arrow
返回

Transferable Black-Box Attack Against Face Recognition With Spatial Mutable Adversarial Patch

delete2023-01-01
delete8
PRE
AI
H
Haotian Ma
许
许可 (Ke Xu)
X
Xinghao Jiang *
Z
Zeyu Zhao
T
Tanfeng Sun
DOI:10.1109/TIFS.2023.3310352delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep Neural Networks (DNNs) are vulnerable to adversarial patch attacks, which raises security concerns for face recognition systems using DNNs. Previous attack methods focus on the perturbation texture and generate adversarial patches with fixed shapes at random or pre-designed locations, which causes poor adversarial transferability. This paper proposes a Spatial Mutable Adversarial Patch (SMAP) method to generate a dynamic mutable patch to be injected into the face. In the proposed SMAP, the texture, position and shape of the patch are optimized simultaneously and the patch generation pipeline is end-to-end differentiable. Specifically, a Patch Location Selection Scheme is designed to find the critical patch position with the most significant influence on the target identity by the step-based gradient search. By innovatively bridging the pre-defined mask and the dynamic update of the patch, the patch position and shape are changed based on the affine transformation and sampling mechanism in each iteration, which maintains the importance of the injected patch to the adversarial objective. To evaluate the vulnerability of face recognition models, we explore more threatening impersonation attacks under the black-box setting and design a strict evaluation metric that aligns with the real-world scenario. Extensive experiments show that the proposed SMAP improves attack performance across various face recognition models and datasets. Moreover, SMAP achieves better transferability on commercial face recognition systems than existing methods.
Keyword:
Adversarial patch
face recognition
impersonation attack
joint optimization
spatial mutability

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

S
shanghai jiao tong university
学者数:
15.7W
论文数: 11.7W
被引数: 159
引用论文

引用论文

Client ahead‐of‐time compiler for embedded Java platforms
err2008-08-05
err0
PREAI
errSunghyun Hong; Jin‐Chul Kim; Soo‐Mook Moon; Jin Woo Shin; Jaemok Lee; Hyeong‐Seok Oh; Hyung‐Kyu Choi
err分享
err收藏
Motion mode of the optimal damping particle in particle dampers
err2016-04-13
err0
PREAI
errKai Zhang; Tianning Chen; Xiaopeng Wang; Jianglong Fang
err分享
err收藏
Breakdown of the Mott-Hubbard State inFe2O3: A First-Order Insulator-Metal Transition with Collapse of Magnetism at 50 GPa
err1999-06-07
err0
PREAI
errM. P. Pasternak; G. Kh. Rozenberg; G. Yu. Machavariani; O. Naaman; R. D. Taylor; R. Jeanloz
err分享
err收藏
学者 查看更多内容