arrow
返回

Invisible Adversarial Attacks on Deep Learning-Based Face Recognition Models

delete2023-01-01
delete3
delete
OA
AI
C
Chih‐Yang Lin
F
Feng-Jie Chen
H
Hui‐Fuang Ng *
W
Wei-Yang Lin *
DOI:10.1109/ACCESS.2023.3279488delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep learning technology has grown rapidly in recent years and achieved tremendous success in the field of computer vision. At present, many deep learning technologies have been applied in daily life, such as face recognition systems. However, as human life increasingly relies on deep neural networks, the potential harms of neural networks are being revealed, particularly in terms of deep neural network security. More and more studies have shown that existing deep learning-based face recognition models are vulnerable to attacks by adversarial samples, resulting in misjudgments that could have serious consequences. However, existing adversarial face images are rather easy to identify with the naked eye, so it is difficult for attackers to carry out attacks on face recognition systems in practice. This paper proposes a method for generating adversarial face images that are indistinguishable from the source images based on facial landmark detection and superpixel segmentation. First, the eyebrows, eyes, nose, and mouth regions are extracted from the face image using a facial landmark detection algorithm. Next, the superpixel segmentation algorithm is used to include the pixels neighboring the extracted facial landmarks with similar pixel values. Lastly, the segmented regions are used as masks to guide existing attack methods to insert adversarial noise within the masked areas. Experimental results show that our method can generate adversarial samples with high Structural Similarity Index Measure (SSIM) values at the cost of a small percentage of attack success rate. In addition, to simulate real-time physical attacks, printouts of the adversarial images generated by the proposed method are presented to the face recognition system via a camera and are still able to fool the face recognition model. Experimental results indicated that the proposed method can successfully perform adversarial attacks on face recognition systems in real-world scenarios.
Keyword:
Face recognition
Perturbation methods
Deep learning
Image segmentation
Facial features
Neural networks
Adversarial attack
deep learning
face recognition

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

U
universiti tunku abdul rahman (utar)
学者数:
2.2K
论文数: 1.8K
被引数: 2
N
National Chung Cheng University
学者数:
3.7K
论文数: 3.3K
被引数: 2.0K
N
National Central University
学者数:
1.0W
论文数: 8.6K
被引数: 6.4K
学者 查看更多机构
引用论文

引用论文

A tutorial on the cross-entropy method关于交叉熵方法的教程
err2005-02-01
err2.2K
PREAI
errDe Boer, PT; Kroese, DP; Mannor, S; Rubinstein, RY
err分享
err收藏
Transdifferentiation of Neural Stem Cells, or Not?
err2002-09-01
err0
errOAAI
errNigel L Kennea; Huseyin Mehmet
err分享
err收藏
Photolysis of CF3CHO at 254 nm and potential contribution to the atmospheric abundance of HFC-23
err2023-12-01
err0
PREAI
errMads Peter Sulbaek Andersen; Sasha Madronich; Joanna May Ohide; Morten Frausig; Ole John Nielsen
err分享
err收藏
Olanzapine in pregnancy and breastfeeding: a review of data from global safety surveillance
err2013-08-01
err0
errOAAI
errElizabeth Brunner; Deborah M Falk; Meghan Jones; Debashish K Dey; Chetan Chinmaya Shatapathy
err分享
err收藏
On the Crystal Structure of Molybdenum Trioxide.
err1950-01-01
err0
errOAAI
errGeorg Andersson; Arne Magnéli; Lars Gunnar Sillén; Max Rottenberg
err分享
err收藏
学者 查看更多内容