Multi-Spectral Palmprints Joint Attack and Defense With Adversarial Examples Learning

被引:9
作者
Zhu, Qi [1 ]
Zhou, Yuze [1 ]
Fei, Lunke [2 ]
Zhang, Daoqiang [1 ]
Zhang, David [3 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing 210016, Peoples R China
[2] Guangdong Univ Technol, Sch Comp Sci & Technol, Guangzhou 510006, Peoples R China
[3] Chinese Univ Hong Kong, Sch Sci & Engn, Shenzhen 518172, Peoples R China
基金
中国国家自然科学基金;
关键词
Perturbation methods; Correlation; Palmprint recognition; Robustness; Training; Security; Glass box; Biometrics; multi-spectral palmprint recognition; adversarial example; security; manifold learning; DIFFERENTIAL EVOLUTION; RECOGNITION;
D O I
10.1109/TIFS.2023.3254432
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As an emerging biometric technology, multi-spectral palmprint recognition has attracted increasing attention in security due to its high accuracy and ease of use. Compared to single spectral case, multi-spectral palmprint model is more susceptible to the attack of adversarial examples. However, the previous adversarial example attack approaches cannot generate the most aggressive adversarial examples for multi-spectral palmprint recognition. In addition, most of them are dependent on the explicit architecture or need time-consuming queries about the network to be attacked, which significantly limits their application in the field of security. To solve the above problems, in this paper, we proposed the multi-spectral palmprints joint attack and defense framework based on multi-view adversarial examples learning. First, we respectively capture the multi-view deep common feature space for the different spectra and the discriminative feature space across the different subjects. Second, we introduce perturbation in the deep common space to achieve adversarial multi-spectral palmprints with gradient propagation. In addition, we pursue the manifold of the difference space and use it to suppress the discriminability of the recognition model with adversarial region theory. Finally, the generated adversarial examples are fed into the training model to enhance the robustness of the recognition algorithm. The experimental results on multi-spectral palmprint dataset demonstrate that the proposed multi-view joint attack approach is superior to the state-of-the-art adversarial example attack methods in attack accuracy and transferability. Moreover, the defense strategy with the adversarial examples by our method can significantly promote the robustness of multi-spectral palmprint recognition methods.
引用
收藏
页码:1789 / 1799
页数:11
相关论文
共 45 条
[41]   An Online System of Multispectral Palmprint Verification [J].
Zhang, David ;
Guo, Zhenhua ;
Lu, Guangming ;
Zhang, Lei ;
Zuo, Wangmeng .
IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2010, 59 (02) :480-490
[42]   Principal Component Adversarial Example [J].
Zhang, Yonggang ;
Tian, Xinmei ;
Li, Ya ;
Wang, Xinchao ;
Tao, Dacheng .
IEEE TRANSACTIONS ON IMAGE PROCESSING, 2020, 29 :4804-4815
[43]   Deep discriminative representation for generic palmprint recognition [J].
Zhao, Shuping ;
Zhang, Bob .
PATTERN RECOGNITION, 2020, 98
[44]   Decade progress of palmprint recognition: A brief survey [J].
Zhong, Dexing ;
Du, Xuefeng ;
Zhong, Kuncai .
NEUROCOMPUTING, 2019, 328 :16-28
[45]   Towards Transferable Adversarial Attack Against Deep Face Recognition [J].
Zhong, Yaoyao ;
Deng, Weihong .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 :1452-1466