Occlusion Resilient Adversarial Attack for Person Re-identification

Xinyu Wang, Xiaolong Zheng, Peilun Du, Liang Liu, Huadóng Ma · 2021

Deep learning-based person re-identification (Re-ID) methods have achieved the significant performance of matching person images across camera views, which plays an important role in the construction of the smart city. Recent works of adversarial attacks have explored the serious vulnerability of deep Re-ID systems. However, existing attacks are performed with idealized conditions and ignore the real-world environments, such as occlusion caused by walking habits. In this paper, we propose a two-stage method to perform an occlusion resilient adversarial attack for better evaluation of deep Re-ID systems. Specifically, we construct the occlusion template from the observation and statics of pedestrian walking habits. Then, we design a partition training strategy for a better combination of occluded and exposed adversarial patches. During the training, we introduce contextual loss to penalize the semantic distance of attacked images with the same identity. The extensive experiments on Market1501 demonstrate the performance of our method.

Read the paper · More papers on PaperTik