Similarity Distribution based Membership Inference Attack on Person Re-identification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gao, Junyao, Jiang, Xinyang, Zhang, Huishuai, Yang, Yifan, Dou, Shuguang, Li, Dongsheng, Miao, Duoqian, Deng, Cheng, Zhao, Cairong
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916166767738880
author Gao, Junyao
Jiang, Xinyang
Zhang, Huishuai
Yang, Yifan
Dou, Shuguang
Li, Dongsheng
Miao, Duoqian
Deng, Cheng
Zhao, Cairong
author_facet Gao, Junyao
Jiang, Xinyang
Zhang, Huishuai
Yang, Yifan
Dou, Shuguang
Li, Dongsheng
Miao, Duoqian
Deng, Cheng
Zhao, Cairong
contents While person Re-identification (Re-ID) has progressed rapidly due to its wide real-world applications, it also causes severe risks of leaking personal information from training data. Thus, this paper focuses on quantifying this risk by membership inference (MI) attack. Most of the existing MI attack algorithms focus on classification models, while Re-ID follows a totally different training and inference paradigm. Re-ID is a fine-grained recognition task with complex feature embedding, and model outputs commonly used by existing MI like logits and losses are not accessible during inference. Since Re-ID focuses on modelling the relative relationship between image pairs instead of individual semantics, we conduct a formal and empirical analysis which validates that the distribution shift of the inter-sample similarity between training and test set is a critical criterion for Re-ID membership inference. As a result, we propose a novel membership inference attack method based on the inter-sample similarity distribution. Specifically, a set of anchor images are sampled to represent the similarity distribution conditioned on a target image, and a neural network with a novel anchor selection module is proposed to predict the membership of the target image. Our experiments validate the effectiveness of the proposed approach on both the Re-ID task and conventional classification task.
format Preprint
id arxiv_https___arxiv_org_abs_2211_15918
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Similarity Distribution based Membership Inference Attack on Person Re-identification
Gao, Junyao
Jiang, Xinyang
Zhang, Huishuai
Yang, Yifan
Dou, Shuguang
Li, Dongsheng
Miao, Duoqian
Deng, Cheng
Zhao, Cairong
Cryptography and Security
Computer Vision and Pattern Recognition
While person Re-identification (Re-ID) has progressed rapidly due to its wide real-world applications, it also causes severe risks of leaking personal information from training data. Thus, this paper focuses on quantifying this risk by membership inference (MI) attack. Most of the existing MI attack algorithms focus on classification models, while Re-ID follows a totally different training and inference paradigm. Re-ID is a fine-grained recognition task with complex feature embedding, and model outputs commonly used by existing MI like logits and losses are not accessible during inference. Since Re-ID focuses on modelling the relative relationship between image pairs instead of individual semantics, we conduct a formal and empirical analysis which validates that the distribution shift of the inter-sample similarity between training and test set is a critical criterion for Re-ID membership inference. As a result, we propose a novel membership inference attack method based on the inter-sample similarity distribution. Specifically, a set of anchor images are sampled to represent the similarity distribution conditioned on a target image, and a neural network with a novel anchor selection module is proposed to predict the membership of the target image. Our experiments validate the effectiveness of the proposed approach on both the Re-ID task and conventional classification task.
title Similarity Distribution based Membership Inference Attack on Person Re-identification
topic Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2211.15918