paper-with-me

홈 › Papers

Stealthy Physical Masked Face Recognition Attack via Adversarial Style Optimization

2023-09-18 · Huihui Gong, Minjing Dong, Siqi Ma, Seyit Camtepe, Surya Nepal, Chang Xu

Deep neural networks (DNNs) have achieved state-of-the-art performance on face recognition (FR) tasks in the last decade. In real scenarios, the deployment of DNNs requires taking various face accessories into consideration, like glasses, hats, and masks. In the COVID-19 pandemic era, wearing face masks is one of the most effective ways to defend against the novel coronavirus. However, DNNs are known to be vulnerable to adversarial examples with a small but elaborated perturbation. Thus, a facial mask with adversarial perturbations may pose a great threat to the widely used deep learning-based FR models. In this paper, we consider a challenging adversarial setting: targeted attack against FR models. We propose a new stealthy physical masked FR attack via adversarial style optimization. Specifically, we train an adversarial style mask generator that hides adversarial perturbations inside style masks. Moreover, to ameliorate the phenomenon of sub-optimization with one fixed style, we propose to discover the optimal style given a target through style optimization in a continuous relaxation manner. We simultaneously optimize the generator and the style selection for generating strong and stealthy adversarial style masks. We evaluated the effectiveness and transferability of our proposed method via extensive white-box and black-box digital experiments. Furthermore, we also conducted physical attack experiments against local FR models and online platforms.

📄 PDF Abstract BibTeX arXiv:2309.09480

Code (0)

등록된 구현이 없습니다.

Tasks

Face Recognition

Similar Papers 제목 키워드 기반

Rethinking the Threat and Accessibility of Adversarial Attacks against Face Recognition Systems

2024-07-11 · Yuxin Cao, Yumeng Zhu, Derui Wang, Sheng Wen 외

Face recognition pipelines have been widely deployed in various mission-critical systems in trust, equitable and responsible AI applications. However, the emergence of adversarial attacks has threatened the security of t…

Adversarial AttackFace Recognition

Adversarial Sticker: A Stealthy Attack Method in the Physical World

2021-04-14 · Xingxing Wei, Ying Guo, Jie Yu

To assess the vulnerability of deep learning in the physical world, recent works introduce adversarial patches and apply them on different tasks. In this paper, we propose another kind of adversarial patch: the Meaningfu…

Face RecognitionImage RetrievalPositionRetrieval+2

Towards Stealthy Backdoor Attacks against Speech Recognition via Elements of Sound

2023-07-17 · Hanbo Cai, Pengcheng Zhang, Hai Dong, Yan Xiao 외

Deep neural networks (DNNs) have been widely and successfully adopted and deployed in various applications of speech recognition. Recently, a few works revealed that these models are vulnerable to backdoor attacks, where…

Backdoor Attackspeech-recognitionSpeech Recognition

T2I-Based Physical-World Appearance Attack against Traffic Sign Recognition Systems in Autonomous Driving

2025-11-17 · Chen Ma, Ningfei Wang, Junhao Zheng, Qing Guo 외 arxiv

Traffic Sign Recognition (TSR) systems play a critical role in Autonomous Driving (AD) systems, enabling real-time detection of road signs, such as STOP and speed limit signs. While these systems are increasingly integra…

Traffic Sign RecognitionAutonomous Driving

Distillation-Enhanced Physical Adversarial Attacks

2025-01-04 · Wei Liu, Yonglin Wu, CHAOQUN LI, Zhuodong Liu 외

The study of physical adversarial patches is crucial for identifying vulnerabilities in AI-based recognition systems and developing more robust deep learning models. While recent research has focused on improving patch s…

Adversarial AttackKnowledge Distillation