错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Human-in-the-Loop Person Re-Identification as a Defence Against Adversarial Attacks

  • Rita Delussu,
  • Lorenzo Putzu,
  • Emanuele Ledda,
  • Giorgio Fumera

摘要

Person re-identification (Re-Id) is a computer vision task useful to security-related applications of video surveillance systems. Recently it has been shown that Re-Id systems, currently based on deep neural networks, are vulnerable to adversarial attacks, some of which are based on manipulating the query image to prevent other images of the same individual from being retrieved. Whereas some ad hoc defence strategies have been proposed so far against different implementations of this kind of attack, we argue that the human-in-the-loop (HITL) approach, originally proposed for retrieval systems (including Re-Id) to improve retrieval accuracy under normal operational conditions, can also act as an effective and general defence strategy, with the notable advantage that it does not degrade accuracy in the absence of attacks, contrary to ad hoc defences. We provide empirical evidence of this fact on several benchmark data sets and state-of-the-art Re-Id models, using a simple HITL implementation based on relevance feedback algorithms.