Return
Deep keypoints adversarial attack on face recognition systems
DOI:10.1016/j.neucom.2024.129295.png)
Abstract
En 中文
Face recognition systems based on deep learning have recently demonstrated an outstanding success in solving complex issues. Yet they turn out to be very vulnerable to attack. Therefore, the vulnerability of such systems has to be studied. An efficient attack strategy that deceives the face recognition system creates adversarial examples. The system may mistakenly reject areal subject as a result of such attack. Current methods for creating adversarial face images have poor perceptual quality and take too long to produce. In this paper, we introduce a novel Adversarial Attack named DKA2 that combines both geometry and intensity based attack categories. The attack consists of three main parts: keypoints detection, Geometrically keypoints Perturbation and adversarial mask Generation. Unlike other attacks which perturb every pixel in the image, our method perturbs only the salient regions of the face represented by the keypoints (2% of the image) and the automatic generated adversarial mask. Limiting the perturbed points minimizes the distortion caused by the attack and resulting images that seem natural. Besides, the suggested approach produces stronger adversarial examples that can avoid black-box face matchers with attack success rates as high as 97,03%.
Keywords:
Face recognition
Adversarial attack
Face keypoints
Landmarks
Journal
IF:
6.5
Papers:
2.5W
Citations:
6.5W

