Universal Adversarial Spoofing Attacks against Face Recognition
We assess the vulnerabilities of deep face recognition systems for images that falsify/spoof multiple identities simultaneously. We demonstrate that, by manipulating the deep feature representation extracted from a face image via imperceptibly small perturbations added at the pixel level using our proposed Universal Adversarial Spoofing Examples (UAXs), one can fool a face verification system into recognizing that the face image belongs to multiple different identities with a high success rate. One characteristic of the UAXs crafted with our method is that they are universal (identity-agnostic); they are successful even against identities not known in advance. For a certain deep neural network, we show that we are able to spoof almost all tested identities (99\%), including those not known beforehand (not included in training). Our results indicate that a multiple-identity attack is a real threat and should be taken into account when deploying face recognition systems.
Code (0)
등록된 구현이 없습니다.
Tasks
Face RecognitionFace VerificationSimilar Papers 제목 키워드 기반
AdvFAS: A robust face anti-spoofing framework against adversarial examples
Ensuring the reliability of face recognition systems against presentation attacks necessitates the deployment of face anti-spoofing techniques. Despite considerable advancements in this domain, the ability of even the mo…
Adversarial DefenseFace Anti-SpoofingFace RecognitionMalafide: a novel adversarial convolutive noise attack against deepfake and spoofing detection systems
We present Malafide, a universal adversarial attack against automatic speaker verification (ASV) spoofing countermeasures (CMs). By introducing convolutional noise using an optimised linear time-invariant filter, Malafid…
Adversarial AttackFace SwappingSelf-Supervised LearningSpeaker VerificationPrinciples of Designing Robust Remote Face Anti-Spoofing Systems
Protecting digital identities of human face from various attack vectors is paramount, and face anti-spoofing plays a crucial role in this endeavor. Current approaches primarily focus on detecting spoofing attempts within…
Face Anti-SpoofingFace SwappingAdversarial Attacks on Both Face Recognition and Face Anti-spoofing Models
Adversarial attacks on Face Recognition (FR) systems have demonstrated significant effectiveness against standalone FR models. However, their practicality diminishes in complete FR systems that incorporate Face Anti-Spoo…
Face Anti-SpoofingFace RecognitionDomain-generalizable Face Anti-Spoofing with Patch-based Multi-tasking and Artifact Pattern Conversion
Face Anti-Spoofing (FAS) algorithms, designed to secure face recognition systems against spoofing, struggle with limited dataset diversity, impairing their ability to handle unseen visual domains and spoofing methods. We…
Domain GeneralizationMulti-Task LearningFace Anti-SpoofingFace Recognition