返回
Beyond Universal Person Re-Identification Attack
DOI:10.1109/TIFS.2021.3081247.png)
摘要
En 中文
Deep learning-based person re-identification (Re-ID) has made great progress and achieved high performance recently. In this paper, we make the first attempt to examine the vulnerability of current person Re-ID models against a dangerous attack method, i.e., the universal adversarial perturbation (UAP) attack, which has been shown to fool classification models with a little overhead. We propose a more universal adversarial perturbation (MUAP) method for both image-agnostic and model-insensitive person Re-ID attack. Firstly, we adopt a list-wise attack objective function to disrupt the similarity ranking list directly. Secondly, we propose a model-insensitive mechanism for cross-model attack. Extensive experiments show that the proposed attack approach achieves high attack performance and outperforms other state of the arts by large margin in cross-model scenario. The results also demonstrate the vulnerability of current Re-ID models to MUAP and further suggest the need of designing more robust Re-ID models.
Keyword:
Perturbation methods
Task analysis
Computational modeling
Electronic mail
Neural networks
Linear programming
Training
Universal adversarial perturbation
cross-model attack
list-wise attack
person Re-ID
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
8
论文数:
5.2K
被引数:
2.3W
机构
引用论文
Deep learning models for electrocardiograms are susceptible to adversarial attack心电图的深度学习模型易受对抗性攻击
NATURE MEDICINE
IF50

