Powerful Physical Adversarial Examples Against Practical Face Recognition Systems

被引:9
作者
Singh, Inderjeet [1 ]
Araki, Toshinori [1 ]
Kakizaki, Kazuya [1 ]
机构
[1] NEC Corp Ltd, Kawasaki, Kanagawa, Japan
来源
2022 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION WORKSHOPS (WACVW 2022) | 2022年
关键词
D O I
10.1109/WACVW54805.2022.00036
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
learning (ML)-based safety-critical applications are vulnerable to carefully crafted input instances called adversarial examples (AXs). An adversary can conveniently attack these target systems from digital as well as physical worlds. This paper aims to the generation of robust physical AXs against face recognition systems. We present a novel smoothness loss function and a patch-noise combo attack for realizing powerful physical AXs. The smoothness loss interjects the concept of delayed constraints during the attack generation process, thereby causing better handling of optimization complexity and smoother AXs for the physical domain. The patch-noise combo attack combines patch noise and imperceptibly small noises from different distributions to generate powerful registration-based physical AXs. An extensive experimental analysis found that our smoothness loss results in robust and more transferable digital and physical AXs than the conventional techniques. Notably, our smoothness loss results in a 1.17 and 1.97 times better mean attack success rate (ASR) in physical white-box and black-box attacks, respectively. Our patch-noise combo attack furthers the performance gains and results in 2.39 and 4.74 times higher mean ASR than conventional technique in physical world white-box and black-box attacks, respectively.
引用
收藏
页码:301 / 310
页数:10
相关论文
共 50 条
[31]   Adversarial Minimax Training for Robustness Against Adversarial Examples [J].
Komiyama, Ryota ;
Hattori, Motonobu .
NEURAL INFORMATION PROCESSING (ICONIP 2018), PT II, 2018, 11302 :690-699
[32]   Phonemic Adversarial Attack Against Audio Recognition in Physical World [J].
Wang, Jiakai ;
Kong, Yusheng ;
Chen, Zhendong ;
Hu, Jin ;
Yin, Zixin ;
Ma, Yuqing ;
Yang, Qinghong ;
Liu, Xianglong .
Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2025, 62 (03) :751-764
[33]   Enhancing Robustness Against Adversarial Examples in Network Intrusion Detection Systems [J].
Hashemi, Mohammad J. ;
Keller, Eric .
2020 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2020, :37-43
[34]   Adversarial Examples Against Image-based Malware Classification Systems [J].
Vi, Bao Ngoc ;
Nguyen, Huu Noi ;
Nguyen, Ngoc Tran ;
Tran, Cao Truong .
PROCEEDINGS OF 2019 11TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SYSTEMS ENGINEERING (KSE 2019), 2019, :347-351
[35]   Adversarial Examples Against WiFi Fingerprint-Based Localization in the Physical World [J].
Wang, Jiakai ;
Tao, Ye ;
Zhang, Yichi ;
Liu, Wanting ;
Kong, Yusheng ;
Tan, Shaolin ;
Yan, Rongen ;
Liu, Xianglong .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 :8457-8471
[36]   VeriFace: Defending against Adversarial Attacks in Face Verification Systems [J].
Sayed, Awny ;
Kinlany, Sohair ;
Zaki, Alaa ;
Mahfouz, Ahmed .
CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 76 (03) :3151-3166
[37]   Stealthy Physical Masked Face Recognition Attack via Adversarial Style Optimization [J].
Gong, Huihui ;
Dong, Minjing ;
Ma, Siqi ;
Camtepe, Seyit ;
Nepal, Surya ;
Xu, Chang .
IEEE TRANSACTIONS ON MULTIMEDIA, 2024, 26 :5014-5025
[38]   Adversarial Light Projection Attacks on Face Recognition Systems: A Feasibility Study [J].
Dinh-Luan Nguyen ;
Arora, Sunpreet S. ;
Wu, Yuhang ;
Yang, Hao .
2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2020), 2020, :3548-3556
[39]   Low-mid adversarial perturbation against unauthorized face recognition system [J].
Zhang, Jiaming ;
Yi, Qi ;
Lu, Dongyuan ;
Sang, Jitao .
INFORMATION SCIENCES, 2023, 648
[40]   RADAP: A Robust and Adaptive Defense Against Diverse Adversarial Patches on face recognition [J].
Liu, Xiaoliang ;
Shen, Furao ;
Zhao, Jian ;
Nie, Changhai .
PATTERN RECOGNITION, 2025, 157