{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T15:19:06Z","timestamp":1777043946345,"version":"3.51.4"},"reference-count":71,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,1,5]],"date-time":"2023-01-05T00:00:00Z","timestamp":1672876800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"crossref","award":["DP150100294 and DP150104251"],"award-info":[{"award-number":["DP150100294 and DP150104251"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"crossref","award":["U19A2073, 62002096"],"award-info":[{"award-number":["U19A2073, 62002096"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Co-operative Innovation Project of Colleges in Anhui","award":["GXXT-2019-025"],"award-info":[{"award-number":["GXXT-2019-025"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Multimedia Comput. Commun. Appl."],"published-print":{"date-parts":[[2023,1,31]]},"abstract":"<jats:p>The vulnerability of re-identification (re-ID) models under adversarial attacks is of significant concern as criminals may use adversarial perturbations to evade surveillance systems. Unlike a closed-world re-ID setting (i.e., a fixed number of training categories), a reliable re-ID system in the open world raises the concern of training a robust yet discriminative classifier, which still shows robustness in the context of unknown examples of an identity. In this work, we improve the robustness of open-world re-ID models by proposing a generative metric learning approach to generate adversarial examples that are regularized to produce robust distance metric. The proposed approach leverages the expressive capability of generative adversarial networks to defend the re-ID models against feature disturbance attacks. By generating the target people variants and sampling the triplet units for metric learning, our learned distance metrics are regulated to produce accurate predictions in the feature metric space. Experimental results on the three re-ID datasets, i.e., Market-1501, DukeMTMC-reID, and MSMT17 demonstrate the robustness of our method.<\/jats:p>","DOI":"10.1145\/3522714","type":"journal-article","created":{"date-parts":[[2022,3,12]],"date-time":"2022-03-12T11:50:20Z","timestamp":1647085820000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":28,"title":["Generative Metric Learning for Adversarially Robust Open-world Person Re-Identification"],"prefix":"10.1145","volume":"19","author":[{"given":"Deyin","family":"Liu","sequence":"first","affiliation":[{"name":"Anhui Provincial Key Laboratory of Multimodal Cognitive Computation, School of Artificial Intelligence, Anhui University, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lin (Yuanbo)","family":"Wu","sequence":"additional","affiliation":[{"name":"The University of Western Australia, Perth, WA, Australia and Hefei University of Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Richang","family":"Hong","sequence":"additional","affiliation":[{"name":"Hefei University of Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zongyuan","family":"Ge","sequence":"additional","affiliation":[{"name":"Monash-Airdoc Research, Monash University, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jialie","family":"Shen","sequence":"additional","affiliation":[{"name":"Queen\u2019s University, Belfast, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Farid","family":"Boussaid","sequence":"additional","affiliation":[{"name":"The University of Western Australia, Perth, WA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammed","family":"Bennamoun","sequence":"additional","affiliation":[{"name":"The University of Western Australia, Perth, WA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,1,5]]},"reference":[{"key":"e_1_3_2_2_2","volume-title":"ICLR","author":"Aditi Raghunathan","year":"2018","unstructured":"Raghunathan Aditi, Steinhardt Jacob, and Liang Percy. 2018. Certified defenses against adversarial examples. In ICLR."},{"key":"e_1_3_2_3_2","first-page":"3908","volume-title":"CVPR","author":"Ahmed Ejaz","year":"2015","unstructured":"Ejaz Ahmed, Michael Jones, and Tim K. Marks. 2015. An improved deep learning architecture for person re-identification. In CVPR. 3908\u20133916."},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2015.2390222"},{"key":"e_1_3_2_5_2","first-page":"284","volume-title":"ICML","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018. Synthesizing robust adversarial examples. In ICML. 284\u2013293."