对抗制
稳健性(进化)
计算机科学
一般化
模型攻击
机器学习
光学(聚焦)
人工智能
训练集
行人
直觉
对手
利用
威胁模型
特征向量
数据建模
模式识别(心理学)
特征(语言学)
攻击模式
作者
Tongzhen Si,Penglei Li,Xiaohui Yang,Fazhi He,Zhiquan Feng,Tao Xu
标识
DOI:10.1109/tii.2025.3610202
摘要
Person reidentification (ReID) could locate target pedestrians from different cameras. However, ReID models are very vulnerable to adversarial samples with quasi-imperceptible perturbations. Hence, studying adversarial attack methods could promote the robustness of person ReID. Existing adversarial attack methods mainly focus on attacking the specific model under specific scenes and obtain poor generalization results. In this study, we propose a novel universal attack via model-guided meta-learning method (UAMM), which could attack different models and other unseen data sources. Specifically, multiple ReID models are extended to extract various pedestrian features from adversarial samples (with perturbation). Then, we develop the meta-learning loss to obtain the feature distribution discrepancy and compute the gradient to update the perturbation for destroying the feature distribution. Afterwards, the model-guided meta-learning strategy is designed to aggregate different gradients and effectively adjusts the gradient update direction for generating a universal perturbation. Under the attack of the learned perturbation, the intraclass distance is larger than that of the interclass distance, resulting in poor recognition of ReID models. Abundant experiments demonstrate that the proposed UAMM generates universal perturbation that possesses the ability to attack different models under various scenes. A large number of experimental data show that our attack method is meaningful and superior to other methods.
科研通智能强力驱动
Strongly Powered by AbleSci AI