On Fooling Facial Recognition Systems using Adversarial Patches
On Fooling Facial Recognition Systems using Adversarial Patches
复制标题
关于使用对抗性补丁欺骗面部识别系统
DOI:
10.1109/ijcnn55064.2022.9892071
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
M. Raval
中科院分区:
文献类型:
--
作者:
Rushirajsinh Parmar;M. Kuribayashi;Hiroto Takiwaki;M. Raval
Researchers are increasingly interested to study novel attacks on machine learning models. The classifiers are fooled by making small perturbation to the input or by learning patches that can be applied to objects. In this paper we present an iterative approach to generate a patch that when digitally placed on the face can successfully fool the facial recognition system. We focus on dodging attack where a target face is misidentified as any other face. The proof of concept is show-cased using FGSM and FaceNet face recognition system under the white-box attack. The framework is generic and it can be extended to other noise model and recognition system. It has been evaluated for different - patch size, noise strength, patch location, number of patches and dataset. The experiments shows that the proposed approach can significantly lower the recognition accuracy. Compared to state of the art digital-world attacks, the proposed approach is simpler and can generate inconspicuous natural looking patch with comparable fool rate and smallest patch size.