},{"issue":"6","key":"e_1_3_2_6_2","doi-asserted-by":"crossref","first-page":"2119","DOI":"10.1109\/TPAMI.2020.3031625","article-title":"Metric attack and defence for person re-identification","volume":"43","author":"Bai Song","year":"2021","unstructured":"Song Bai, Yingwei Li, Yuyin Zhou, Qizhu Li, and Philip H. S. Torr. 2021. Metric attack and defence for person re-identification. IEEE Trans. Pattern Anal. Mach. Intell. 43, 6 (2021), 2119\u20132126.","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"e_1_3_2_7_2","volume-title":"CoRR abs\/1709.05583","author":"Cao Xiaoyu","year":"2017","unstructured":"Xiaoyu Cao and Neil Zhenqiang Gong. 2017. Mitigating evasion attacks to deep neural networks via region-based classification. CoRR abs\/1709.05583."},{"key":"e_1_3_2_8_2","doi-asserted-by":"crossref","unstructured":"Nicholas Carlini and David A. Wagner. 2017. Towards evaluating the robustness of neural networks. In S&P . 39\u201357.","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_9_2","first-page":"1320","volume-title":"CVPR","author":"Chen Weihua","year":"2017","unstructured":"Weihua Chen, Xiaotang Chen, Jianguo Zhang, and Kaiqi Huang. 2017. Beyond triplet loss: A deep quadruplet network for person re-identification. In CVPR. 1320\u20131329."},{"key":"e_1_3_2_10_2","first-page":"854","volume-title":"ICML","author":"Cisse Moustapha","year":"2017","unstructured":"Moustapha Cisse, Piotr Bojanowski annd Edouard Grave, and Yann Douphin annd Nicolas Usunier. 2017. Parseval networks: Improving robustness to adversarial examples. In ICML. 854\u2013863."},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"key":"e_1_3_2_12_2","volume-title":"CVPR","author":"Deng Weijian","year":"2018","unstructured":"Weijian Deng, Liang Zheng, Qixiang Ye, Guoliang Kang, Yi Yang, and Jianbin Jiao. 2018. Image-image domain adaptation with preserved self-similarity and domain-dissimilarity for person re-identification. In CVPR."},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3081247"},{"key":"e_1_3_2_14_2","first-page":"9185","volume-title":"CVPR","author":"Dong Yinpeng","year":"2018","unstructured":"Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li. 2018. Boosting adversarial attacks with momentum. In CVPR. 9185\u20139193."},{"key":"e_1_3_2_15_2","first-page":"2780","volume-title":"CVPR","author":"Duan Yueqi","year":"2018","unstructured":"Yueqi Duan, Wanqing Zheng, Xudong Lin, Jiwen Lu, and Jie Zhou. 2018. Deep adversarial metric learning. In CVPR. 2780\u20132789."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2009.167"},{"key":"e_1_3_2_17_2","volume-title":"arXiv:2101.08783","author":"Gong Yunpeng","year":"2021","unstructured":"Yunpeng Gong, Zhiyong Zeng, Liwen Chen, Yifan Luo, Bin Weng, and Feng Ye. 2021. A person re-identification data augmentation method with adversarial defense effect. arXiv:2101.08783. Retrieved from https:\/\/arxiv.org\/abs\/2101.08783."},{"key":"e_1_3_2_18_2","volume-title":"NIPS","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In NIPS."},{"key":"e_1_3_2_19_2","volume-title":"ICLR","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In ICLR."},{"key":"e_1_3_2_20_2","volume-title":"arXiv:1703.07737","author":"Hermans Alexander","year":"2017","unstructured":"Alexander Hermans, Lucas Beyer, and Bastian Leibe. 2017. In defence of the triplet loss for person re-identification. arXiv:1703.07737. Retrieved from https:\/\/arxiv.org\/abs\/1703.07737."},{"key":"e_1_3_2_21_2","volume-title":"CVPR","author":"Huang Gao","year":"2017","unstructured":"Gao Huang, Zhuang Liu, Laurens van der Maaten, and Kilian Q. Weinberger. 2017. Densely connected convolutional networks. In CVPR."},{"key":"e_1_3_2_22_2","first-page":"5098","volume-title":"CVPR","author":"Huang Houjing","year":"2018","unstructured":"Houjing Huang, Dangwei Li, Zhang Zhang, Xiaotang Chen, and Kaiqi Huang. 2018. Adversarially occluded samples for person re-identification. In CVPR. 5098\u20135107."},{"key":"e_1_3_2_23_2","first-page":"2142","volume-title":"ICML","author":"Ilyas Andrew","year":"2018","unstructured":"Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018. Black-box adversarial attacks with limited queries and information. In ICML. 2142\u20132151."