Multi-Spectral Palmprints Joint Attack and Defense With Adversarial Examples Learning

被引:7
作者
Zhu, Qi [1 ]
Zhou, Yuze [1 ]
Fei, Lunke [2 ]
Zhang, Daoqiang [1 ]
Zhang, David [3 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing 210016, Peoples R China
[2] Guangdong Univ Technol, Sch Comp Sci & Technol, Guangzhou 510006, Peoples R China
[3] Chinese Univ Hong Kong, Sch Sci & Engn, Shenzhen 518172, Peoples R China
基金
中国国家自然科学基金;
关键词
Perturbation methods; Correlation; Palmprint recognition; Robustness; Training; Security; Glass box; Biometrics; multi-spectral palmprint recognition; adversarial example; security; manifold learning; DIFFERENTIAL EVOLUTION; RECOGNITION;
D O I
10.1109/TIFS.2023.3254432
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As an emerging biometric technology, multi-spectral palmprint recognition has attracted increasing attention in security due to its high accuracy and ease of use. Compared to single spectral case, multi-spectral palmprint model is more susceptible to the attack of adversarial examples. However, the previous adversarial example attack approaches cannot generate the most aggressive adversarial examples for multi-spectral palmprint recognition. In addition, most of them are dependent on the explicit architecture or need time-consuming queries about the network to be attacked, which significantly limits their application in the field of security. To solve the above problems, in this paper, we proposed the multi-spectral palmprints joint attack and defense framework based on multi-view adversarial examples learning. First, we respectively capture the multi-view deep common feature space for the different spectra and the discriminative feature space across the different subjects. Second, we introduce perturbation in the deep common space to achieve adversarial multi-spectral palmprints with gradient propagation. In addition, we pursue the manifold of the difference space and use it to suppress the discriminability of the recognition model with adversarial region theory. Finally, the generated adversarial examples are fed into the training model to enhance the robustness of the recognition algorithm. The experimental results on multi-spectral palmprint dataset demonstrate that the proposed multi-view joint attack approach is superior to the state-of-the-art adversarial example attack methods in attack accuracy and transferability. Moreover, the defense strategy with the adversarial examples by our method can significantly promote the robustness of multi-spectral palmprint recognition methods.
引用
收藏
页码:1789 / 1799
页数:11
相关论文
共 45 条
  • [1] Multispectral Palmprint Recognition: A Survey and Comparative Study
    Aberni, Yassir
    Boubchir, Larbi
    Daachi, Boubaker
    [J]. JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2019, 28 (07)
  • [2] Afriat S. N., 1957, MATH P CAMBRIDGE PHI, V53, P800
  • [3] Andrew G., 2013, Proceedings of the 30th International Conference on Machine Learning, P1247
  • [4] [Anonymous], 2011, P ADV NEUR INF PROC
  • [5] Benton A, 2017, Arxiv, DOI arXiv:1702.02519
  • [6] Multi-spectral palmprint recognition based on oriented multiscale log-Gabor filters
    Bounneche, Meriem Dorsaf
    Boubchir, Larbi
    Bouridane, Ahmed
    Nekhoul, Bachir
    Ali-Cherif, Arab
    [J]. NEUROCOMPUTING, 2016, 205 : 274 - 286
  • [7] Brendel W, 2018, Arxiv, DOI arXiv:1712.04248
  • [8] Towards Evaluating the Robustness of Neural Networks
    Carlini, Nicholas
    Wagner, David
    [J]. 2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, : 39 - 57
  • [9] Chen P-Y, 2017, ACM WORKSH ART INT S, P15, DOI DOI 10.1145/3128572.3140448
  • [10] Differential Evolution: A Survey of the State-of-the-Art
    Das, Swagatam
    Suganthan, Ponnuthurai Nagaratnam
    [J]. IEEE TRANSACTIONS ON EVOLUTIONARY COMPUTATION, 2011, 15 (01) : 4 - 31