模式识别与人工智能
Friday, Apr. 11, 2025 Home      About Journal      Editorial Board      Instructions      Ethics Statement      Contact Us                   中文
Pattern Recognition and Artificial Intelligence  2022, Vol. 35 Issue (6): 483-496    DOI: 10.16451/j.cnki.issn1003-6059.202206001
Deep Learning Based Object Detection and Recognition Current Issue| Next Issue| Archive| Adv Search |
Multi-scale Gradient Adversarial Examples Generation Network
SHI Lei1, ZHANG Xiaohan1, HONG Xiaopeng1,2, LI Jiliang1, DING Wenjie3, SHEN Chao1
1. School of Cyber Science and Engineering, Xi'an Jiaotong University, Xi'an 710049;
2. Faculty of Computing, Harbin Institute of Technology, Harbin 150001;
3. Beijing Megvii Technology Co., Ltd., Beijing 100080

Download: PDF (2839 KB)   HTML (1 KB) 
Export: BibTeX | EndNote (RIS)      
Abstract  Traditional person re-identification(ReID) adversarial attack methods hold some limitations, such as the dependence on the registry(Gallery) to generate adversarial examples and too single examples generation method . To address these problems, an efficient ReID adversarial attack model, multi-scale gradient adversarial examples generation network(MSG-AEGN), is put forward. MSG-AEGN is based on the multi-scale gradient adversarial networks. A multi-scale network structure is adopted to obtain different semantic levels of the input images and the intermediate features of the generator. An attention module is adopted to convert the intermediate features of the generator into multi-scale weights, thereby modulating the image pixels. Finally, the network outputs high-quality adversarial examples to confuse the ReID models. On this basis, an improved adversarial loss function based on the average distance of image features and the triplet loss is proposed to constrain and guide the training of MSG-AEGN. Experiments on three pedestrian ReID datasets, namely Market1501, CUHK03 and Duke-MTMC-ReID, show that the proposed method produces promising attack effects on both the mainstream Re-ID models based on deep convolutional neural networks and the transformer networks. Moreover, MSG-AEGN possesses the advantages of low required attack energy and high structural similarity between adversarial samples and original images.
Key wordsPerson Re-identification      Multi-scale Generative Adversarial Network      Adversarial Attack      Improved Adversarial Loss     
Received: 09 March 2022     
ZTFLH: TP 391  
Fund:National Key Research and Development Project of China(No.2019YFB1312000), National Natural Science Foundation of China(No.62076195)
Corresponding Authors: HONG Xiaopeng, Ph.D., professor. His research interests include video surveillance and deep continual learning.   
About author:: SHI Lei, master, assistant engineer. His research interests include person re-identification robustness analysis.
ZHANG Xiaohan, master student. Her research interests include incremental lear-ning.LI Jiliang, Ph.D., associate professor. His research interests include cryptography theory and application.
DING Wenjie, master, assistant professor. Her research interests include deep adversa-rial attack and person re-identification.
SHEN Chao, Ph.D., professor. His research interests include artificial intelligence and network security.
Service
E-mail this article
Add to my bookshelf
Add to citation manager
E-mail Alert
RSS
Articles by authors
SHI Lei
ZHANG Xiaohan
HONG Xiaopeng
LI Jiliang
DING Wenjie
SHEN Chao
Cite this article:   
SHI Lei,ZHANG Xiaohan,HONG Xiaopeng等. Multi-scale Gradient Adversarial Examples Generation Network[J]. Pattern Recognition and Artificial Intelligence, 2022, 35(6): 483-496.
URL:  
http://manu46.magtech.com.cn/Jweb_prai/EN/10.16451/j.cnki.issn1003-6059.202206001      OR     http://manu46.magtech.com.cn/Jweb_prai/EN/Y2022/V35/I6/483
Copyright © 2010 Editorial Office of Pattern Recognition and Artificial Intelligence
Address: No.350 Shushanhu Road, Hefei, Anhui Province, P.R. China Tel: 0551-65591176 Fax:0551-65591176 Email: bjb@iim.ac.cn
Supported by Beijing Magtech  Email:support@magtech.com.cn