},{"key":"e_1_3_2_24_2","first-page":"125","volume-title":"NeurIPS","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial examples are not bugs, they are features. In NeurIPS. 125\u2013136."},{"key":"e_1_3_2_25_2","volume-title":"arXiv:1803.06373","author":"Kannan Harini","year":"2018","unstructured":"Harini Kannan, Alexey Kurakin, and Ian J. Goodfellow. 2018. Adversarial logit pairing. arXiv:1803.06373. Retrieved from https:\/\/arxiv.org\/abs\/1803.06373."},{"key":"e_1_3_2_26_2","first-page":"422","volume-title":"SIBIRCON","author":"Kaziakhmedov Edgar","year":"2019","unstructured":"Edgar Kaziakhmedov, Klim Kireev, Grigorii Melnikov, Mikhail Pautov, and Aleksandr Petiushko. 2019. Real-world attack on MTCNN face detection system. In SIBIRCON. 422\u2013427."},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.5555\/3275298"},{"key":"e_1_3_2_28_2","volume-title":"arXiv:1607.02533","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial examples in the physical world. In arXiv:1607.02533. Retrieved from https:\/\/arxiv.org\/abs\/1607.02533."},{"key":"e_1_3_2_29_2","first-page":"4899","volume-title":"ICCV","author":"Li Jie","year":"2019","unstructured":"Jie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong, Yue Gao, and Qi Tian. 2019. Universal perturbation attack against image retrieval. In ICCV. 4899\u20134908."},{"key":"e_1_3_2_30_2","volume-title":"CVPR","author":"Li Wei","year":"2011","unstructured":"Wei Li, Rui Zhao, Tong Xiao, and Xiaogang Wang. 2011. Deepreid: Deep filter pairing neural network for person re-identification. In CVPR."},{"key":"e_1_3_2_31_2","first-page":"2285","volume-title":"CVPR","author":"Li Wei","year":"2018","unstructured":"Wei Li, Xiatian Zhu, and Shaogang Gong. 2018. Harmonious attention network for person re-identification. In CVPR. 2285\u20132294."},{"key":"e_1_3_2_32_2","first-page":"287","volume-title":"ECCV","author":"Li Xiang","year":"2018","unstructured":"Xiang Li, Ancong Wu, and Wei-Shi Zheng. 2018. Adversarial open-world person re-identification. In ECCV. 287\u2013303."},{"key":"e_1_3_2_33_2","first-page":"2197","volume-title":"CVPR","author":"Liao Shengcai","year":"2015","unstructured":"Shengcai Liao, Yang Hu, Xiangyu Zhu, and Stan Z. Li. 2015. Person re-identification by local maximal occurrence representation and metric learning. In CVPR. 2197\u20132206."},{"key":"e_1_3_2_34_2","first-page":"2117","volume-title":"CVPR","author":"Lin Tsung-Yi","year":"2017","unstructured":"Tsung-Yi Lin, Piotr Doll\u00e1r, Ross Girshick, Kaiming He, Bharath Hariharan, and Serge Belongie. 2017. Feature pyramid networks for object detection. In CVPR. 2117\u20132125."},{"key":"e_1_3_2_35_2","volume-title":"ICLR","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models using resistant to adversarial attacks. In ICLR."},{"key":"e_1_3_2_36_2","volume-title":"NeurIPS","author":"Mao Chengzhi","year":"2019","unstructured":"Chengzhi Mao, Ziyuan Zhong, Junfeng Yang, Carl Vondrick, and Baishakhi Ray. 2019. Metric learning for adversarial robustness. In NeurIPS."},{"key":"e_1_3_2_37_2","first-page":"86","volume-title":"CVPR","author":"Moosavi-Dezfooli Seyed-Mohsen","year":"2017","unstructured":"Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal adversarial perturbations. In CVPR. 86\u201394."},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2861800"},{"key":"e_1_3_2_39_2","first-page":"427","volume-title":"CVPR","author":"Nguyen Anh","year":"2015","unstructured":"Anh Nguyen, Jason Yosinski, and Jeff Clune. 2015. Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. In CVPR. 427\u2013436."},{"key":"e_1_3_2_40_2","volume-title":"CoRR abs\/1605.07277","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick D. McDaniel, and Ian J. Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. In CoRR abs\/1605.07277."},{"key":"e_1_3_2_41_2","first-page":"91","volume-title":"NIPS","author":"Ren Shaoqing","year":"2015","unstructured":"Shaoqing Ren, Kaiming he, Ross Girshick, and Jian Sun. 2015. Faster r-cnn: Towards real-time object detection with region proposal networks. In NIPS. 91\u201399."},{"key":"e_1_3_2_42_2","first-page":"17","volume-title":"ECCV Workshop on Benchmarking Multi-Target Tracking","author":"Ristani Ergys","year":"2016","unstructured":"Ergys Ristani, Francesco SoleraRoger, ZouRita Cucchiara, and Carlo Tomasi. 