节点文献

多尺度梯度对抗样本生成网络

Multi-scale Gradient Adversarial Examples Generation Network

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 石磊张晓涵洪晓鹏李吉亮丁文杰沈超

【Author】 SHI Lei;ZHANG Xiaohan;HONG Xiaopeng;LI Jiliang;DING Wenjie;SHEN Chao;School of Cyber Science and Engineering,Xi’an Jiaotong University;Faculty of Computing,Harbin Institute of Technology;Beijing Megvii Technology Co.,Ltd.;

【通讯作者】 洪晓鹏;

【机构】 西安交通大学网络空间安全学院哈尔滨工业大学计算学部北京旷视科技有限公司

【摘要】 传统的行人重识别(Person Re-identification, ReID)对抗攻击方法存在需要依赖注册集(Gallery)以生成对抗样本或样本生成方式过于单一等局限.为了解决此问题,文中提出具有强攻击性的ReID对抗攻击模型,即多尺度梯度对抗样本生成网络(Multi-scale Gradient Adversarial Examples Generation Network, MSG-AEGN).MSG-AEGN采用多尺度的网络结构,获得不同语义级别的原始样本输入和生成器中间特征.利用注意力调制模块将生成器中间特征转换成多尺度权重,从而对原始样本像素进行调制,最终输出高质量的对抗样本以迷惑ReID模型.在此基础上,提出基于图像特征平均距离和三元组损失的改进型对抗损失函数,约束和引导MSG-AEGN的训练.在Market1501、CUHK03、DukeMTMC-reID这3个行人重识别数据集上的实验表明,MSG-AEGN对基于深度卷积神经网络和基于变形器网络(Transformer)的主流Re-ID方法均具有较好的攻击效果.此外,MSG-AEGN具有所需攻击能量较低且对抗样本与原始图像的结构相似度较高的优点.

【Abstract】 Traditional person re-identification( ReID) adversarial attack methods hold some limitations,such as the dependence on the registry( Gallery) to generate adversarial examples and too single examples generation method. To address these problems,an efficient ReID adversarial attack model,multi-scale gradient adversarial examples generation network( MSG-AEGN),is put forward.MSG-AEGN is based on the multi-scale gradient adversarial networks. A multi-scale network structure is adopted to obtain different semantic levels of the input images and the intermediate features of the generator. An attention module is adopted to convert the intermediate features of the generator into multiscale weights,thereby modulating the image pixels. Finally,the network outputs high-quality adversarial examples to confuse the ReID models. On this basis,an improved adversarial loss function based on the average distance of image features and the triplet loss is proposed to constrain and guide the training of MSG-AEGN. Experiments on three pedestrian ReID datasets,namely Market1501,CUHK03 and DukeMTMC-ReID,show that the proposed method produces promising attack effects on both the mainstream Re-ID models based on deep convolutional neural networks and the transformer networks. Moreover,MSG-AEGN possesses the advantages of low required attack energy and high structural similarity between adversarial samples and original images.

【基金】 国家重点研发计划项目(No.2019YFB1312000);国家自然科学基金项目(No.62076195)资助~~
  • 【文献出处】 模式识别与人工智能 ,Pattern Recognition and Artificial Intelligence , 编辑部邮箱 ,2022年06期
  • 【分类号】TP391.41;TP183
  • 【下载频次】162
节点文献中: 

本文链接的文献网络图示:

本文的引文网络