Fast Geometrically-Perturbed Adversarial Faces

被引:43
作者
Dabouei, Ali [1 ]
Soleymani, Sobhan [1 ]
Dawson, Jeremy [1 ]
Nasrabadi, Nasser M. [1 ]
机构
[1] West Virginia Univ, Morgantown, WV 26506 USA
来源
2019 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV) | 2019年
关键词
D O I
10.1109/WACV.2019.00215
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The state-of-the-art performance of deep learning algorithms has led to a considerable increase in the utilization of machine learning in security-sensitive and critical applications. However, it has recently been shown that a small and carefully crafted perturbation in the input space can completely fool a deep model. In this study, we explore the extent to which face recognition systems are vulnerable to geometrically-perturbed adversarial faces. We propose a fast landmark manipulation method for generating adversarial faces, which is approximately 200 times faster than the previous geometric attacks and obtains 99.86% success rate on the state-of-the-art face recognition models. To further force the generated samples to be natural, we introduce a second attack constrained on the semantic structure of the face which has the half speed of the first attack with the success rate of 99.96%. Both attacks are extremely robust against the state-of-the-art defense methods with the success rate of equal or greater than 53.59%. Code is available at https://github.com/alldbi/FLM.
引用
收藏
页码:1979 / 1988
页数:10
相关论文
共 35 条
[1]  
[Anonymous], 2017, ARXIV170508378
[2]  
[Anonymous], 2017, COMMUN ACM, DOI DOI 10.1145/3065386
[3]  
[Anonymous], 2015, PROC CVPR IEEE
[4]  
[Anonymous], 2017, ABS171108534 CORR
[5]  
[Anonymous], 2016, ARXIV161201401
[6]  
[Anonymous], 2018, IEEE BTAS
[7]  
[Anonymous], 2017, ARXIV170502900
[8]  
[Anonymous], PROC CVPR IEEE
[9]  
[Anonymous], P IEEE S SECUR PRIV
[10]  
[Anonymous], 2015, PROC 28 INT C NEURAL