2016. Performance measures and a data set for multi-target, multi-camera tracking. In ECCV Workshop on Benchmarking Multi-Target Tracking. 17\u201335."},{"key":"e_1_3_2_43_2","volume-title":"CVPR","author":"Ristani Ergys","year":"2018","unstructured":"Ergys Ristani and Carlo Tomasi. 2018. Features for multi-target multi-camera tracking and person re-identification. In CVPR."},{"key":"e_1_3_2_44_2","volume-title":"arXiv:1805.06605","author":"Samangouei Pouya","year":"2018","unstructured":"Pouya Samangouei, Maya Kabkab, and Rama Chellappa. 2018. Defense-gan: Protecting classifiers against adversarial attacks using generative models. arXiv:1805.06605. Retrieved from https:\/\/arxiv.org\/abs\/1805.06605."},{"key":"e_1_3_2_45_2","volume-title":"NeurIPS","author":"Shafahi Ali","year":"2019","unstructured":"Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein. 2019. Adversarial training for free! In NeurIPS."},{"key":"e_1_3_2_46_2","first-page":"732","volume-title":"ECCV","author":"Shi Hailin","year":"2016","unstructured":"Hailin Shi, Yang Yang, Xiangyu Zhu, Shengcai Liao, Zhen Lei, and Weishi Zheng. 2016. Embedding deep metric for person re-identification: A study against large variations. In ECCV. 732\u2013748."},{"key":"e_1_3_2_47_2","volume-title":"ECCV","author":"Sun Yifan","year":"2018","unstructured":"Yifan Sun, Liang Zheng, Yi Yang, Qi Tian, and Shengjin Wang. 2018. Beyond part models: Person retrieval with refined part pooling. In ECCV."},{"key":"e_1_3_2_48_2","volume-title":"ICLR","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In ICLR."},{"key":"e_1_3_2_49_2","volume-title":"ICLR","author":"Tram\u00e8r Florian","year":"2018","unstructured":"Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2018. Ensemble adversarial training: Attacks and defenses. In ICLR."},{"key":"e_1_3_2_50_2","first-page":"342","volume-title":"CVPR","author":"Wang Hongjun","year":"2020","unstructured":"Hongjun Wang, Guangrun Wang, Ya Li, Dongyu Zhang, and Liang Lin. 2020. Transferable, controllable, and inconspicuous adversarial attacks on person re-identification with deep mis-ranking. In CVPR. 342\u2013351."},{"key":"e_1_3_2_51_2","first-page":"8341","volume-title":"ICCV","author":"Wang Zhibo","year":"2019","unstructured":"Zhibo Wang, Siyang Zheng, Mengkai Song, Qian Wang, Alireza Rahimpour, and Hairong Qi. 2019. advPattern: Physical-world attacks on deep re-identification via adversarially transformable patterns. In ICCV. 8341\u20138350."},{"key":"e_1_3_2_52_2","first-page":"79","volume-title":"CVPR","author":"Wei Longhui","year":"2018","unstructured":"Longhui Wei, Shiliang Zhang, Wen Gao, and Qi Tian. 2018. Person transfer gan to bridge domain gap for person re- identification. In CVPR. 79\u201388."},{"key":"e_1_3_2_53_2","volume-title":"ICLR","author":"Wieland Brendel","year":"2018","unstructured":"Brendel Wieland, Jonas Rauber, and Matthias Bethge. 2018. Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In ICLR."},{"key":"e_1_3_2_54_2","first-page":"5283","volume-title":"ICML","author":"Wong Eric","year":"2018","unstructured":"Eric Wong and Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. In ICML. 5283\u20135292."},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2017.08.029"},{"issue":"1","key":"e_1_3_2_56_2","first-page":"1233","article-title":"Few-shot deep adversarial learning for video-based person re-identification","volume":"29","author":"Wu Lin","year":"2020","unstructured":"Lin Wu, Yang Wang, Hongzhi Yin, Meng Wang, and Ling Shao. 2020. Few-shot deep adversarial learning for video-based person re-identification. IEEE Trans. Image Process. 29, 1 (2020), 1233\u20131245.","journal-title":"IEEE Trans. Image Process."},{"key":"e_1_3_2_57_2","volume-title":"ICLR","author":"Xiao Kai Y.","year":"2019","unstructured":"Kai Y. Xiao, Vincent Tjeng, Nur Muhammad Shafiullah, and Aleksander Madry. 2019. Training for faster adversarial robustness verification via inducing relu stability. In ICLR."},{"key":"e_1_3_2_58_2","volume-title":"CoRR abs\/1812.03411","author":"Xie Cihang","year":"2018","unstructured":"Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan L. Yuille, and Kaiming He. 2018. Feature denoising for improving adversarial robustness. CoRR abs\/1812.03411."