arXiv:2511.09933cs.CV2025-11中稿 · AAAI

提出新防御框架,提升行人重识别在对抗攻击下的鲁棒性。

Debiased Dual-Invariant Defense for Adversarially Robust Person Re-Identification

论文配图:Debiased Dual-Invariant Defense for Adversarially Robust Person Re-Identification
图 1 · 摘自论文原文
  • 用扩散模型重采样数据,缓解模型偏差
  • 双对抗自元学习机制,提升对未知身份和攻击的泛化能力
  • 在多个数据集上显著优于现有防御方法

行人重识别(ReID)是轨迹追踪等实际应用中的关键任务。然而,基于深度学习的ReID模型极易受到对抗攻击——微小扰动即可导致错误匹配,带来严重安全风险。尽管已有大量分类任务的防御方法,但其在度量学习类任务如ReID中的应用仍不充分。现有方法未能解决对抗鲁棒性ReID的独特挑战。本文系统分析出两大核心问题:模型偏差与复合泛化需求。为此,提出去偏双不变防御框架,包含两阶段:第一阶段采用基于扩散模型的数据重采样策略,提升训练数据公平性与多样性;第二阶段引入新颖的度量对抗训练方法,结合最远负样本扩展软化机制,克服无分类器导致的鲁棒性下降,并设计对抗增强的自元学习机制,实现对未见身份与未见攻击类型的双重泛化。实验表明,该方法显著优于现有最先进的防御方案。

原文摘要 · Abstract (English)

Person re-identification (ReID) is a fundamental task in many real-world applications such as pedestrian trajectory tracking. However, advanced deep learning-based ReID models are highly susceptible to adversarial attacks, where imperceptible perturbations to pedestrian images can cause entirely incorrect predictions, posing significant security threats. Although numerous adversarial defense strategies have been proposed for classification tasks, their extension to metric learning tasks such as person ReID remains relatively unexplored. Moreover, the several existing defenses for person ReID fail to address the inherent unique challenges of adversarially robust ReID. In this paper, we systematically identify the challenges of adversarial defense in person ReID into two key issues: model bias and composite generalization requirements. To address them, we propose a debiased dual-invariant defense framework composed of two main phases. In the data balancing phase, we mitigate model bias using a diffusion-model-based data resampling strategy that promotes fairness and diversity in training data. In the bi-adversarial self-meta defense phase, we introduce a novel metric adversarial training approach incorporating farthest negative extension softening to overcome the robustness degradation caused by the absence of classifier. Additionally, we introduce an adversarially-enhanced self-meta mechanism to achieve dual-generalization for both unseen identities and unseen attack types. Experiments demonstrate that our method significantly outperforms existing state-of-the-art defenses.

行人重识别对抗防御度量学习扩散模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。