paper-with-me

홈 › Papers

Adversarial Relighting Against Face Recognition

2021-08-18 · Qian Zhang, Qing Guo, Ruijun Gao, Felix Juefei-Xu, Hongkai Yu, Wei Feng

Deep face recognition (FR) has achieved significantly high accuracy on several challenging datasets and fosters successful real-world applications, even showing high robustness to the illumination variation that is usually regarded as a main threat to the FR system. However, in the real world, illumination variation caused by diverse lighting conditions cannot be fully covered by the limited face dataset. In this paper, we study the threat of lighting against FR from a new angle, i.e., adversarial attack, and identify a new task, i.e., adversarial relighting. Given a face image, adversarial relighting aims to produce a naturally relighted counterpart while fooling the state-of-the-art deep FR methods. To this end, we first propose the physical modelbased adversarial relighting attack (ARA) denoted as albedoquotient-based adversarial relighting attack (AQ-ARA). It generates natural adversarial light under the physical lighting model and guidance of FR systems and synthesizes adversarially relighted face images. Moreover, we propose the auto-predictive adversarial relighting attack (AP-ARA) by training an adversarial relighting network (ARNet) to automatically predict the adversarial light in a one-step manner according to different input faces, allowing efficiency-sensitive applications. More importantly, we propose to transfer the above digital attacks to physical ARA (PhyARA) through a precise relighting device, making the estimated adversarial lighting condition reproducible in the real world. We validate our methods on three state-of-the-art deep FR methods, i.e., FaceNet, ArcFace, and CosFace, on two public datasets. The extensive and insightful results demonstrate our work can generate realistic adversarial relighted face images fooling face recognition tasks easily, revealing the threat of specific light directions and strengths.

📄 PDF Abstract BibTeX arXiv:2108.07920

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackFace Recognition

Methods 이 논문이 사용한 방법론

ArcFace ArcFace, or Additive Angular Margin Loss, is a loss function used in face recognition tasks. The softmax is traditionally used…

Similar Papers 제목 키워드 기반

Rethinking the Threat and Accessibility of Adversarial Attacks against Face Recognition Systems

2024-07-11 · Yuxin Cao, Yumeng Zhu, Derui Wang, Sheng Wen 외

Face recognition pipelines have been widely deployed in various mission-critical systems in trust, equitable and responsible AI applications. However, the emergence of adversarial attacks has threatened the security of t…

Adversarial AttackFace Recognition

Similarity-based Gray-box Adversarial Attack Against Deep Face Recognition

2022-01-11 · Hanrui Wang, Shuo Wang, Zhe Jin, Yandan Wang 외

The majority of adversarial attack techniques perform well against deep face recognition when the full knowledge of the system is revealed (\emph{white-box}). However, such techniques act unsuccessfully in the gray-box s…

Adversarial AttackFace Recognition

Light as Deception: GPT-driven Natural Relighting Against Vision-Language Pre-training Models

2025-05-30 · Ying Yang, Jie Zhang, Xiao Lv, Di Lin 외

While adversarial attacks on vision-and-language pretraining (VLP) models have been explored, generating natural adversarial samples crafted through realistic and semantically meaningful perturbations remains an open cha…

Image CaptioningQuestion AnsweringVisual Question Answering

RAF: Recursive Adversarial Attacks on Face Recognition Using Extremely Limited Queries

2022-07-04 · Keshav Kasichainula, Hadi Mansourifar, Weidong Shi

Recent successful adversarial attacks on face recognition show that, despite the remarkable progress of face recognition models, they are still far behind the human intelligence for perception and recognition. It reveals…

Adversarial AttackFace Recognition

Privacy-preserving Adversarial Facial Features

2023-05-08 · CVPR 2023 1 · Zhibo Wang, He Wang, Shuaifan Jin, Wenwen Zhang 외

Face recognition service providers protect face privacy by extracting compact and discriminative facial features (representations) from images, and storing the facial features for real-time recognition. However, such fea…

Face RecognitionPrivacy Preserving