as video surveillance and intelligent transportation, imposing higher demands on model security. In practice, the adversarial attacks based on VIReID aim to disrupt output ranking and quantify the security risks of models. Although numerous studies have been emerged on adversarial attacks and defenses in fields such as face recognition, person re-identification, and pedestrian detection, there is currently a lack of research on the security of VIReID systems. To this end, we propose to explore the vulnerabilities of VIReID systems and prevent potential serious losses due to insecurity. Compared to research on single-modality ReID, adversarial feature alignment and modality differences need to be particularly emphasized. Thus, we advocate for feature-level adversarial attacks to disrupt the output rankings of VIReID systems. To obtain adversarial features, we introduce Universal Adversarial Perturbations (UAP) to simulate common disturbances in real-world environments. Additionally, we employ a Frequency-Spatial Attention Module (FSAM), integrating frequency information extraction and spatial focusing mechanisms, and further emphasize important regional features from different domains on the shared features. This ensures that adversarial features maintain consistency within the feature space. Finally, we employ an Auxiliary Quadruple Adversarial Loss to amplify the differences between modalities, thereby improving the distinction and recognition of features between visible and infrared images, which cause the system to output incorrect rankings. Extensive experiments on two VIReID benchmarks (i.e., SYSU-MM01, RegDB) and different systems validate the effectiveness of our method.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper17
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Channel Augmented Joint Learning for Visible-Infrared RecognitionMang Ye, Weijian Ruan, Bo Du, Mike Zheng ShouICCV 2021 · 被引用 310 次
- Towards a Unified Middle Modality Learning for Visible-Infrared Person Re-IdentificationYukang Zhang, Yan Yan, Yang Lu, Hanzi WangACM MM 2021 · 被引用 219 次
- CM-NAS: Cross-Modality Neural Architecture Search for Visible-Infrared Person Re-IdentificationChaoyou Fu, Yibo Hu, Xiang Wu, Hailin Shi 等ICCV 2021 · 被引用 150 次
- Universal Perturbation Attack Against Image RetrievalJie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong 等ICCV 2019 · 被引用 115 次
相关 Paper
- Cross-Modality Perturbation Synergy Attack for Person Re-identificationYunpeng Gong, Zhun Zhong, Yansong Qu, Zhiming Luo 等NeurIPS 2024 · 被引用 67 次
- Video-based Visible-Infrared Person Re-Identification via Style Disturbance Defense and Dual InteractionChuhao Zhou, Jinxing Li, Huafeng Li, Guangming Lu 等ACM MM 2023 · 被引用 23 次
- FA3T: Feature-Aware Adversarial Attacks for Multi-modal TrackingJiahao Wang, Fang Liu, Licheng Jiao, Hao Wang 等ACM MM 2025
- Co-Attentive Lifting for Infrared-Visible Person Re-IdentificationXing Wei, Diangang Li, Xiaopeng Hong, Wei Ke 等ACM MM 2020 · 被引用 61 次
- Keypoint-Guided Modality-Invariant Discriminative Learning for Visible-Infrared Person Re-identificationTengfei Liang, Yi Jin, Wu Liu, Songhe Feng 等ACM MM 2022 · 被引用 19 次
