Powerful Physical Adversarial Examples Against Practical Face Recognition Systems

被引:9
作者
Singh, Inderjeet [1 ]
Araki, Toshinori [1 ]
Kakizaki, Kazuya [1 ]
机构
[1] NEC Corp Ltd, Kawasaki, Kanagawa, Japan
来源
2022 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION WORKSHOPS (WACVW 2022) | 2022年
关键词
D O I
10.1109/WACVW54805.2022.00036
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
learning (ML)-based safety-critical applications are vulnerable to carefully crafted input instances called adversarial examples (AXs). An adversary can conveniently attack these target systems from digital as well as physical worlds. This paper aims to the generation of robust physical AXs against face recognition systems. We present a novel smoothness loss function and a patch-noise combo attack for realizing powerful physical AXs. The smoothness loss interjects the concept of delayed constraints during the attack generation process, thereby causing better handling of optimization complexity and smoother AXs for the physical domain. The patch-noise combo attack combines patch noise and imperceptibly small noises from different distributions to generate powerful registration-based physical AXs. An extensive experimental analysis found that our smoothness loss results in robust and more transferable digital and physical AXs than the conventional techniques. Notably, our smoothness loss results in a 1.17 and 1.97 times better mean attack success rate (ASR) in physical white-box and black-box attacks, respectively. Our patch-noise combo attack furthers the performance gains and results in 2.39 and 4.74 times higher mean ASR than conventional technique in physical world white-box and black-box attacks, respectively.
引用
收藏
页码:301 / 310
页数:10
相关论文
共 50 条
[41]   Leveraging Universal Adversarial Perturbation and Frequency Band Filters Against Face Recognition [J].
Zhou, Limengnan ;
He, Bufan ;
Jin, Xi ;
Sun, Guangling .
MATHEMATICS, 2024, 12 (20)
[42]   Sibling-Attack: Rethinking Transferable Adversarial Attacks against Face Recognition [J].
Li, Zexin ;
Yin, Bangjie ;
Yao, Taiping ;
Guo, Junfeng ;
Ding, Shouhong ;
Chen, Simin ;
Liu, Cong .
2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, :24626-24637
[43]   Unravelling Robustness of Deep Learning Based Face Recognition against Adversarial Attacks [J].
Goswami, Gaurav ;
Ratha, Nalini ;
Agarwal, Akshay ;
Singh, Richa ;
Vatsa, Mayank .
THIRTY-SECOND AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTIETH INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE / EIGHTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2018, :6829-6836
[44]   Understanding adversarial robustness against on-manifold adversarial examples [J].
Xiao, Jiancong ;
Yang, Liusha ;
Fan, Yanbo ;
Wang, Jue ;
Luo, Zhi-Quan .
PATTERN RECOGNITION, 2025, 159
[45]   Defending Against Adversarial Examples Via Modeling Adversarial Noise [J].
Zhou, Dawei ;
Wang, Nannan ;
Han, Bo ;
Liu, Tongliang ;
Gao, Xinbo .
INTERNATIONAL JOURNAL OF COMPUTER VISION, 2025,
[46]   Simple Physical Adversarial Examples against End-to-End Autonomous Driving Models [J].
Boloor, Adith ;
He, Xin ;
Gill, Christopher ;
Vorobeychik, Yevgeniy ;
Zhang, Xuan .
2019 IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (ICESS), 2019,
[47]   MIGAA: A Physical Adversarial Attack Method against SAR Recognition Models [J].
Xie, Jianyue ;
Peng, Bo ;
Lu, Zhengzhi ;
Zhou, Jie ;
Peng, Bowen .
2024 9TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS, ICCCS 2024, 2024, :309-314
[48]   Transferable universal adversarial perturbations against speaker recognition systems [J].
Liu, Xiaochen ;
Tan, Hao ;
Zhang, Junjian ;
Li, Aiping ;
Gu, Zhaoquan .
WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2024, 27 (03)
[49]   Adversarial Examples on Object Recognition: A Comprehensive Survey [J].
Serban, Alex ;
Poll, Erik ;
Visser, Joost .
ACM COMPUTING SURVEYS, 2020, 53 (03)
[50]   LPLA: The Adversarial Attack Against License Plate Recognition Systems [J].
Zhang, Kejia ;
Qin, Yingxin ;
Pan, Haiwei .
WEB AND BIG DATA, APWEB-WAIM 2024, PT I, 2024, 14961 :407-421