Skip to main content
QUICK REVIEW

[論文レビュー] Backdoor Attacks on Facial Recognition in the Physical World

Emily Wenger, Josephine Passananti|arXiv (Cornell University)|Jun 25, 2020
Adversarial Robustness in Machine Learning参考文献 34被引用数 24
ひとこと要約

本稿は、実世界の装飾品をトリガーとして用いることで、顔認識システムに対する物理的バックドア攻撃の実現可能性を調査している。デジタルトリガーに比べて物理的トリガーは効果が低く、誤検出のリスクも高いが、現存する防御策が物理的状況では成立しない仮定に依存しているため、依然として深刻な脅威であることが示された。

ABSTRACT

Backdoor attacks embed hidden malicious behaviors inside deep neural networks (DNNs) that are only activated when a specific is present on some input to the model. A variety of these attacks have been successfully proposed and evaluated, generally using digitally generated patterns or images as triggers. Despite significant prior work on the topic, a key question remains unanswered: can backdoor attacks be physically realized in the real world, and what limitations do attackers face in executing them? In this paper, we present results of a detailed study on DNN backdoor attacks in the physical world, specifically focused on the task of facial recognition. We take 3205 photographs of 10 volunteers in a variety of settings and backgrounds and train a facial recognition model using transfer learning from VGGFace. We evaluate the effectiveness of 9 accessories as potential triggers, and analyze impact from external factors such as lighting and image quality. First, we find that triggers vary significantly in efficacy and a key factor is that facial recognition models are heavily tuned to features on the face and less so to features around the periphery. Second, the efficacy of most trigger objects is. negatively impacted by lower image quality but unaffected by lighting. Third, most triggers suffer from false positives, where non-trigger objects unintentionally activate the backdoor. Finally, we evaluate 4 backdoor defenses against physical backdoors. We show that they all perform poorly because physical triggers break key assumptions they made based on triggers in the digital domain. Our key takeaway is that implementing physical backdoors is much more challenging than described in literature for both attackers and defenders and much more work is necessary to understand how backdoors work in the real world.

研究の動機と目的

  • 実世界の顔認識システムに対する物理的トリガーを用いたバックドア攻撃の実現可能性を評価すること。
  • 照明や画像品質などの環境要因がトリガー有効性に与える影響を評価すること。
  • 既存のバックドア防御の物理的トリガーに対する性能を分析すること。
  • 攻撃者と防御者が物理的バックドアを展開・検出する際に直面する主な制限要因を特定すること。

提案手法

  • 異なる設定や背景条件下で10名の被験者について合計3,205枚の実世界の顔画像を収集した。
  • 収集したデータセットを用いて、VGGFaceからの転移学習を用いて顔認識モデルを訓練した。
  • 9種類の物理的装飾品をトリガー候補として評価し、異なる照明条件および画像品質下での成功率をテストした。
  • 多様な物理的トリガー物体に対して、バックドアの成功率と誤検出率を測定した。
  • 物理的トリガーに対する耐性を評価するために、4つの既存のバックドア防御を評価した。
  • モデルが顔の特徴と周辺特徴にどれほど感度を示すかを分析し、トリガー有効性のばらつきを説明した。

実験結果

リサーチクエスチョン

  • RQ1実世界の顔認識システムにおいて、物理的トリガーがバックドアを正常に起動できるか?
  • RQ2照明条件や画像品質が物理的トリガーの成功率にどのように影響するか?
  • RQ3非トリガー物体が存在する場合、物理的トリガーが誤検出を引き起こす程度はどの程度か?
  • RQ4なぜ既存のデジタルドメイン用バックドア防御は物理的トリガーに適用すると失敗するのか?
  • RQ5顔特徴の局在化と周辺特徴への感度が、トリガー有効性に果たす役割は何か?

主な発見

  • 物理的トリガーはデジタルトリガーに比べて著しく効果が低く、異なる装飾品によって有効性に大きなばらつきが生じる。
  • 顔認識モデルは顔の特徴に対して周辺特徴よりも感度が高いため、顔に基づくトリガーがより効果的である。
  • 画像品質が低いとトリガー有効性が低下するが、照明条件の影響は最小限である。
  • 大多数の物理的トリガーは、非トリガー物体が意図せずバックドアを起動するという高い誤検出率を示す。
  • テストされたすべてのバックドア防御は、物理的状況では成立しない仮定に依存しているため、物理的トリガーに対して失敗する。
  • 本研究は、物理的バックドアが従来の想定よりも実装および検出が困難であると結論づけ、新たな研究手法の必要性を示唆した。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。