paper-with-me

Papers

Data Poisoning Won’t Save You From Facial Recognition

2021-06-18 · ICML Workshop AML 2021 7 · Evani Radiya-Dixit, Florian Tramer

Data poisoning has been proposed as a compelling defense against facial recognition models trained on Web-scraped pictures. By perturbing the images they post online, users can fool models into misclassifying future (unperturbed) pictures. We demonstrate that this strategy provides a false sense of security, as it ignores an inherent asymmetry between the parties: users' pictures are perturbed once and for all before being published and scraped, and must thereafter fool all future models---including models trained adaptively against the users' past attacks, or models that use technologies discovered after the attack. We evaluate two poisoning attacks against large-scale facial recognition, Fawkes 500,000+ downloads) and LowKey. We demonstrate how an ``oblivious'' model trainer can simply wait for future developments in computer vision to nullify the protection of pictures collected in the past. We further show that an adversary with black-box access to the attack can train a robust model that resists the perturbations of collected pictures. We caution that facial recognition poisoning will not admit an ''arms race'' between attackers and defenders. Once perturbed pictures are scraped, the attack cannot be changed so any future defense irrevocably undermines users' privacy.

📄 PDF Abstract BibTeX

Code (0)

등록된 구현이 없습니다.

Tasks

Data Poisoning

Methods 이 논문이 사용한 방법론

Fawkes Fawkes is an image cloaking system that helps individuals inoculate their images against unauthorized facial recognition models. Fawkes achieves this by helping users add…

Similar Papers 제목 키워드 기반

Data Poisoning Won't Save You From Facial Recognition

2021-06-28 · Evani Radiya-Dixit, Sanghyun Hong, Nicholas Carlini, Florian Tramèr

Data poisoning has been proposed as a compelling defense against facial recognition models trained on Web-scraped pictures. Users can perturb images they post online, so that models will misclassify future (unperturbed) …

Data Poisoning

A Robust Framework for Deep Learning Approaches to Facial Emotion Recognition and Evaluation

2022-01-30 · Nyle Siddiqui, Rushit Dave, Tyler Bauer, Thomas Reither 외

Facial emotion recognition is a vast and complex problem space within the domain of computer vision and thus requires a universally accepted baseline method with which to evaluate proposed models. While test datasets hav…

Emotion ClassificationEmotion RecognitionFacial Emotion Recognition

Explore the Effect of Data Selection on Poison Efficiency in Backdoor Attacks

2023-10-15 · Ziqiang Li, Pengfei Xia, Hong Sun, Yueqi Zeng 외

As the number of parameters in Deep Neural Networks (DNNs) scales, the thirst for training data also increases. To save costs, it has become common for users and enterprises to delegate time-consuming data collection to …

Audio Classificationimage-classificationImage Classificationtext-classification+1

Meta Transfer Learning for Facial Emotion Recognition

2018-05-25 · Dung Nguyen, Kien Nguyen, Sridha Sridharan, Iman Abbasnejad 외

The use of deep learning techniques for automatic facial expression recognition has recently attracted great interest but developed models are still unable to generalize well due to the lack of large emotion datasets for…

Deep LearningEmotion RecognitionFacial Emotion RecognitionFacial Expression Recognition+2

Protecting Proprietary Data: Poisoning for Secure Dataset Release

2021-09-29 · Liam H Fowl, Ping-Yeh Chiang, Micah Goldblum, Jonas Geiping 외

Large organizations such as social media companies continually release data, for example user images. At the same time, these organizations leverage their massive corpora of released data to train proprietary models tha…

Data Poisoning