paper-with-me

Papers

Dodging Attack Using Carefully Crafted Natural Makeup

2021-09-14 · Nitzan Guetta, Asaf Shabtai, Inderjeet Singh, Satoru Momiyama, Yuval Elovici

Deep learning face recognition models are used by state-of-the-art surveillance systems to identify individuals passing through public areas (e.g., airports). Previous studies have demonstrated the use of adversarial machine learning (AML) attacks to successfully evade identification by such systems, both in the digital and physical domains. Attacks in the physical domain, however, require significant manipulation to the human participant's face, which can raise suspicion by human observers (e.g. airport security officers). In this study, we present a novel black-box AML attack which carefully crafts natural makeup, which, when applied on a human participant, prevents the participant from being identified by facial recognition models. We evaluated our proposed attack against the ArcFace face recognition model, with 20 participants in a real-world setup that includes two cameras, different shooting angles, and different lighting conditions. The evaluation results show that in the digital domain, the face recognition system was unable to identify all of the participants, while in the physical domain, the face recognition system was able to identify the participants in only 1.22% of the frames (compared to 47.57% without makeup and 33.73% with random natural makeup), which is below a reasonable threshold of a realistic operational environment.

📄 PDF Abstract BibTeX arXiv:2109.06467

Code (0)

등록된 구현이 없습니다.

Tasks

Face Recognition

Methods 이 논문이 사용한 방법론

ArcFace ArcFace, or Additive Angular Margin Loss, is a loss function used in face recognition tasks. The softmax is traditionally used…

Similar Papers 제목 키워드 기반

MASQUE: A Text-Guided Diffusion-Based Framework for Localized and Customized Adversarial Makeup

2025-03-13 · Youngjin Kwon, Xiao Zhang

As facial recognition is increasingly adopted for government and commercial services, its potential misuse has raised serious concerns about privacy and civil rights. To counteract, various anti-facial recognition techni…

Real-World Adversarial Examples involving Makeup Application

2021-09-04 · Chang-Sheng Lin, Chia-Yi Hsu, Pin-Yu Chen, Chia-Mu Yu

Deep neural networks have developed rapidly and have achieved outstanding performance in several tasks, such as image classification and natural language processing. However, recent studies have indicated that both digit…

Adversarial AttackFace Recognitionimage-classificationImage Classification

Rethinking Impersonation and Dodging Attacks on Face Recognition Systems

2024-01-17 · Fengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng 외

Face Recognition (FR) systems can be easily deceived by adversarial examples that manipulate benign face images through imperceptible perturbations. Adversarial attacks on FR encompass two types: impersonation (targeted)…

Adversarial AttackFace Recognition

Threat-Aware UAV Dodging of Human-Thrown Projectiles with an RGB-D Camera

2025-11-28 · Yuying Zhang, Na Fan, Haowen Zheng, Junning Liang 외 arxiv

Uncrewed aerial vehicles (UAVs) performing tasks such as transportation and aerial photography are vulnerable to intentional projectile attacks from humans. Dodging such a sudden and fast projectile poses a significant c…

Pose Estimation

Makeup-Guided Facial Privacy Protection via Untrained Neural Network Priors

2024-08-20 · Fahad Shamshad, Muzammal Naseer, Karthik Nandakumar

Deep learning-based face recognition (FR) systems pose significant privacy risks by tracking users without their consent. While adversarial attacks can protect privacy, they often produce visible artifacts compromising u…

DecoderFace RecognitionFace Verification