},{"key":"e_1_3_2_59_2","volume-title":"ICML","author":"Yang Yuzhe","year":"2019","unstructured":"Yuzhe Yang, Guo Zhang, Dina Katabi, and Zhi Xu. 2019. Me-net: Towards effective adversarial robustness with matrix estimation. In ICML."},{"key":"e_1_3_2_60_2","article-title":"Deep learning for person re-identification: A survey and outlook","author":"Ye Mang","year":"2020","unstructured":"Mang Ye, Jianbing Shen, Gaojie Lin, Tao Xiang, Ling Shao, and Steven C. H. Hoi. 2020. Deep learning for person re-identification: A survey and outlook. IEEE Trans. Pattern Anal. Mach. Intell. (2020).","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"e_1_3_2_61_2","volume-title":"NeurIPS","author":"Zhang Dinghuai","year":"2019","unstructured":"Dinghuai Zhang, Tianyuan Zhang, Yiping Lu, Zhanxing Zhu, and Bin Dong. 2019. You only propagate once: Accelerating adversarial training via maximal principle. In NeurIPS."},{"key":"e_1_3_2_62_2","unstructured":"Xuan Zhang Hao Luo Xing Fan Weilai Xiang Yixiao Sun Qiqi Xiao Wei Jiang Chi Zhang and Jian Sun. 2017. Alignedreid: Surpassing human-level performance in person re-identification."},{"key":"e_1_3_2_63_2","volume-title":"ICCV","author":"Zheng Liang","year":"2015","unstructured":"Liang Zheng, Liyue Shen, Lu Tian, Shengjin Wang, Jingdong Wang, and Qi Tian. 2015. Scalable person re-identification: A benchmark. In ICCV."},{"key":"e_1_3_2_64_2","volume-title":"arXiv:1610.02984","author":"Zheng Liang","year":"2018","unstructured":"Liang Zheng, Yi Yang, and Alexander G. Hauptmann. 2018. Person re-identification: Past, present and future. arXiv:1610.02984. Retrieved from https:\/\/arxiv.org\/abs\/1610.02984."},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2012.138"},{"key":"e_1_3_2_66_2","first-page":"7913","volume-title":"NIPS","author":"Zheng Zhihao","year":"2018","unstructured":"Zhihao Zheng and Pengyu Hong. 2018. Robust detection of adversarial attacks by modeling the intrinsic properties of deep neural networks. In NIPS. 7913\u20137922."},{"key":"e_1_3_2_67_2","first-page":"2138","volume-title":"CVPR","author":"Zheng Zhedong","year":"2019","unstructured":"Zhedong Zheng, Xiaodong Yang, Zhiding Yu, Liang Zheng, Yi Yang, and Jan Kautz. 2019. Joint discriminative and generative learning for person re-identification. In CVPR. 2138\u20132146."},{"key":"e_1_3_2_68_2","volume-title":"ICCV","author":"Zheng Zhedong","year":"2017","unstructured":"Zhedong Zheng, Liang Zheng, and Yi Yang. 2017. Unlabeled samples generated by GAN improve the person re-identification baseline in vitro. In ICCV."},{"key":"e_1_3_2_69_2","volume-title":"arXiv:1809.02681","author":"Zheng Zhedong","year":"2018","unstructured":"Zhedong Zheng, Liang Zheng, Yi Yang, and Fei Wu. 2018. Query attack via opposite-direction feature: Towards robust image retrieval. arXiv:1809.02681. Retrieved from https:\/\/arxiv.org\/abs\/1809.02681."},{"key":"e_1_3_2_70_2","volume-title":"ICCV","author":"Zhong Zhun","year":"2017","unstructured":"Zhun Zhong, Liang Zheng, Donglin Cao, and Shaozi Li. 2017. Re-ranking person re-identification with k-reciprocal encoding. In ICCV."},{"key":"e_1_3_2_71_2","first-page":"172","volume-title":"ECCV","author":"Zhong Zhun","year":"2018","unstructured":"Zhun Zhong, Liang Zheng, Shaozi Li, and Yi Yang. 2018. Generalizing a person retrieval model hetero and homogenerously. In ECCV. 172\u2013188."},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2017.2740564"}],"container-title":["ACM Transactions on Multimedia Computing, Communications, and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3522714","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3522714","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:30:15Z","timestamp":1750188615000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3522714"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,5]]},"references-count":71,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,1,31]]}},"alternative-id":["10.1145\/3522714"],"URL":"https:\/\/doi.org\/10.1145\/3522714","relation":{},"ISSN":["1551-6857","1551-6865"],"issn-type":[{"value":"1551-6857","type":"print"},{"value":"1551-6865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,5]]},"assertion":[{"value":"2021-07-06","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-02-24","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-01-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}