Similarity Distribution Based Membership Inference Attack on Person Re-identification

Junyao Gao,Xinyang Jiang,Huishuai Zhang,Yifan Yang,Shuguang Dou,Dongsheng Li,Duoqian Miao,Cheng Deng,Cairong Zhao
DOI: https://doi.org/10.1609/aaai.v37i12.26731
2023-01-01
Abstract:While person Re-identification (Re-ID) has progressed rapidly due to its widereal-world applications, it also causes severe risks of leaking personalinformation from training data. Thus, this paper focuses on quantifying thisrisk by membership inference (MI) attack. Most of the existing MI attackalgorithms focus on classification models, while Re-ID follows a totallydifferent training and inference paradigm. Re-ID is a fine-grained recognitiontask with complex feature embedding, and model outputs commonly used byexisting MI like logits and losses are not accessible during inference. SinceRe-ID focuses on modelling the relative relationship between image pairsinstead of individual semantics, we conduct a formal and empirical analysiswhich validates that the distribution shift of the inter-sample similaritybetween training and test set is a critical criterion for Re-ID membershipinference. As a result, we propose a novel membership inference attack methodbased on the inter-sample similarity distribution. Specifically, a set ofanchor images are sampled to represent the similarity distribution conditionedon a target image, and a neural network with a novel anchor selection module isproposed to predict the membership of the target image. Our experimentsvalidate the effectiveness of the proposed approach on both the Re-ID task andconventional classification task.
What problem does this paper attempt to address?