On Fooling Facial Recognition Systems using Adversarial Patches

On Fooling Facial Recognition Systems using Adversarial Patches
复制标题

关于使用对抗性补丁欺骗面部识别系统

DOI:
10.1109/ijcnn55064.2022.9892071
复制
发表时间:
2022
期刊:
2022 International Joint Conference on Neural Networks (IJCNN)
影响因子:
--
通讯作者:
M. Raval
M. Raval
中科院分区:
--
文献类型:
--
作者:
Rushirajsinh Parmar;M. Kuribayashi;Hiroto Takiwaki;M. Raval

文献摘要

被引文献

相似文献

研究人员越来越有兴趣研究对机器学习模型的新型攻击。通过对输入进行小扰动或通过学习可应用于对象的补丁来欺骗分类器。在本文中,我们提出了一种迭代的方法来生成一个补丁,当数字放置在脸上可以成功地欺骗面部识别系统。我们专注于躲避攻击,其中一个目标脸被错误地识别为任何其他脸。在白盒攻击下,使用FGSM和FaceNet人脸识别系统展示了概念证明。该框架具有通用性,可以推广到其他噪声模型和识别系统中。它已被评估为不同的补丁大小,噪声强度,补丁位置,补丁和数据集的数量。实验结果表明,该方法可以显着降低识别精度。与现有的数字世界攻击相比,该方法更简单,可以生成不显眼的自然外观补丁,具有可比的欺骗率和最小的补丁大小。
Researchers are increasingly interested to study novel attacks on machine learning models. The classifiers are fooled by making small perturbation to the input or by learning patches that can be applied to objects. In this paper we present an iterative approach to generate a patch that when digitally placed on the face can successfully fool the facial recognition system. We focus on dodging attack where a target face is misidentified as any other face. The proof of concept is show-cased using FGSM and FaceNet face recognition system under the white-box attack. The framework is generic and it can be extended to other noise model and recognition system. It has been evaluated for different - patch size, noise strength, patch location, number of patches and dataset. The experiments shows that the proposed approach can significantly lower the recognition accuracy. Compared to state of the art digital-world attacks, the proposed approach is simpler and can generate inconspicuous natural looking patch with comparable fool rate and smallest patch size.