Black-box attacks on face recognition via affine-invariant training

被引:0
|
作者
Sun, Bowen [1 ]
Su, Hang [2 ]
Zheng, Shibao [1 ]
机构
[1] Shanghai Jiao Tong Univ, Dept Elect Engn, Shanghai 200240, Peoples R China
[2] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
来源
NEURAL COMPUTING & APPLICATIONS | 2024年 / 36卷 / 15期
基金
中国国家自然科学基金;
关键词
Face recognition; Black-box attack; Affine-invariant training; AI-block; EIGENFACES;
D O I
10.1007/s00521-024-09543-y
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural network (DNN)-based face recognition has shown impressive performance in verification; however, recent studies reveal a vulnerability in deep face recognition algorithms, making them susceptible to adversarial attacks. Specifically, these attacks can be executed in a black-box manner with limited knowledge about the target network. While this characteristic is practically significant due to hidden model details in reality, it presents challenges such as high query budgets and low success rates. To improve the performance of attacks, we establish the whole framework through affine-invariant training, serving as a substitute for inefficient sampling. We also propose AI-block-a novel module that enhances transferability by introducing generalized priors. Generalization is achieved by creating priors with stable features when sampled over affine transformations. These priors guide attacks, improving efficiency and performance in black-box scenarios. The conversion via AI-block enables the transfer gradients of a surrogate model to be used as effective priors for estimating the gradients of a black-box model. Our method leverages this enhanced transferability to boost both transfer-based and query-based attacks. Extensive experiments conducted on 5 commonly utilized databases and 7 widely employed face recognition models demonstrate a significant improvement of up to 11.9 percentage points in success rates while maintaining comparable or even reduced query times.
引用
收藏
页码:8549 / 8564
页数:16
相关论文
共 50 条
  • [21] Iconic representation and recognition using Affine-Invariant Spectral Signatures
    BenArie, J
    Wang, ZQ
    Rao, KR
    IMAGE UNDERSTANDING WORKSHOP, 1996 PROCEEDINGS, VOLS I AND II, 1996, : 1277 - 1285
  • [22] Parsimonious Black-Box Adversarial Attacks via Efficient Combinatorial Optimization
    Moon, Seungyong
    An, Gaon
    Song, Hyun Oh
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [23] Affine-invariant local descriptors and neighborhood statistics for texture recognition
    Lazebnik, S
    Schmid, C
    Ponce, J
    NINTH IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION, VOLS I AND II, PROCEEDINGS, 2003, : 649 - 655
  • [24] On Black-Box Explanation for Face Verification
    Mery, Domingo
    Morris, Bernardita
    2022 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2022), 2022, : 1194 - 1203
  • [25] AFFINE-INVARIANT SHAPE MATCHING AND RECOGNITION UNDER PARTIAL OCCLUSION
    Mai, F.
    Chang, C. Q.
    Hung, Y. S.
    2010 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, 2010, : 4605 - 4608
  • [26] Black-box adversarial attacks through speech distortion for speech emotion recognition
    Gao, Jinxing
    Yan, Diqun
    Dong, Mingyu
    EURASIP JOURNAL ON AUDIO SPEECH AND MUSIC PROCESSING, 2022, 2022 (01)
  • [27] Efficient Decision-based Black-box Patch Attacks on Video Recognition
    Jiang, Kaixun
    Chen, Zhaoyu
    Huang, Hao
    Wang, Jiafeng
    Yang, Dingkang
    Li, Bo
    Wang, Yan
    Zhang, Wenqiang
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4356 - 4366
  • [28] Query-Efficient Black-Box Adversarial Attacks on Automatic Speech Recognition
    Tong, Chuxuan
    Zheng, Xi
    Li, Jianhua
    Ma, Xingjun
    Gao, Longxiang
    Xiang, Yong
    IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2023, 31 : 3981 - 3992
  • [29] Black-box adversarial attacks through speech distortion for speech emotion recognition
    Jinxing Gao
    Diqun Yan
    Mingyu Dong
    EURASIP Journal on Audio, Speech, and Music Processing, 2022
  • [30] Generative Adversarial Networks for Black-Box API Attacks with Limited Training Data
    Shi, Yi
    Sagduyu, Yalin E.
    Davaslioglu, Kemal
    Li, Jason H.
    2018 IEEE INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING AND INFORMATION TECHNOLOGY (ISSPIT), 2018, : 453 - 458